You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[FEATURE] - Adopt a "latest version" dependency policy (ADR-004) #154
Dependencies drift behind upstream. There is no .github/dependabot.yml, so only Dependabot security updates are active: PRs only appear when a CVE is published, pile up (11 open at once, some >30 days, which disables Dependabot auto-rebase), and conflict with each other on lockfiles. Major bumps (e.g. #147, Express 4 → 5) are treated as optional and left open, which makes the eventual migration larger and riskier.
Impact
Medium
Proposed solution
Record an explicit policy as ADR-004: Track latest dependency versions: every dependency across all stacks (npm, pip, NuGet, Docker base images, GitHub Actions) is kept on its latest stable release, majors included. Major bumps are migrated (code fixed + tests added) instead of ignored or pinned.
Scope of this issue:
docs/adr/ADR-004-latest-dependency-versions.md + link in README.md.
Follow-up (separate change): .github/dependabot.yml enabling version updates for all ecosystems, so the policy is enforced by automation.
Problem to solve
Dependencies drift behind upstream. There is no
.github/dependabot.yml, so only Dependabot security updates are active: PRs only appear when a CVE is published, pile up (11 open at once, some >30 days, which disables Dependabot auto-rebase), and conflict with each other on lockfiles. Major bumps (e.g. #147, Express 4 → 5) are treated as optional and left open, which makes the eventual migration larger and riskier.Impact
Medium
Proposed solution
Record an explicit policy as ADR-004: Track latest dependency versions: every dependency across all stacks (npm, pip, NuGet, Docker base images, GitHub Actions) is kept on its latest stable release, majors included. Major bumps are migrated (code fixed + tests added) instead of ignored or pinned.
Scope of this issue:
docs/adr/ADR-004-latest-dependency-versions.md+ link inREADME.md..github/dependabot.ymlenabling version updates for all ecosystems, so the policy is enforced by automation.apps-serviceto Express 5 (chore(deps): bump qs and express in /services/apps-service #147) —req.bodyisundefinedwithout a JSON body in Express 5, which turnsPOST /without body into a 500 instead of a 400.Constraints or notes