Skip to content

ci(deps): monitor all supported dependency sources - #56

Merged
Wondertan merged 3 commits into
mainfrom
chore/dependabot-all-dependencies
Sep 29, 2026
Merged

Wondertan merged 3 commits into
mainfrom
chore/dependabot-all-dependencies

Conversation

@Wondertan

@Wondertan Wondertan commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Generalize the Wrangler-only rule to all declared and supported indirect dependencies, preserving its fortnightly schedule, seven-day cooldown, and one-PR limit.
  • Add the /ts pnpm workspace, harness Compose images, and GitHub Actions.
  • Combine all supported sources into one version-update group. Coverage and unsupported/manual pins are summarized below.

Verification

  • All 13 configurations pass the current Dependabot schema.
  • Audited coverage of 90 supported dependency files plus workflow Actions across the organization.
  • No dependency versions changed; full application builds were not run for these configuration/documentation changes.

Activation

Merge to activate version checks. This does not enable auto-merge or change security-alert settings. See the coverage notes below for unsupported sources and coupled proof-toolchain updates.

Scope: the final PR diff contains YAML files only. Regression checks were run locally; no documentation or standalone test files are added.

Manual-update coverage gaps

  • Nargo/Noir dependencies in libID-circuits and TLSN examples are unsupported.
  • Raw Cargo Git SHA pins and transitive Git dependencies require manual updates; version-like Git tags can be updated.
  • Workflow tool-version inputs, shell-installed tools, Foundry/solc pins, and workflow service-image values are not covered by these jobs.
  • Nargo/Barretenberg, browser proof packages, generated verifiers/keys, custom release-version fields, downloaded artifacts and their checksums need coordinated review. Dependabot cannot coordinate that release sequence across repositories.
  • Floating tool/image tags have no pinned release to bump. No auto-merge or security-alert settings are changed.
  • The TLSN and MPZ forks require explicit version-update enablement in Settings > Advanced Security after merging.

Each configured manifest root was audited, including excluded Cargo workspaces, both pnpm workspaces, Solidity Git submodules, Docker/Compose files, and the nested contracts composite Action. The two Grounded repositories are covered in separate PRs linked in the rollout comments.

Cadence and PR policy

  • Every other Monday at 09:00 UTC, using interval: cron and cronjob: "0 9 * * mon%2". Next scheduled dates after 2026-09-29 are October 12 and 26, subject to activation before then.
  • One catch-all version-update group per repository, with open-pull-requests-limit: 1. Multi-ecosystem repositories share a top-level group; single-ecosystem repositories use a normal wildcard group.
  • Default automatic refresh/rebase is retained. Dependabot refreshes existing group PRs instead of creating another for that group. It is not a permanent rolling PR guarantee: automatic rebasing stops after 30 days or human commits.
  • Security updates remain separate from the version-update group, cadence and limit; no security settings are disabled.
  • Existing cooldowns and all manifest roots are preserved. Related packages remain together inside the larger catch-all group. YAML changes only.

Verification: all 15 configurations pass schema and grouping/coverage assertions; Fugit 1.14.0 generated 260 consecutive runs in UTC with exact 14-day gaps across year boundaries. The handles-link-site quality gate and formatting check pass. GitHub-side scheduling is not yet verified because these PRs are unmerged. GitHub has acknowledged a cron regression; check the live Dependabot schedule and first scheduled run after activation.

Remove the Wrangler-only allowlist, cover both pnpm workspaces and Compose, and document the organization-wide coverage and manual-only pins.

Assisted-by: GPT-6
Signed-off-by: Wondertan <hlibwondertan@gmail.com>
@Wondertan

Wondertan commented Sep 29, 2026 •

Copy link
Copy Markdown
Member Author

Dependabot rollout (all 15 setup PRs merged; verified 2026-09-29): 2 merged, 11 awaiting review with auto-merge enabled, 2 held; verified 2026-09-29):

Current policy: one catch-all version-update group per repo with a one-PR limit, every other Monday at 09:00 UTC. All final diffs remain YAML-only. Existing cooldowns and manifest roots are preserved. Security updates remain separate and unrestricted by the version-update limit.

Automatic refresh/rebase remains enabled, but Dependabot stops automatic rebasing after 30 days or human commits; this is not a permanent-PR guarantee. The cron expression was tested over 260 runs with exact 14-day gaps. All 15 configurations pass schema and grouping/coverage validation, and the handles-link-site quality gate passes. Available pre-merge PR checks passed except the main libID Cloudflare build, which was also failing on main. At the user's explicit direction, the 13 remaining PRs were admin-merged, including libID. All 15 merged commits were verified to contain only YAML changes, matching DCO sign-offs, and model attribution.

Version-update configuration is now merged into each default branch; tlsn and mpz still need explicit fork version-update enablement verified. Because of reported GitHub cron regressions, verify the live schedule and first scheduled run after activation. CVE alerts and automatic security-fix PRs are now enabled and verified on all 15 repositories (2026-09-29), independently of the version-update PRs. The user explicitly approved bypassing the required reviews and libID's unrelated Cloudflare failure for this rollout. Repository protection settings and personal email/web notification preferences are unchanged. Newly generated dependency/security-update PRs were not merged.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Failed ❌

View logs ↗
6b133c9 2026-09-29T17:25:53.467Z View logs ↗
  • Build: Failed ❌

View logs ↗
0387793 2026-09-29T17:04:06.620Z View logs ↗
  • Build: Failed ❌

View logs ↗
9e0449a 2026-09-29T16:47:19.124Z View logs ↗

@Wondertan

Copy link
Copy Markdown
Member Author

Grounded repositories are now included in the rollout (15 PRs total):

Both existing Wrangler-only rules now allow all direct and indirect dependencies, preserving their schedule, cooldown, and PR limit. handles-link-site also gains GitHub Actions coverage. Both configs validate; the site passes its full local quality gate (including 38 tests). Both Cloudflare build checks have passed; the site GitHub quality check is still running. Neither PR has been merged.

Remove the documentation additions and references; keep regression checks outside the repository and coverage notes in the pull requests.

Assisted-by: GPT-6
Signed-off-by: Wondertan <hlibwondertan@gmail.com>
Use one catch-all version-update group with a one-PR limit, scheduled every other Monday at 09:00 UTC. Preserve manifest coverage and existing cooldowns; security updates remain separate.

Assisted-by: GPT-6
Signed-off-by: Wondertan <hlibwondertan@gmail.com>
@Wondertan
Wondertan merged commit a648d28 into main Sep 29, 2026
6 of 7 checks passed
@Wondertan
Wondertan deleted the chore/dependabot-all-dependencies branch September 29, 2026 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant