Skip to content

ci(deps): monitor all supported dependency sources - #1

Merged
Wondertan merged 3 commits into
mainfrom
chore/dependabot-all-dependencies
Sep 29, 2026
Merged

Wondertan merged 3 commits into
mainfrom
chore/dependabot-all-dependencies

Conversation

@Wondertan

@Wondertan Wondertan commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Add fortnightly Dependabot checks for all supported dependency roots in this repository, with no package-name allowlist or ignores.
  • Include direct and indirect package dependencies and use Conventional Commit messages.
  • Preserve DCO enforcement while accepting the exact Dependabot bot author with its standard support-address sign-off; unsigned and spoofed commits still fail.
  • Organization coverage and manual-only pins: ci(deps): monitor all supported dependency sources libID#56

Verification

  • All 13 organization configurations pass current Dependabot schema validation.
  • Audited 90 supported dependency files plus all workflow Actions, including excluded Rust workspaces and the nested contracts composite Action.
  • Executed 90 DCO regression cases against the actual shell steps across the 10 affected workflows; all pass.
  • Workflow YAML parsing and git diff --check pass. No dependency versions changed; full application builds were not run locally.

Activation

Merge to the default branch to activate version checks. No auto-merge or security-alert settings changed. Rollout tracking: libid-org/libID#56

Scope: the final PR diff contains YAML files only. Regression checks were run locally; no documentation or standalone test files are added.

Cadence and PR policy

  • Every other Monday at 09:00 UTC, using interval: cron and cronjob: "0 9 * * mon%2". Next scheduled dates after 2026-09-29 are October 12 and 26, subject to activation before then.
  • One catch-all version-update group per repository, with open-pull-requests-limit: 1. Multi-ecosystem repositories share a top-level group; single-ecosystem repositories use a normal wildcard group.
  • Default automatic refresh/rebase is retained. Dependabot refreshes existing group PRs instead of creating another for that group. It is not a permanent rolling PR guarantee: automatic rebasing stops after 30 days or human commits.
  • Security updates remain separate from the version-update group, cadence and limit; no security settings are disabled.
  • Existing cooldowns and all manifest roots are preserved. Related packages remain together inside the larger catch-all group. YAML changes only.

Verification: all 15 configurations pass schema and grouping/coverage assertions; Fugit 1.14.0 generated 260 consecutive runs in UTC with exact 14-day gaps across year boundaries. The handles-link-site quality gate and formatting check pass. GitHub-side scheduling is not yet verified because these PRs are unmerged. GitHub has acknowledged a cron regression; check the live Dependabot schedule and first scheduled run after activation.

Add weekly Dependabot checks for every supported manifest root. Where strict DCO checks apply, accept the exact Dependabot author with its standard support-address sign-off; keep rejecting unsigned commits.

Assisted-by: GPT-6
Signed-off-by: Wondertan <hlibwondertan@gmail.com>
Remove the documentation additions and references; keep regression checks outside the repository and coverage notes in the pull requests.

Assisted-by: GPT-6
Signed-off-by: Wondertan <hlibwondertan@gmail.com>
Use one catch-all version-update group with a one-PR limit, scheduled every other Monday at 09:00 UTC. Preserve manifest coverage and existing cooldowns; security updates remain separate.

Assisted-by: GPT-6
Signed-off-by: Wondertan <hlibwondertan@gmail.com>
@Wondertan
Wondertan merged commit ac85a92 into main Sep 29, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant