docs: record the Dependabot round closure, the declined display-name decision, and the governance re-verification - #161
Merged
Conversation
…decision, and the governance re-verification docs/ARCHIVE.md gains the dated §14 entry for the round: the merge/close outcome for every queue member, the #158 -> #159 branch replacement and its mechanics corrections, the DECLINED profile-display-name decision, the verified-unchanged alembic timing claim, the re-verified ignore-list-on-main finding with its options and costs, the live governance/ruleset re-verification, the sandbox-interpreter resolution (3.14.6 installable via a current uv; suite green; the 3.13 pathlib failure re-reproduced as recorded), and the environment's footer-append behaviour on GitHub writes. CLAUDE.md § Git & PR conventions and docs/ROADMAP.md now record the display name as declined-not-deferred so future sessions do not re-raise it, with web-UI/API merge commits stated as correct as they stand. The ROADMAP's CodeQL item is reduced to alert disposition (both settings edits verified done via live ruleset reads), the 2026-08-02 governance list is re-dated with what was re-verifiable, and the #86 sweep entry names #153 as its open, deliberately unactioned Dependabot expression.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The durable record for the 2026-08-09 round that finished the open Dependabot queue, plus the documentation corrections that round surfaced. Docs-only — no code, schema, CI-behavior, or dependency change.
What changed
docs/ARCHIVE.mdgains the dated §14 entry covering the round end-to-end: the merge order and per-merge CI verification for deps: reapply the mergeable half of #157 and record the Dependabot queue audit #159/docker: bump debian from7b140f3toabd67ffin /docker in the docker-images group #151/ci: bump the github-actions group with 2 updates #154/deps: bump bundled scanners to trivy 0.73.0, grype 0.116.1, syft 1.50.0 #160/docker: bump aquasec/trivy from 0.72.0 to 0.73.0 in /docker in the docker-images group #150; the closures (ci: bump cryptography from 49.0.0 to 50.0.0 in /backend in the pip group across 1 directory #149 after verifying fix(deps): bump cryptography 49.0.0 -> 50.0.0, closing CVE-2026-69247 #156's supersession in thedevdiff, backend: bump the backend-dependencies group across 1 directory with 2 updates #157, deps: reapply the mergeable half of #157 and record the Dependabot queue audit #158 replaced by deps: reapply the mergeable half of #157 and record the Dependabot queue audit #159 from a renamed branch, with the mechanics corrections); the DECLINED profile-display-name decision, written so a future reader does not re-raise it; the verified-unchanged alembic timing claim (PyPI: 1.19.1 published 2026-08-08T16:32Z, ~7h after backend: bump the backend-dependencies group across 1 directory with 2 updates #157 opened — the entry was right as written); the re-verifiedignore-list-read-from-mainfinding with its options and costs, deliberately left; the live governance/ruleset re-verification (including two settings edits found done that nothing recorded — the CodeQL contexts are required on both rulesets and default setup is off); the sandbox-interpreter resolution (3.14.6 installs via a current uv; full suite 728 passed / 11 skipped; the 3.13pathlibfailure re-reproduced exactly as the 2026-08-03 entry records); and the environment's footer-append behavior on GitHub API writes.docs/ROADMAP.md— the governance checklist now records the display name as declined, not deferred (web-UI/API merge commits are correct as they stand), re-dates what was re-verifiable on 2026-08-09, reduces the CodeQL item to alert disposition only, and names frontend: bump the frontend-dependencies group in /frontend with 13 updates #153 as the frontend: bump the frontend-dependencies group across 1 directory with 25 updates #86 sweep's open, deliberately unactioned Dependabot expression.CLAUDE.md§ Git & PR conventions — the sentence requiring the profile display name to readtyler-richis replaced with the declined decision, so the rules document and the decision agree. (This file was not named in the round's scope; it is included because it is read first every session and would otherwise keep re-raising the closed question.)Verification