Skip to content

chore: stop scheduled version updates, keeping Dependabot for security only - #154

Merged
kilianmc merged 1 commit into
devfrom
chore/dependabot-security-only
Sep 10, 2026
Merged

kilianmc merged 1 commit into
devfrom
chore/dependabot-security-only

Conversation

@kilianmc

Copy link
Copy Markdown
Owner

Kilian believed every Dependabot PR was a security alert. They were not.

.github/dependabot.yml scheduled weekly version updates across three ecosystems (uv, npm at /web, github-actions), all with applies-to: version-updates. That is where #137, #138 and #144 came from — #144 carried no advisory and broke the web build.

Alerts and security updates are a repo-level setting, already enabled, and untouched by this PR. Verified via the API: dependabot_security_updates: enabled on all four of his repos, 0 open alerts. Advisories still arrive automatically. There is no version-updates opt-out short of removing the config, so the file goes.

It is read from the default branch only, so this takes effect at the next dev → main promotion.

Deleting it would have left two doctrine lines false

Both in CLAUDE.md, both forced rather than tidy:

  • One cited the config as a path, which the filesystem arm of test_claude_md_claims.py would have turned red. Its actual subject — a class of file read only from main — is still true, and workflow_dispatch registration is another member, so the line keeps the doctrine and drops the example.
  • One said "Some pinned action SHAs are immutable releases Dependabot can never bump". That implied the rest were handled — false in the dangerous direction once nothing is bumped on a schedule. It now says every pin is checked by hand. It still says an advisory can move an action pin, which is correct: GitHub Actions is supported by security updates.

A prohibition may not be deleted with the file that carried it

The config's two ignore rules were held decisions:

  • typescript major hold — already stated at CLAUDE.md:64 with its reason (typescript-eslint peers <6.1.0). The ignore entry was only its enforcement arm. Deleted cleanly.
  • @types/node major hold — had no home in the working tree. The reason was archived ("@types/* match the runtime major, not the newest — type-checking against a runtime we do not run is a defect TypeScript accepts silently") but the prohibition itself lived only in the config.

So it becomes tests/test_node_types_pin.py: the @types/node major in web/package.json must equal the major in .nvmrc (both 24). A guard rather than another tripwire line, because the claim is executable — and because staleness is the correct state here, nothing else in the repo objects to a newer major, and a hold nothing enforces is one the next reader "fixes". Shown to fail at ^26.0.0: @types/node is on major 26 but .nvmrc runs Node 24.

Also swapped the now-dead .github/dependabot.yml literal in the token-regex positive control for a real path — a dead fixture is exactly the phantom that test exists to prevent.

🤖 Generated with Claude Code

…y only

Kilian believed every Dependabot PR was a security alert. They were not: this
config scheduled weekly VERSION updates across three ecosystems, and that is
where #137, #138 and #144 came from. #144 carried no advisory and broke the
web build. Alerts and security PRs are a repo-level setting, already enabled
and untouched by this change, so advisories still arrive automatically.

There is no version-updates opt-out short of removing the config, so the file
goes. It is read from the default branch only, so this takes effect when `dev`
is next promoted.

Deleting it would have left two lines in `CLAUDE.md` false:

- one cited the config as a path, which the path arm of
  `test_claude_md_claims.py` would have caught. Its subject — a class of file
  read only from `main` — is still true, and `workflow_dispatch` registration
  is another member, so the line keeps the doctrine and drops the example.
- "SOME pinned action SHAs Dependabot can never bump" implied the rest were
  handled. Nothing is now bumped on a schedule, and only an advisory can move
  an action pin, so the line says every pin is checked by hand.

The config's two `ignore` rules were holds, and a prohibition may not be
deleted with the file that carried it. The `typescript` hold is already stated
at `CLAUDE.md:64` and needed nothing. The `@types/node` hold had no home in
the tree — only PR #6's commit body and an archived reason — so it becomes
`tests/test_node_types_pin.py`, which asserts the `@types/node` major equals
the `.nvmrc` runtime major. A guard rather than a tripwire line, because the
claim is executable: staleness is the correct state here, nothing else in the
repo objects to a newer major, and a hold nothing enforces is one the next
reader "fixes". Shown to fail at `^26.0.0`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
climb-trainer Ready Ready Preview Sep 10, 2026 8:42pm UTC

@kilianmc
kilianmc merged commit 3b181fa into dev Sep 10, 2026
5 checks passed
@kilianmc
kilianmc deleted the chore/dependabot-security-only branch September 10, 2026 20:44

This branch was successfully deployed

1 active deployment
Preview — 95152591 Deployed Sep 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant