Skip to content

Group Dependabot updates with a 14-day cooldown - #1907

Merged
Bill Schnurr (bschnurr) merged 1 commit into
microsoft:mainfrom
bschnurr:bschnurr/dependabot-cooldown-14d
Oct 9, 2026
Merged

Bill Schnurr (bschnurr) merged 1 commit into
microsoft:mainfrom
bschnurr:bschnurr/dependabot-cooldown-14d

Conversation

@bschnurr

Copy link
Copy Markdown
Member

Summary

  • Keep GitHub Actions dependency updates grouped into a single Dependabot PR
  • Increase the default cooldown from 7 to 14 days

The delay follows the supply-chain hardening pattern used by python/cpython-devcontainers and avoids the highest-risk window immediately after a new dependency release.

Validation

  • Parsed the YAML configuration successfully
  • Verified the GitHub Actions entry uses a wildcard group
  • Verified cooldown.default-days: 14
  • git diff --check

Co-authored-by: Copilot <[email protected]>

Copilot-Session: ce6aeb0a-6210-4716-8a84-2f3e7555625f
@bschnurr Bill Schnurr (bschnurr) added the debt Code quality issues label Oct 7, 2026
@bschnurr
Bill Schnurr (bschnurr) enabled auto-merge (squash) October 8, 2026 22:46
@heejaechang

Copy link
Copy Markdown

🔒 Automated review in progress — Heejae Chang (@heejaechang) is auto-reviewing this PR.

@heejaechang

Copy link
Copy Markdown

Result: ⚠️ partially-verified

Verification details

Verification: Isolated verification observed failures that were not classified as caused by this PR: Dependency and test discovery.

Summary: Container checks passed: the YAML parses, GitHub Actions retains its weekly schedule and wildcard group, and the cooldown is integer 14. No relevant existing tests were found under src/test, and the PR adds none. Git-based discovery and diff validation failed because the container lacks Git metadata. Static configuration checks passed, but live Dependabot behavior was not exercised.

Test runs: 1 passed, 1 failed

  • ❌ Failed | unrelated to this PR | Dependency and test discovery | printf 'Sandbox profile: %s\n' "$AUTOMATION_SANDBOX_PROFILE"; git diff HEAD^ HEAD --stat; git diff HEAD^ HEAD -- .github/dependabot.yml; python -c "import importlib.util; print('PyYAML available:', importlib.util.find_spec('yaml') is not None)"; git grep -n -i -E 'dependabot|cooldown' -- .github src/test scripts package.json || test "$?" -eq 1
  • ✅ Passed | Dependabot configuration assertions | python - <<'PY'
    from pathlib import Path
    import yaml

path = Path('.github/dependabot.yml')
text = path.read_text()
config = yaml.safe_load(text)
assert config['version'] == 2, config
assert len(config['updates']) == 1, config['updates']
update = config['updates'][0]
assert update['package-ecosystem'] == 'github-actions', update
assert update['directory'] == '/', update
assert update['schedule'] == {'interval': 'weekly'}, update['schedule']
assert update['groups'] == {'github-actions': {'patterns': ['*']}}, update['groups']
assert update['cooldown'] == {'default-days': 14}, update['cooldown']
assert type(update['cooldown']['default-days']) is int
assert all(line == line.rstrip() for line in text.splitlines()), 'Trailing whitespace'
assert text.endswith('\n'), 'Missing final newline'
print('PASS: YAML parses; Dependabot version 2; single GitHub Actions entry at root')
print('PASS: weekly schedule and single wildcard group preserved')
print('PASS: cooldown.default-days is integer 14')
print('PASS: no trailing whitespace; final newline present')
PY

❌ Dependency and test discovery diagnostic output
Sandbox profile: typescript
error: Could not access 'HEAD^'
warning: Not a git repository.
PyYAML available: True
fatal: not a git repository (or any parent up to mount point /)
[container exit=1]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved via Review Center.

@heejaechang Heejae Chang (heejaechang) added the review-auto:approved Automated review: no blocking findings (approval posted). label Oct 9, 2026
@bschnurr
Bill Schnurr (bschnurr) merged commit 7c894fc into microsoft:main Oct 9, 2026
77 of 79 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

debt Code quality issues review-auto:approved Automated review: no blocking findings (approval posted).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants