Repository navigation
fix: suppress dependabot security updates for all test fixture manifests - #613
Conversation
Replace root-level `directory: "/"` entries (which only match the repo root) with explicit per-directory listings for every ecosystem. This is the only approach that reliably suppresses both version and security update PRs — confirmed by 5+ months of data on the JS client. Add `scripts/sync-dependabot-config.sh` to auto-generate the fixture entries from a scan of `src/test/`, and a CI check in the PR workflow to catch missing entries when new fixtures are added. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Reviewer's GuideThe PR changes Dependabot suppression from unreliable root-level entries to explicitly generated per-directory entries for all test-fixture ecosystems, with a synchronization script, PR CI drift check, and updated contributor guidance. Flow diagram for generated Dependabot fixture suppressionflowchart LR
Fixtures["src/test manifests"] --> Scanner["sync-dependabot-config.sh"]
Scanner --> Config[".github/dependabot.yml"]
Config --> Suppression["Per-directory ignore-all entries"]
Fixtures --> CICheck["PR workflow --check"]
Config --> CICheck
CICheck --> Result["Pass or report configuration drift"]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="scripts/sync-dependabot-config.sh" line_range="127" />
<code_context>
+before=$(sed -n "1,/^${BEGIN_MARKER}/{ /^${BEGIN_MARKER}/d; p; }" "$DEPENDABOT_YML")
+tmpfile=$(mktemp)
+trap 'rm -f "$tmpfile"' EXIT
+printf '%s\n%s\n' "$before" "$generated" > "$tmpfile"
+
+if $check_mode; then
</code_context>
<issue_to_address>
**Check mode reports a false difference**
When the checked-in config has a blank line before the `BEGIN` marker, the `before=$(sed ...)` command substitution strips trailing newlines, so the temporary file loses that blank line and `--check` reports the config as out of date, failing the PR check.
Preserve the prefix’s trailing newlines when constructing the temporary file.
</issue_to_address>Sourcery assessment
Needs a human reviewer. 1 finding to address first, and if the generated paths or suppression policy are wrong, Dependabot may stop reporting security updates for fixture dependencies or generate unwanted updates for other manifests, and alerts missed during that period are not automatically recovered by reverting. The affected dependencies are test fixtures rather than production data or access, and the configuration can be corrected and regenerated.
Blocking findings: scripts/sync-dependabot-config.sh:127
Test Results615 tests 615 ✅ 1m 31s ⏱️ Results for commit aaa9240. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #613 +/- ##
=======================================
Coverage ? 69.99%
Complexity ? 1071
=======================================
Files ? 66
Lines ? 4436
Branches ? 786
=======================================
Hits ? 3105
Misses ? 986
Partials ? 345
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
Replace root-level
directory: "/"entries (which only match the repo root) with explicit per-directory listings for every ecosystem. This is the only approach that reliably suppresses both version and security update PRs — confirmed by 5+ months of data on the JS client.Add
scripts/sync-dependabot-config.shto auto-generate the fixture entries from a scan ofsrc/test/, and a CI check in the PR workflow to catch missing entries when new fixtures are added.Summary by Sourcery
Ensure all test fixture manifests are explicitly excluded from Dependabot updates and keep the exclusions synchronized automatically.
New Features:
Bug Fixes:
Enhancements:
CI:
Documentation:
Chores: