Skip to content

[FEATURE] - Adopt a "latest version" dependency policy (ADR-004) #154

Description

@koydas

Problem to solve

Dependencies drift behind upstream. There is no .github/dependabot.yml, so only Dependabot security updates are active: PRs only appear when a CVE is published, pile up (11 open at once, some >30 days, which disables Dependabot auto-rebase), and conflict with each other on lockfiles. Major bumps (e.g. #147, Express 4 → 5) are treated as optional and left open, which makes the eventual migration larger and riskier.

Impact

Medium

Proposed solution

Record an explicit policy as ADR-004: Track latest dependency versions: every dependency across all stacks (npm, pip, NuGet, Docker base images, GitHub Actions) is kept on its latest stable release, majors included. Major bumps are migrated (code fixed + tests added) instead of ignored or pinned.

Scope of this issue:

  1. docs/adr/ADR-004-latest-dependency-versions.md + link in README.md.
  2. Follow-up (separate change): .github/dependabot.yml enabling version updates for all ecosystems, so the policy is enforced by automation.
  3. Follow-up: migrate apps-service to Express 5 (chore(deps): bump qs and express in /services/apps-service #147) — req.body is undefined without a JSON body in Express 5, which turns POST / without body into a 500 instead of a 400.

Constraints or notes

  • Branch protection requires code owner review, so every Dependabot PR still needs an approval; auto-merge is disabled in repo settings.
  • Exceptions (pinning a version) must be documented with a reason and a revisit condition.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions