chore: stop scheduled version updates, keeping Dependabot for security only - #154
Merged
Merged
Conversation
…y only Kilian believed every Dependabot PR was a security alert. They were not: this config scheduled weekly VERSION updates across three ecosystems, and that is where #137, #138 and #144 came from. #144 carried no advisory and broke the web build. Alerts and security PRs are a repo-level setting, already enabled and untouched by this change, so advisories still arrive automatically. There is no version-updates opt-out short of removing the config, so the file goes. It is read from the default branch only, so this takes effect when `dev` is next promoted. Deleting it would have left two lines in `CLAUDE.md` false: - one cited the config as a path, which the path arm of `test_claude_md_claims.py` would have caught. Its subject — a class of file read only from `main` — is still true, and `workflow_dispatch` registration is another member, so the line keeps the doctrine and drops the example. - "SOME pinned action SHAs Dependabot can never bump" implied the rest were handled. Nothing is now bumped on a schedule, and only an advisory can move an action pin, so the line says every pin is checked by hand. The config's two `ignore` rules were holds, and a prohibition may not be deleted with the file that carried it. The `typescript` hold is already stated at `CLAUDE.md:64` and needed nothing. The `@types/node` hold had no home in the tree — only PR #6's commit body and an archived reason — so it becomes `tests/test_node_types_pin.py`, which asserts the `@types/node` major equals the `.nvmrc` runtime major. A guard rather than a tripwire line, because the claim is executable: staleness is the correct state here, nothing else in the repo objects to a newer major, and a hold nothing enforces is one the next reader "fixes". Shown to fail at `^26.0.0`. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Kilian believed every Dependabot PR was a security alert. They were not.
.github/dependabot.ymlscheduled weekly version updates across three ecosystems (uv,npmat/web,github-actions), all withapplies-to: version-updates. That is where #137, #138 and #144 came from — #144 carried no advisory and broke the web build.Alerts and security updates are a repo-level setting, already enabled, and untouched by this PR. Verified via the API:
dependabot_security_updates: enabledon all four of his repos, 0 open alerts. Advisories still arrive automatically. There is no version-updates opt-out short of removing the config, so the file goes.It is read from the default branch only, so this takes effect at the next
dev→mainpromotion.Deleting it would have left two doctrine lines false
Both in
CLAUDE.md, both forced rather than tidy:test_claude_md_claims.pywould have turned red. Its actual subject — a class of file read only frommain— is still true, andworkflow_dispatchregistration is another member, so the line keeps the doctrine and drops the example.A prohibition may not be deleted with the file that carried it
The config's two
ignorerules were held decisions:typescriptmajor hold — already stated atCLAUDE.md:64with its reason (typescript-eslintpeers<6.1.0). Theignoreentry was only its enforcement arm. Deleted cleanly.@types/nodemajor hold — had no home in the working tree. The reason was archived ("@types/*match the runtime major, not the newest — type-checking against a runtime we do not run is a defect TypeScript accepts silently") but the prohibition itself lived only in the config.So it becomes
tests/test_node_types_pin.py: the@types/nodemajor inweb/package.jsonmust equal the major in.nvmrc(both 24). A guard rather than another tripwire line, because the claim is executable — and because staleness is the correct state here, nothing else in the repo objects to a newer major, and a hold nothing enforces is one the next reader "fixes". Shown to fail at^26.0.0:@types/node is on major 26 but .nvmrc runs Node 24.Also swapped the now-dead
.github/dependabot.ymlliteral in the token-regex positive control for a real path — a dead fixture is exactly the phantom that test exists to prevent.🤖 Generated with Claude Code