Skip to content

ADR-004 latest dependency versions: Dependabot version updates + Express 5 migration - #155

Merged
koydas merged 3 commits into
mainfrom
claude/dependabot-pr-review-14fhe1
Sep 26, 2026
Merged

koydas merged 3 commits into
mainfrom
claude/dependabot-pr-review-14fhe1

Conversation

@koydas

@koydas koydas commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Closes #154. Supersedes #147.

Changes

  • ADR-004 (docs/adr/ADR-004-latest-dependency-versions.md, linked in README.md): every dependency tracks its latest stable release, majors included; majors are migrated, not ignored; held-back dependencies must be documented next to an ignore rule.
  • .github/dependabot.yml: enables weekly version updates for npm (/, client, apps-service, agent-service), pip, NuGet, Docker (8 directories), docker-compose and GitHub Actions. Minor/patch grouped per ecosystem; majors get their own PR. Validated against the SchemaStore schema.
  • apps-service → Express 5.2.1: Express 5 leaves req.body undefined when a request has no parsable body, which turned POST /api/apps without body into a 500 (TypeError in createApp's destructuring) instead of 400. Route handler now passes req.body ?? {}; new HTTP-level tests in tests/appsRoutes.test.js (fails on Express 5 without the fix, passes with it). 19/19 apps-service tests pass; lockfile resolves only from registry.npmjs.org, no install scripts, npm audit clean.

Expected follow-ups once merged

Dependabot will open major-version PRs that need manual handling:

  • .NET 8 → 10: image and EF Core bumps will fail CI until TargetFramework is migrated in the same PR.
  • postgres:16, mongo:7, mssql:2022-latest: engine majors require a data migration (pg_upgrade, Mongo FCV); CI starts from empty volumes and won't catch it.

Checklist

  • All CI checks pass
  • README.md updated if behaviour changed
  • ADR created or updated if an architectural decision was made
  • New service registered in discover-services.js and smoke tests added if applicable — N/A, no new service

🤖 Generated with Claude Code

https://claude.ai/code/session_01HcKxmDJ1KBXLKgbTxp7Wtx

Record the policy of keeping every dependency on its latest stable
release, majors included, enforced by Dependabot version updates.

Refs #154

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HcKxmDJ1KBXLKgbTxp7Wtx
Enforce ADR-004: weekly version updates for npm, pip, NuGet, Docker,
docker-compose and GitHub Actions. Minor/patch bumps are grouped per
directory; majors get their own PR.

Refs #154

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HcKxmDJ1KBXLKgbTxp7Wtx
Upgrade express 4.22 -> 5.2.1 (supersedes Dependabot #147), per ADR-004.

Express 5 leaves req.body undefined when a request has no parsable
body, which made POST /api/apps without a body crash in createApp's
destructuring and return 500 instead of 400. Default the body to {} in
the route handler and cover both no-body and empty-JSON cases with
HTTP-level tests.

Refs #154

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HcKxmDJ1KBXLKgbTxp7Wtx
@koydas koydas changed the title docs(adr): add ADR-004 track latest dependency versions ADR-004 latest dependency versions: Dependabot version updates + Express 5 migration Sep 26, 2026
@koydas
koydas merged commit 7cedbd0 into main Sep 26, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FEATURE] - Adopt a "latest version" dependency policy (ADR-004)

2 participants