Skip to content

chore(ci): Dependabot for Go modules and frontend npm packages - #89

Open
0xMMA wants to merge 4 commits into
mainfrom
chore/dependabot-gomod-npm
Open

0xMMA wants to merge 4 commits into
mainfrom
chore/dependabot-gomod-npm

Conversation

@0xMMA

@0xMMA 0xMMA commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Roadmap housekeeping item: add gomod and npm to Dependabot.

What

  • gomod (/) and npm (/frontend), monthly, grouped.
  • npm has a 7-day cooldown. packageManager moves from npm 11.9.0 to 11.19.0, the version the dev box runs. Dependabot only passes --min-release-age with npm >= 11.10, and without it the cooldown would not reach transitive packages.
  • Framework family (@angular/*, primeng, @primeuix/*, primeicons, typescript) is one group, minor/patch only. Their majors need ng update, the TypeScript major Angular dictates, and a look at every screen on Windows. A Dependabot PR does none of that.
  • Everything else gets one minor/patch group per ecosystem. Other npm majors (e.g. dotenv 18) arrive as single PRs.

What it does not do (also stated in the file)

  • It does not surface the drift that prompted the item. Wails is ignored on both sides, and framework majors are blocked. The quarterly check in the roadmap housekeeping section does that; it now covers framework majors and Wails too.
  • Security updates skip ignore rules that have no versions range (dependabot-core ignore_condition.rb). An advisory for Wails or a framework package can still arrive as a PR. That is deliberate, because it is the loudest notice. It is not merge-on-green.
  • Go: a module-path major (/v4) is never proposed. v0 minor bumps (wire, selfupdate, go-keyring) land in go-minor and may break the API.

Also

  • .claude/rules/testing.md and .claude/docs/testing.md: vi.mock has only been blocked for relative/absolute paths since Angular 21.2.1. The Vitest 5 gate lifts at @angular/build >= 22.2, not with any Angular 22. Duplicated ## Go Tests heading removed.
  • Roadmap: E4 TypeScript step (Angular 22 needs TS 6.0), Vitest notes, quarterly check extended.

Review

Two Opus review rounds.

  • Round 1: separate major groups could never resolve. Redesigned.
  • Round 2: the security-ignore claim was the wrong way round, the cooldown did not reach transitive packages under npm 11.9, and several comments and doc lines were inaccurate. All addressed, each verified against dependabot-core source or the npm registry.

Verification

  • SchemaStore dependabot-2.0: 0 errors.
  • npm install --package-lock-only: no lockfile change.

0xMMA added a commit that referenced this pull request Sep 24, 2026
Re-resolved from main's lockfile with npm --before=2026-09-18, then npm audit fix under the same cutoff: every one of the 147 changed versions was published before the cutoff (checked against the registry), and audit still reports 0 vulnerabilities. Angular lands on 21.2.23 instead of the day-old 21.2.24; jsdom 30.1.0, prettier 3.9.8. Matches the 7-day npm cooldown #89 gives Dependabot.
Second review: ignore rules without versions do not apply to security updates (dependabot-core ignore_condition.rb), so advisories can still arrive as PRs; say so instead of claiming the opposite. Dependabot passes --min-release-age only with npm >= 11.10, so packageManager moves 11.9.0 -> 11.19.0 (what the dev box runs) for the cooldown to reach transitive packages. Reasons for the framework-major block no longer claim unresolvability. vi.mock and Vitest-gate wording updated for Angular 21.2.1+ / 22.2.
@0xMMA

0xMMA commented Sep 24, 2026

Copy link
Copy Markdown
Owner Author

Merge-ready: CI green, two Opus review rounds (each with review-pr fork supplement), all findings addressed and verified against dependabot-core source / npm registry. Touches frontend/package.json (packageManager line) like #91 — merge after #91; conflict unlikely (different lines).

PrimeNG 22, @primeuix/* 3 (styled/motion 1, utils 0.8) and primeicons 8 moved from MIT to the commercial PrimeUI License (key required, banner without). Explicit versions ranges so security updates cannot cross the line either; roadmap records the decision it forces on E4 step 2.
@0xMMA

0xMMA commented Sep 24, 2026

Copy link
Copy Markdown
Owner Author

Added after the reviews: a licence fence (59da5f0). PrimeNG 22, @primeuix/* 3 / 1 / 0.8 and primeicons 8 moved to the commercial PrimeUI License (see #35). Explicit versions: ignores, which unlike update-type ignores also bind security updates, keep them out. Every version below the bounds is MIT (checked per version); the current lockfile is entirely MIT. Schema still valid.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant