From 6c3f6297d78e2d58694befa96f0548381d14bd08 Mon Sep 17 00:00:00 2001 From: Pierre Jeanjacquot <26487010+PierreJeanjacquot@users.noreply.github.com> Date: Fri, 2 Oct 2026 11:15:10 +0200 Subject: [PATCH 1/2] docs: dependencies housekeeping --- CONTRIBUTING.md | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index e721f35..1e8909c 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -29,3 +29,33 @@ mise run lint ``` CI runs the same command on every pull request and on every push to `main`. + +## Updating dependencies + +Keep dependencies fresh opportunistically: whenever you work on something, check its dependencies and apply the updates that don't break the build in the same pull request. Updates that need more work belong in a dedicated pull request. + +Only adopt a release once it has been published for at least 7 days. This cooldown leaves time for broken or compromised releases to be caught before they land here, so don't work around it. Only mise enforces it, for dev tools. For everything else, such as workflow actions, check the release date yourself. + +### Workflow actions + +Every `uses:` reference to an action or reusable workflow is pinned to a full commit SHA, followed by a comment with the version it resolves to: + +```yaml +uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0 +``` + +When you work on a workflow, check its `uses:` references for newer releases that are at least 7 days old. To bump one, update the SHA and the version comment together, and make sure the SHA is the commit the release tag points to. + +### Dev tools + +Dev tools (e.g. actionlint, shellcheck, ...) are managed with [mise](https://mise.jdx.dev). Their configuration is committed: `mise.toml`, `mise.lock` and anything under `.mise/`. Upgrade them with: + +```sh +mise upgrade --bump +``` + +This bumps the versions in `mise.toml` and refreshes `mise.lock` along with its sidecar files under `.mise/`. Commit all of them. + +mise enforces the 7-day cooldown through `minimum_release_age = "7d"` in `mise.toml`. + +When you work on the repository, run `mise outdated --bump` to check the dev tools. From e9340c496ceace189ae5f3344ee671f98110fe91 Mon Sep 17 00:00:00 2001 From: Pierre Jeanjacquot <26487010+PierreJeanjacquot@users.noreply.github.com> Date: Fri, 2 Oct 2026 11:21:47 +0200 Subject: [PATCH 2/2] chore: remove non operational renovate config renovate config is currently not working and could trick a contributor into thinking that deps bump just works --- renovate.json | 6 ------ 1 file changed, 6 deletions(-) delete mode 100644 renovate.json diff --git a/renovate.json b/renovate.json deleted file mode 100644 index 103eee7..0000000 --- a/renovate.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "$schema": "https://docs.renovatebot.com/renovate-schema.json", - "extends": [ - "local>iExecBlockchainComputing/renovate-config" - ] -}