Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
57 changes: 4 additions & 53 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,60 +1,11 @@
version: 2

registries:
fontawesome:
type: npm-registry
url: https://npm.fontawesome.com
token: ${{secrets.FONTAWESOME_NPM_AUTH_TOKEN}}
scope: "@fortawesome"

updates:
# A new major is deliberate work (spec §6.1): .NET and Microsoft's packages stay on 10, Umbraco on its 17 LTS, and
# uSync's majors follow Umbraco's.
# This entry only starts GitHub's automatic dependency submission for NuGet, which the root's .slnx does not. Without
# that submission the dependency graph reads every version in Directory.Packages.props as ">= 0", and no NuGet alert
# fires.
- package-ecosystem: nuget
directory: /
schedule:
interval: weekly
ignore:
- dependency-name: "*"
update-types: ["version-update:semver-major"]
groups:
umbraco:
patterns: ["Umbraco.*", "uSync*"]
nuget:
patterns: ["*"]

- package-ecosystem: npm
directory: /
registries:
- fontawesome
schedule:
interval: weekly
ignore:
- dependency-name: "*"
update-types: ["version-update:semver-major"]
groups:
npm:
patterns: ["*"]

# Node stays on 24: its images from 26 on drop Yarn 1, which the build uses.
- package-ecosystem: docker
directories:
- /
- /deploy/kcc-backup
schedule:
interval: weekly
ignore:
- dependency-name: "dotnet/*"
update-types: ["version-update:semver-major"]
- dependency-name: "node"
update-types: ["version-update:semver-major"]

- package-ecosystem: docker-compose
directory: /deploy
schedule:
interval: weekly

- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
open-pull-requests-limit: 0
16 changes: 9 additions & 7 deletions docs/hosting/runbook.md
Original file line number Diff line number Diff line change
Expand Up @@ -190,9 +190,10 @@ application key. Do not edit the Pi's clone: a local change to a tracked file ma
2. **The packages stay private.** After the first push to `main` (the images job), open your profile's Packages. For
each of `kcc-app`, `kcc-ssr` and `kcc-backup`, Package settings should say **Private**, and list this repository
with the Admin role under "Manage Actions access". The images job needs that role to prune old versions.
3. **Dependabot's secrets.** Workflows that Dependabot's pull requests trigger read Dependabot's secrets, not the
repository's. Under Settings → Secrets and variables → **Dependabot**, add copies of `FONTAWESOME_NPM_AUTH_TOKEN`,
`KCC_E2E_MEMBER_USERNAME` and `KCC_E2E_MEMBER_PASSWORD` with the same values as the Actions secrets.
3. **Dependabot alerts.** Under Settings → Advanced Security, turn on **Dependabot alerts**, leave **Dependabot
security updates** off, and set **Automatic dependency submission**, under Dependency graph, to **Enabled**. The
submission gives the dependency graph the versions in `Directory.Packages.props`. Without it the graph reads each
NuGet package as `>= 0`, and no NuGet alert fires.

## 7. Install the stack and boot it

Expand Down Expand Up @@ -370,10 +371,11 @@ application key. Do not edit the Pi's clone: a local change to a tracked file ma
3. Delete the copies on the Pi: `sudo rm /tmp/Umbraco.sqlite.db /tmp/kcc-media.tar.gz`. They hold members' data.

The development site then signs you in as the production administrator.
- **Updates.** Dependabot opens pull requests weekly: merging one deploys it. Umbraco's 17.x patches arrive that way.
Dependabot does not read `deploy/local.yaml`, so Caddy's tag there, which only the smoke test and the drill use and
the Pi never runs, is bumped by hand. The OS updates itself; reboot now and then for a new kernel (`sudo reboot`),
and the stack comes back on its own.
- **Updates.** Dependabot opens no pull requests. Its alerts flag a vulnerable npm, NuGet or Actions package: bump it
by hand, and merging the bump deploys it. Alerts follow security advisories only, so Umbraco's other 17.x patches
come unannounced, and Docker images have no alerts at all. Now and then, check for new releases of Umbraco, of the
images in both Dockerfiles' `FROM` lines, and of cloudflared and Caddy under `deploy/`. The OS updates itself; reboot
now and then for a new kernel (`sudo reboot`), and the stack comes back on its own.
- **Rotate the GHCR token** before it expires: make a new classic token (section 6), then run
`sudo -u kcc -H docker login ghcr.io -u <your GitHub username>` again.

Expand Down
4 changes: 2 additions & 2 deletions docs/replatform/specs/2026-09-21-replatform-off-xperience.md
Original file line number Diff line number Diff line change
Expand Up @@ -487,8 +487,8 @@ Every long-running service restarts unless stopped.
### 13.6 Monitoring and maintenance

Container health checks with restart policies; the backup ping; Umbraco's log viewer over the file logs on the data
volume. Dependabot for NuGet, npm, Docker and Actions. Umbraco 17 patch releases as they ship; the 21 LTS move as
§6.1 describes.
volume. Dependabot alerts for NuGet, npm and Actions, with no update pull requests. Umbraco 17 patch releases as they
ship; the 21 LTS move as §6.1 describes.

### 13.7 Fallback

Expand Down
Loading