Skip to content

fix(ci): exempt routine Dependabot bumps from Dependency Audit Trail gate - #3016

Merged
Imran Siddique (imran-siddique) merged 1 commit into
microsoft:mainfrom
carloshvp:fix/dependabot-audit-gate
Jun 13, 2026
Merged

Imran Siddique (imran-siddique) merged 1 commit into
microsoft:mainfrom
carloshvp:fix/dependabot-audit-gate

Conversation

@carloshvp

Copy link
Copy Markdown
Contributor

Problem

The Dependency Audit Trail gate (vendored-patch-audit job in .github/workflows/quality-gates.yml) requires every PR that changes a lockfile to also add a dated docs/dependency-audits/YYYY-MM-DD-<desc>.md doc. Dependabot changes lockfiles but never authors that doc, so every Dependabot PR fails this required check by construction — blocking routine patch/minor bumps unless a maintainer hand-authors a doc or admin-bypasses the gate. (#2975)

Fix

Issue #2975 option 2: exempt routine Dependabot bumps, keep the control for everyone else.

  • The vendored-patch-audit job now resolves the bump type with dependabot/fetch-metadata — the same action and pinned SHA already used by auto-merge-dependabot.yml. The step runs only when github.actor == 'dependabot[bot]'; it's skipped for every other PR.
  • scripts/ci/vendored-patch-audit.sh exempts the audit-doc requirement when PR_ACTOR=dependabot[bot] and the update is non-major (update-type != version-update:semver-major). This is exactly the set auto-merge-dependabot.yml already auto-merges, so the policy stays consistent.

Still enforced (fail-closed)

Scenario Result
Human PR changes a lockfile, no doc ❌ doc required (unchanged)
Dependabot patch/minor bump ✅ exempt
Dependabot major bump ❌ doc still required
Dependabot PR but update-type empty/missing ❌ doc required
Non-Dependabot actor spoofing a patch update-type ❌ doc required (actor must be dependabot[bot])
Any lockfile change with an audit doc ✅ passes (unchanged)

The required check name (Dependency Audit Trail) is unchanged, so branch protection is unaffected. The job gains pull-requests: read for the metadata lookup.

Testing

Logic validated locally against a throwaway git repo covering all six scenarios above; the untrusted update-type/actor values are passed via env: and only ever referenced as quoted shell variables (no run: interpolation).

Closes #2975

🤖 Generated with Claude Code

…gate

The vendored-patch-audit gate requires every lockfile change to ship a dated docs/dependency-audits/ doc. Dependabot never authors that doc, so every Dependabot PR failed this required check by construction, blocking routine patch/minor bumps.

Resolve the bump type via dependabot/fetch-metadata (already used, same pinned SHA, by auto-merge-dependabot.yml) and exempt only non-major Dependabot updates — the same set that workflow already auto-merges. Human PRs and Dependabot major bumps still require the audit doc; a missing/empty update-type or a non-Dependabot actor falls through to enforcement (fail-closed).

Closes microsoft#2975

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exactly what #2975 asked for. The implementation is clean:

  • Uses the same pinned SHA as so the exemption boundary is consistent with the auto-merge policy
  • Guards at both layers (GHA step condition + shell script double-check on PR_ACTOR) so neither can be bypassed alone
  • Major bumps still require the audit doc
  • Empty/missing DEPENDABOT_UPDATE_TYPE (e.g. action fetch failed) falls through to the doc requirement

All CI gates pass.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exactly what issue 2975 asked for. The implementation is clean: uses the same pinned dependabot/fetch-metadata SHA as auto-merge-dependabot.yml so the exemption boundary is consistent with the auto-merge policy, guards at both layers (GHA step condition + shell script double-check on PR_ACTOR), major bumps still require the audit doc, and empty/missing DEPENDABOT_UPDATE_TYPE falls through to the doc requirement. All CI gates pass.

@imran-siddique
Imran Siddique (imran-siddique) merged commit c5bfc60 into microsoft:main Jun 13, 2026
14 of 15 checks passed
@carloshvp
Carlos Hernandez (carloshvp) deleted the fix/dependabot-audit-gate branch June 16, 2026 18:47
jlaportebot (jlaportebot) pushed a commit to jlaportebot/agent-governance-toolkit that referenced this pull request Jun 17, 2026
…gate (microsoft#3016)

The vendored-patch-audit gate requires every lockfile change to ship a dated docs/dependency-audits/ doc. Dependabot never authors that doc, so every Dependabot PR failed this required check by construction, blocking routine patch/minor bumps.

Resolve the bump type via dependabot/fetch-metadata (already used, same pinned SHA, by auto-merge-dependabot.yml) and exempt only non-major Dependabot updates — the same set that workflow already auto-merges. Human PRs and Dependabot major bumps still require the audit doc; a missing/empty update-type or a non-Dependabot actor falls through to enforcement (fail-closed).

Closes microsoft#2975

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: jlaportebot <jlaportebot@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

scripts/ci/cd size/S Small PR (< 50 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[CI]: Dependabot PRs are permanently blocked by the Dependency Audit Trail gate (no auto-generated audit doc)

2 participants