Repository navigation
ci(deps): monitor all supported dependency sources - #56
Conversation
Remove the Wrangler-only allowlist, cover both pnpm workspaces and Compose, and document the organization-wide coverage and manual-only pins. Assisted-by: GPT-6 Signed-off-by: Wondertan <hlibwondertan@gmail.com>
|
Dependabot rollout (all 15 setup PRs merged; verified 2026-09-29): 2 merged, 11 awaiting review with auto-merge enabled, 2 held; verified 2026-09-29):
Current policy: one catch-all version-update group per repo with a one-PR limit, every other Monday at 09:00 UTC. All final diffs remain YAML-only. Existing cooldowns and manifest roots are preserved. Security updates remain separate and unrestricted by the version-update limit. Automatic refresh/rebase remains enabled, but Dependabot stops automatic rebasing after 30 days or human commits; this is not a permanent-PR guarantee. The cron expression was tested over 260 runs with exact 14-day gaps. All 15 configurations pass schema and grouping/coverage validation, and the handles-link-site quality gate passes. Available pre-merge PR checks passed except the main libID Cloudflare build, which was also failing on main. At the user's explicit direction, the 13 remaining PRs were admin-merged, including libID. All 15 merged commits were verified to contain only YAML changes, matching DCO sign-offs, and model attribution. Version-update configuration is now merged into each default branch; tlsn and mpz still need explicit fork version-update enablement verified. Because of reported GitHub cron regressions, verify the live schedule and first scheduled run after activation. CVE alerts and automatic security-fix PRs are now enabled and verified on all 15 repositories (2026-09-29), independently of the version-update PRs. The user explicitly approved bypassing the required reviews and libID's unrelated Cloudflare failure for this rollout. Repository protection settings and personal email/web notification preferences are unchanged. Newly generated dependency/security-update PRs were not merged. |
🚀 Deploying Preview to Cloudflare 🚀Preview Deployments by commit
|
|
Grounded repositories are now included in the rollout (15 PRs total):
Both existing Wrangler-only rules now allow all direct and indirect dependencies, preserving their schedule, cooldown, and PR limit. handles-link-site also gains GitHub Actions coverage. Both configs validate; the site passes its full local quality gate (including 38 tests). Both Cloudflare build checks have passed; the site GitHub quality check is still running. Neither PR has been merged. |
Remove the documentation additions and references; keep regression checks outside the repository and coverage notes in the pull requests. Assisted-by: GPT-6 Signed-off-by: Wondertan <hlibwondertan@gmail.com>
Use one catch-all version-update group with a one-PR limit, scheduled every other Monday at 09:00 UTC. Preserve manifest coverage and existing cooldowns; security updates remain separate. Assisted-by: GPT-6 Signed-off-by: Wondertan <hlibwondertan@gmail.com>
Summary
Verification
Activation
Merge to activate version checks. This does not enable auto-merge or change security-alert settings. See the coverage notes below for unsupported sources and coupled proof-toolchain updates.
Scope: the final PR diff contains YAML files only. Regression checks were run locally; no documentation or standalone test files are added.
Manual-update coverage gaps
Each configured manifest root was audited, including excluded Cargo workspaces, both pnpm workspaces, Solidity Git submodules, Docker/Compose files, and the nested contracts composite Action. The two Grounded repositories are covered in separate PRs linked in the rollout comments.
Cadence and PR policy
interval: cronandcronjob: "0 9 * * mon%2". Next scheduled dates after 2026-09-29 are October 12 and 26, subject to activation before then.open-pull-requests-limit: 1. Multi-ecosystem repositories share a top-level group; single-ecosystem repositories use a normal wildcard group.Verification: all 15 configurations pass schema and grouping/coverage assertions; Fugit 1.14.0 generated 260 consecutive runs in UTC with exact 14-day gaps across year boundaries. The handles-link-site quality gate and formatting check pass. GitHub-side scheduling is not yet verified because these PRs are unmerged. GitHub has acknowledged a cron regression; check the live Dependabot schedule and first scheduled run after activation.