Repository navigation
fix(ci): exempt routine Dependabot bumps from Dependency Audit Trail gate - #3016
Conversation
…gate The vendored-patch-audit gate requires every lockfile change to ship a dated docs/dependency-audits/ doc. Dependabot never authors that doc, so every Dependabot PR failed this required check by construction, blocking routine patch/minor bumps. Resolve the bump type via dependabot/fetch-metadata (already used, same pinned SHA, by auto-merge-dependabot.yml) and exempt only non-major Dependabot updates — the same set that workflow already auto-merges. Human PRs and Dependabot major bumps still require the audit doc; a missing/empty update-type or a non-Dependabot actor falls through to enforcement (fail-closed). Closes microsoft#2975 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
Exactly what #2975 asked for. The implementation is clean:
- Uses the same pinned SHA as so the exemption boundary is consistent with the auto-merge policy
- Guards at both layers (GHA step condition + shell script double-check on
PR_ACTOR) so neither can be bypassed alone - Major bumps still require the audit doc
- Empty/missing
DEPENDABOT_UPDATE_TYPE(e.g. action fetch failed) falls through to the doc requirement
All CI gates pass.
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
Exactly what issue 2975 asked for. The implementation is clean: uses the same pinned dependabot/fetch-metadata SHA as auto-merge-dependabot.yml so the exemption boundary is consistent with the auto-merge policy, guards at both layers (GHA step condition + shell script double-check on PR_ACTOR), major bumps still require the audit doc, and empty/missing DEPENDABOT_UPDATE_TYPE falls through to the doc requirement. All CI gates pass.
c5bfc60
into
microsoft:main
…gate (microsoft#3016) The vendored-patch-audit gate requires every lockfile change to ship a dated docs/dependency-audits/ doc. Dependabot never authors that doc, so every Dependabot PR failed this required check by construction, blocking routine patch/minor bumps. Resolve the bump type via dependabot/fetch-metadata (already used, same pinned SHA, by auto-merge-dependabot.yml) and exempt only non-major Dependabot updates — the same set that workflow already auto-merges. Human PRs and Dependabot major bumps still require the audit doc; a missing/empty update-type or a non-Dependabot actor falls through to enforcement (fail-closed). Closes microsoft#2975 Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Signed-off-by: jlaportebot <jlaportebot@gmail.com>
Problem
The
Dependency Audit Trailgate (vendored-patch-auditjob in.github/workflows/quality-gates.yml) requires every PR that changes a lockfile to also add a dateddocs/dependency-audits/YYYY-MM-DD-<desc>.mddoc. Dependabot changes lockfiles but never authors that doc, so every Dependabot PR fails this required check by construction — blocking routine patch/minor bumps unless a maintainer hand-authors a doc or admin-bypasses the gate. (#2975)Fix
Issue #2975 option 2: exempt routine Dependabot bumps, keep the control for everyone else.
vendored-patch-auditjob now resolves the bump type withdependabot/fetch-metadata— the same action and pinned SHA already used byauto-merge-dependabot.yml. The step runs only whengithub.actor == 'dependabot[bot]'; it's skipped for every other PR.scripts/ci/vendored-patch-audit.shexempts the audit-doc requirement whenPR_ACTOR=dependabot[bot]and the update is non-major (update-type != version-update:semver-major). This is exactly the setauto-merge-dependabot.ymlalready auto-merges, so the policy stays consistent.Still enforced (fail-closed)
update-typeempty/missingupdate-typedependabot[bot])The required check name (
Dependency Audit Trail) is unchanged, so branch protection is unaffected. The job gainspull-requests: readfor the metadata lookup.Testing
Logic validated locally against a throwaway git repo covering all six scenarios above; the untrusted
update-type/actor values are passed viaenv:and only ever referenced as quoted shell variables (norun:interpolation).Closes #2975
🤖 Generated with Claude Code