You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Reviewing the first wave of Dependabot version updates (ADR-004, #154) surfaced gaps where CI stays green while production can break:
Runtime drift — service tests run on a hard-coded runtime that differs from the Docker image actually shipped: CI Node 20/22 vs node:26-alpine images, CI Python 3.10 vs python:3.11-slim. Dependabot bumps Dockerfiles but never the workflow versions, so the drift grows with each update.
Service test jobs read their runtime version from the service Dockerfile instead of hard-coding it, plus a check (.devops/tests/consistency) that fails if a service test job hard-codes node-version / python-version / dotnet-version again.
A db-upgrade-tests workflow on PRs touching databases/** or docker-compose.yml: start the base-branch image on a volume, write a probe record, restart the PR image on the same volume, assert the probe is readable (mongo, postgres, mssql Dockerfile, root compose mssql image).
Dependabot groups for react* / @types/react* and Microsoft.EntityFrameworkCore*.
Constraints or notes
The DB upgrade test detects upgrades that break startup or data access; it does not detect that a successful upgrade is irreversible (e.g. SQL Server 2022 → 2025). That stays a review concern.
smoke / playwright-e2e runner Node versions only run the test harness, not the services; out of scope.
Problem to solve
Reviewing the first wave of Dependabot version updates (ADR-004, #154) surfaced gaps where CI stays green while production can break:
node:26-alpineimages, CI Python 3.10 vspython:3.11-slim. Dependabot bumps Dockerfiles but never the workflow versions, so the drift grows with each update.smokealways starts databases on an empty volume. A major that cannot open an existing data directory (e.g. PostgreSQL majors, a Mongo FCV mismatch, apostgres:18volume path change) passes CI and fails in production (chore(deps): bump mssql/server from 2022-latest to 2025-latest #156, chore(deps): bump mongo from 7 to 8 in /databases/mongo-db #159, chore(deps): bump mssql/server from 2022-latest to 2025-latest in /databases/mssql #160).react/react-dom(chore(deps): bump react and @types/react in /client #175, chore(deps): bump react-dom and @types/react-dom in /client #179) andMicrosoft.EntityFrameworkCore*(Bump Microsoft.EntityFrameworkCore from 8.0.8 to 9.0.20 #176, Bump Microsoft.EntityFrameworkCore.Design from 8.0.8 to 9.0.20 #178, Bump Microsoft.EntityFrameworkCore.SqlServer from 8.0.8 to 9.0.20 #180) arrive as separate PRs that can never pass on their own.Impact
High
Proposed solution
.devops/tests/consistency) that fails if a service test job hard-codesnode-version/python-version/dotnet-versionagain.db-upgrade-testsworkflow on PRs touchingdatabases/**ordocker-compose.yml: start the base-branch image on a volume, write a probe record, restart the PR image on the same volume, assert the probe is readable (mongo, postgres, mssql Dockerfile, root compose mssql image).react*/@types/react*andMicrosoft.EntityFrameworkCore*.Constraints or notes
smoke/playwright-e2erunner Node versions only run the test harness, not the services; out of scope.