Skip to content

fix: suppress dependabot security updates for all test fixture manifests - #613

Merged
Strum355 merged 1 commit into
mainfrom
nsc/dependabot-script
Oct 6, 2026
Merged

Strum355 merged 1 commit into
mainfrom
nsc/dependabot-script

Conversation

@Strum355

@Strum355 Strum355 commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Replace root-level directory: "/" entries (which only match the repo root) with explicit per-directory listings for every ecosystem. This is the only approach that reliably suppresses both version and security update PRs — confirmed by 5+ months of data on the JS client.

Add scripts/sync-dependabot-config.sh to auto-generate the fixture entries from a scan of src/test/, and a CI check in the PR workflow to catch missing entries when new fixtures are added.

Summary by Sourcery

Ensure all test fixture manifests are explicitly excluded from Dependabot updates and keep the exclusions synchronized automatically.

New Features:

  • Add automatic generation of Dependabot suppression entries for all test fixture manifest directories.
  • Add CI validation to ensure Dependabot coverage stays synchronized with test fixtures.

Bug Fixes:

  • Suppress both version and security Dependabot updates for dependencies declared in test fixtures across supported ecosystems.

Enhancements:

  • Document the generated Dependabot configuration workflow and fixture coverage requirements.

CI:

  • Run the Dependabot configuration coverage check in the pull request workflow.

Documentation:

  • Update test fixture conventions to require explicit Dependabot suppression coverage and describe the synchronization script.

Chores:

  • Replace root-level test-fixture suppression rules with explicit per-directory entries for each detected ecosystem.

Replace root-level `directory: "/"` entries (which only match the repo
root) with explicit per-directory listings for every ecosystem. This is
the only approach that reliably suppresses both version and security
update PRs — confirmed by 5+ months of data on the JS client.

Add `scripts/sync-dependabot-config.sh` to auto-generate the fixture
entries from a scan of `src/test/`, and a CI check in the PR workflow
to catch missing entries when new fixtures are added.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@Strum355
Strum355 requested review from a-oren and ruromero October 6, 2026 11:38
@sourcery-ai

sourcery-ai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Reviewer's Guide

The PR changes Dependabot suppression from unreliable root-level entries to explicitly generated per-directory entries for all test-fixture ecosystems, with a synchronization script, PR CI drift check, and updated contributor guidance.

Flow diagram for generated Dependabot fixture suppression

flowchart LR
    Fixtures["src/test manifests"] --> Scanner["sync-dependabot-config.sh"]
    Scanner --> Config[".github/dependabot.yml"]
    Config --> Suppression["Per-directory ignore-all entries"]
    Fixtures --> CICheck["PR workflow --check"]
    Config --> CICheck
    CICheck --> Result["Pass or report configuration drift"]
Loading

File-Level Changes

Change Details Files
Replace root-level ignore-all Dependabot entries with generated, explicit fixture-directory suppressions across all supported ecosystems.
  • Retain production Maven configuration separately while adding monthly, zero-PR, ignore-all entries for each discovered fixture directory.
  • Cover Cargo, Go modules, Gradle, Maven, npm, pip, and uv manifests, including workspace module directories.
  • Add generated-section markers and update the Maven fixture list for newly discovered manifests.
.github/dependabot.yml
Automate Dependabot fixture coverage generation and detect configuration drift.
  • Scan src/test for recognized manifest filenames and map them to Dependabot ecosystems.
  • Generate sorted per-ecosystem directory entries in update mode.
  • Validate the generated section against the committed configuration in --check mode.
scripts/sync-dependabot-config.sh
Enforce generated Dependabot coverage in pull-request CI.
  • Add a dedicated verification job that checks out the repository and runs the synchronization script in check mode.
.github/workflows/pr.yml
Document the new explicit-list and regeneration workflow for test fixtures.
  • Require every fixture manifest directory to be listed with an ignore-all rule.
  • Document the regeneration command and CI enforcement.
CONVENTIONS.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="scripts/sync-dependabot-config.sh" line_range="127" />
<code_context>
+before=$(sed -n "1,/^${BEGIN_MARKER}/{ /^${BEGIN_MARKER}/d; p; }" "$DEPENDABOT_YML")
+tmpfile=$(mktemp)
+trap 'rm -f "$tmpfile"' EXIT
+printf '%s\n%s\n' "$before" "$generated" > "$tmpfile"
+
+if $check_mode; then
</code_context>
<issue_to_address>
**Check mode reports a false difference**

When the checked-in config has a blank line before the `BEGIN` marker, the `before=$(sed ...)` command substitution strips trailing newlines, so the temporary file loses that blank line and `--check` reports the config as out of date, failing the PR check.

Preserve the prefix’s trailing newlines when constructing the temporary file.
</issue_to_address>

Sourcery assessment

Needs a human reviewer. 1 finding to address first, and if the generated paths or suppression policy are wrong, Dependabot may stop reporting security updates for fixture dependencies or generate unwanted updates for other manifests, and alerts missed during that period are not automatically recovered by reverting. The affected dependencies are test fixtures rather than production data or access, and the configuration can be corrected and regenerated.

Blocking findings: scripts/sync-dependabot-config.sh:127


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Comment thread scripts/sync-dependabot-config.sh
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Test Results

615 tests   615 ✅  1m 31s ⏱️
 38 suites    0 💤
 38 files      0 ❌

Results for commit aaa9240.

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (main@25079fa). Learn more about missing BASE report.

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##             main     #613   +/-   ##
=======================================
  Coverage        ?   69.99%           
  Complexity      ?     1071           
=======================================
  Files           ?       66           
  Lines           ?     4436           
  Branches        ?      786           
=======================================
  Hits            ?     3105           
  Misses          ?      986           
  Partials        ?      345           
Flag Coverage Δ
integration-tests 69.99% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@Strum355
Strum355 merged commit 7ba337f into main Oct 6, 2026
43 of 46 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants