Skip to content

[FEATURE] - Regression guards for dependency upgrades (runtime drift, DB volume upgrades, split bumps) #183

Description

@koydas

Problem to solve

Reviewing the first wave of Dependabot version updates (ADR-004, #154) surfaced gaps where CI stays green while production can break:

  1. Runtime drift — service tests run on a hard-coded runtime that differs from the Docker image actually shipped: CI Node 20/22 vs node:26-alpine images, CI Python 3.10 vs python:3.11-slim. Dependabot bumps Dockerfiles but never the workflow versions, so the drift grows with each update.
  2. Database major upgrades on existing data — smoke always starts databases on an empty volume. A major that cannot open an existing data directory (e.g. PostgreSQL majors, a Mongo FCV mismatch, a postgres:18 volume path change) passes CI and fails in production (chore(deps): bump mssql/server from 2022-latest to 2025-latest #156, chore(deps): bump mongo from 7 to 8 in /databases/mongo-db #159, chore(deps): bump mssql/server from 2022-latest to 2025-latest in /databases/mssql #160).
  3. Split coupled bumps — react/react-dom (chore(deps): bump react and @types/react in /client #175, chore(deps): bump react-dom and @types/react-dom in /client #179) and Microsoft.EntityFrameworkCore* (Bump Microsoft.EntityFrameworkCore from 8.0.8 to 9.0.20 #176, Bump Microsoft.EntityFrameworkCore.Design from 8.0.8 to 9.0.20 #178, Bump Microsoft.EntityFrameworkCore.SqlServer from 8.0.8 to 9.0.20 #180) arrive as separate PRs that can never pass on their own.

Impact

High

Proposed solution

  1. Service test jobs read their runtime version from the service Dockerfile instead of hard-coding it, plus a check (.devops/tests/consistency) that fails if a service test job hard-codes node-version / python-version / dotnet-version again.
  2. A db-upgrade-tests workflow on PRs touching databases/** or docker-compose.yml: start the base-branch image on a volume, write a probe record, restart the PR image on the same volume, assert the probe is readable (mongo, postgres, mssql Dockerfile, root compose mssql image).
  3. Dependabot groups for react* / @types/react* and Microsoft.EntityFrameworkCore*.

Constraints or notes

  • The DB upgrade test detects upgrades that break startup or data access; it does not detect that a successful upgrade is irreversible (e.g. SQL Server 2022 → 2025). That stays a review concern.
  • smoke / playwright-e2e runner Node versions only run the test harness, not the services; out of scope.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions