mirror of
https://github.com/Sea-Haven-Industries/engineering-handbook.git
synced 2026-10-07 16:19:06 +00:00
docs(deps): reconcile Renovate policy with exact-pin and ruleset names
This commit is contained in:
parent
e6ee6df952
commit
b8e53ec1c4
3 changed files with 7 additions and 5 deletions
|
|
@ -50,7 +50,7 @@ Why exact + automated: the exact pin plus the lockfile gives reproducible builds
|
|||
|
||||
aws-cdk-lib bundles transitive dependencies (`inBundle: true`) that npm `overrides` cannot patch. When a bundled dep has a vulnerability, the only fix is advancing to a release that bundles the patched version — treat the alert as a prompt to merge the next Renovate bump, never as something to dismiss indefinitely.
|
||||
|
||||
If a specific release is known-bad, exclude that version only with a `packageRules` entry in the repo's `renovate.json` (`matchPackageNames: ["aws-cdk-lib"], allowedVersions: "!/^2\\.254\\.0$/"`) with a comment explaining why, and remove the entry once a fixed release ships.
|
||||
If a specific release is known-bad, exclude that version only with a `packageRules` entry in the repo's `renovate.json` (`matchPackageNames: ["aws-cdk-lib"], allowedVersions: "!/^2\\.254\\.0$/"`), explain why in the rule's `description` field since `renovate.json` is strict JSON and cannot carry comments, and remove the entry once a fixed release ships.
|
||||
|
||||
When upgrading, verify on a branch first:
|
||||
|
||||
|
|
|
|||
|
|
@ -52,9 +52,9 @@ Renovate detects package files on its own (`package.json`, `requirements.txt`, `
|
|||
|
||||
Pins are for reproducibility, not for freezing time. The pinned version is kept current by Renovate PRs gated by CI and dependency review, never by a version number written in documentation.
|
||||
|
||||
- npm, pip, and Terraform providers keep semver ranges (`rangeStrategy: bump`); the lockfile is the pin. GitHub Actions are pinned to a full commit SHA with a `# vX.Y.Z` comment.
|
||||
- npm, pip, and Terraform providers keep whatever range style the repo already uses (`rangeStrategy: bump`): a caret range is bumped to a new caret range and an exact pin is bumped to a new exact pin. The lockfile is the pin for ranged dependencies. Dependencies under an explicit exact-pin policy, such as `aws-cdk-lib` (see [aws-infrastructure.md](aws-infrastructure.md#cdk-version-policy)), stay exact. GitHub Actions are pinned to a full commit SHA with a `# vX.Y.Z` comment.
|
||||
- Runtime and language versions (`node-version`, `python-version`, Terraform `required_version`, `.terraform-version`) are not bumped by Renovate.
|
||||
- Never add a blanket ignore for a dependency. If a specific release is broken, add a `packageRules` entry in the repo's `renovate.json` that excludes that version only, with a comment, and remove it once a fixed release ships.
|
||||
- Never add a blanket ignore for a dependency. If a specific release is broken, add a `packageRules` entry in the repo's `renovate.json` that excludes that version only, explain why in the rule's `description` field (`renovate.json` is strict JSON and cannot carry comments), and remove it once a fixed release ships.
|
||||
- Never dismiss a vulnerability alert as "waiting for upstream" without a linked follow-up that advances the pin when the fix ships.
|
||||
- If a bump PR fails CI, the gate worked. Leave the bad release unmerged and take the next one.
|
||||
|
||||
|
|
@ -108,13 +108,15 @@ Set them with `gh repo edit <repo> --add-topic a,b,c`. Adding topics is part of
|
|||
|
||||
## Required CI Status Check
|
||||
|
||||
Two org rulesets. A repo is on exactly one of them. Never both.
|
||||
Two org rulesets carry the required status check. A repo is on exactly one of them. Never both.
|
||||
|
||||
| Ruleset | Required check | Who |
|
||||
|---|---|---|
|
||||
| **main branch protection** | `ci / ci` | Unconverted remaining-lane repos |
|
||||
| **CI complete** | `ci-complete` | Converted HCP callers |
|
||||
|
||||
A third org ruleset, **main branch review**, carries the pull request rule (one approving review, squash only) for every repo except `shoc-backend`, `shoc-frontend-new`, `open-swe`, and `.github-private`. Each repo also has its own **main merge queue** ruleset.
|
||||
|
||||
`CI complete` starts with no repos. Flip include/unexclude in the same window as the workflow merge that lands `name: ci-complete`. Do not put portion names (`frontend / static`, `unit (1)`, `browser-smoke`) in a ruleset.
|
||||
|
||||
If the check name in the ruleset does not match what CI actually emits, merges will be blocked by a phantom required check. Verify after any change to CI job names.
|
||||
|
|
|
|||
|
|
@ -24,7 +24,7 @@ Each PR should represent a single logical change. If you find yourself writing "
|
|||
| `fix(auth): correct null check in session handler (PLAT-7)` | `Bug fix` |
|
||||
| `build: update Lambda runtime to Python 3.12 (DEV-88)` | `Updates` |
|
||||
|
||||
**Exemptions:** Renovate PRs and permission-controlled emergency reverts are the only PRs that may omit the Jira key suffix.
|
||||
**Exemptions:** Automated dependency-bot PRs (Renovate, and Dependabot security PRs on repos not yet Interactive in Renovate) and permission-controlled emergency reverts are the only PRs that may omit the Jira key suffix.
|
||||
|
||||
## Description
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue