Skip to content

Dependabot: one grouped PR per directory, after a five-day cooldown - #846

Merged
irparent merged 1 commit into
mainfrom
ci/dependabot-grouped
Oct 5, 2026
Merged

irparent merged 1 commit into
mainfrom
ci/dependabot-grouped

Conversation

@irparent

@irparent irparent commented Oct 5, 2026

Copy link
Copy Markdown
Member

What changes

From 10-01 to 10-05, 266 of 1,000 Actions runs were on Dependabot branches: 31 branches, 21 re-pushes, each running about 73 checks. The resulting batches were then merged by hand.

Before Now
Minor and patch updates a PR per package outside a few named groups one grouped PR per directory per week (a catch-all after the named groups); majors stay separate
Brand-new releases proposed the day they publish a five-day cooldown, which also keeps a release pulled within days of publishing, the usual shape of a compromised package, from reaching a PR
Tools only CI uses (real clients, the Python build tools, the Docker base image) weekly monthly
Directories CI installs from the OpenTelemetry recipes (npm and pip) and the Python client were not watched monthly, one grouped PR each

Every existing ignore rule and named group is unchanged.

Tests

  • The file parses, and each of the 12 blocks has its schedule, cooldown and groups as listed above.
  • npm run preflight passed on this commit.

🤖 Generated with Claude Code

…ooldown

From 10-01 to 10-05, 266 of 1,000 Actions runs were on Dependabot
branches (31 branches, 21 re-pushes), each running about 73 checks, and
the batches were then merged by hand. Now:

- each directory groups its minor and patch updates into one PR (a
  catch-all after the named groups); majors stay separate;
- a five-day cooldown before a new release is proposed, which also keeps
  a release pulled within days of publishing from reaching a PR;
- the tools only CI uses (real clients, the Python build tools, the
  Docker base image) move to monthly;
- the three directories CI installs from that nothing watched get
  monthly, grouped updates: the OpenTelemetry recipes (npm and pip) and
  the Python client.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
website Ignored Ignored Oct 5, 2026 10:04pm UTC

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Iris gate — 1 of 2 tripped --fail-on detector_veto

iris-eval ingest: 3 stored, 1 tripped --fail-on detector_veto (2 of 3 evaluated in dataset "release-gate")

Trace Verdict Basis Rules, classes or missing inputs Evidence
decb4ccac96cc5fd8866a8449678106f failed detector_veto + risk_over_loss no_pii, pii_leak, credential_leak no_pii: AWS Access Key (output 45–65)
Verdict basis Traces
detector_veto 2
clean 1

Unjudged questions: task_completed (3), tool_use_correct (3) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/traces.ndjson · 3 evaluated · dataset release-gate: 2 in the gate · exit 1 · what the bases mean

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Iris gate — 1 stored, nothing tripped --fail-on any

iris-eval ingest: 1 stored, 0 tripped --fail-on any

Verdict basis Traces
clean 1

Unjudged questions: task_completed (1), tool_use_correct (1) — a trace that did not carry what a rule needs.

tests/fixtures/ci-gate/clean.ndjson · 1 evaluated · exit 0 · what the bases mean

@irparent
irparent merged commit a47543f into main Oct 5, 2026
74 checks passed
@irparent
irparent deleted the ci/dependabot-grouped branch October 5, 2026 22:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant