docs(ci): dependabot.yml — record the jsboige arbitration (header still said "NOT merged") - #936
Merged
Merged
Conversation
…der said "NOT merged" The file landed on master in #910 still carrying its pre-merge header: "OPEN AS A PR — NOT merged. Deliberate jsboige arbitration on scope". Both halves are now false — it is merged, and the arbitration returned. Replaces that line with the decision actually taken (jsboige, interactive, 2026-07-26): option A — keep the 26 vendored 2sxc/DNN npm trees under dependabot surveillance, grouped, majors filtered. Security patches and minors keep arriving; only majors are suppressed. Also notes that #901 (webpack-dev-server 5->6, the motivating case cited in the comment) was closed out-of-policy under this very rule, and documents the escape hatch: a CVE fixable only by a vendored major means dropping the `ignore` for that one directory here, not merging the major around the policy. Comments only — YAML re-validated, 29 update blocks unchanged. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
42 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
La politique dependabot a été mergée en #910 (
05e12463), mais le fichier a atterri sur master avec son en-tête d'avant-merge :Les deux moitiés sont fausses depuis le merge : le fichier est mergé, et l'arbitrage est rendu. Un fichier de politique qui affirme être en attente d'arbitrage se relit, dans six mois, comme une politique non ratifiée.
Ce que ça enregistre
Décision jsboige, interactive, 2026-07-26 — option A : les 26 arbres npm vendored (2sxc/DNN) restent sous surveillance dependabot, groupés, majors filtrés. Les patches et minors de sécurité continuent d'arriver ; seuls les majors sont supprimés. Plafond ~26 PR/semaine au lieu de plusieurs centaines sans
groups.Deux ajouts au passage
webpack-dev-server 5->6 in Bootstrap 4 Instant) a été fermée out-of-policy au titre de cette règle même. Le commentaire dit maintenant l'issue de l'affaire, pas seulement son énoncé.ignorede ce répertoire-là dans ce fichier, pas de merger le major en contournant la politique. Sans cette ligne, la première urgence réelle se règle par un bypass, et la politique meurt en silence.Vérification
Commentaires uniquement — aucune règle touchée. YAML re-validé après édition :
version: 2, 29 blocsupdatesinchangés (1 nuget + 2 npm à nous + 26 vendored).Réf : #910 · #901 · roadmap #458.
🤖 Coordinator ai-01