diff --git a/.github/dependabot.yml b/.github/dependabot.yml index e84d530..00fec5f 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -2,7 +2,7 @@ # Every ecosystem tracks its latest stable release, majors included. # Minor/patch bumps are grouped per directory; majors get their own PR so the # migration can be reviewed on its own, except packages that only resolve -# together (react, EF Core), which are always grouped. +# together (react, EF Core, dotnet images), which are always grouped. # Held-back dependencies must be declared with an `ignore` rule here, with a # comment giving the reason and the condition for removing it. version: 2 @@ -55,6 +55,10 @@ updates: - "/databases/postgre" schedule: interval: "weekly" + groups: + # The SDK (build stage) and ASP.NET runtime images must share a major. + dotnet-images: + patterns: ["dotnet/*"] - package-ecosystem: "docker-compose" directory: "/" diff --git a/docs/adr/ADR-004-latest-dependency-versions.md b/docs/adr/ADR-004-latest-dependency-versions.md index f8c4bcc..f5462a7 100644 --- a/docs/adr/ADR-004-latest-dependency-versions.md +++ b/docs/adr/ADR-004-latest-dependency-versions.md @@ -14,6 +14,9 @@ Every dependency is kept on its latest stable release, major versions included. - Major version bumps are migrated, not ignored: the pull request is completed with the required code changes and tests covering any behavior change, then merged. - A dependency may be held back only when no compatible migration path exists yet (for example an unreleased upstream fix). The exception is recorded in `.github/dependabot.yml` next to the `ignore` rule, with the reason and the condition for removing it. - Pre-release versions (alpha, beta, rc) are out of scope. +- CI tests each service on the runtime version its Dockerfile ships (Node, Python, .NET), resolved by `.devops/runtime-version.js` and enforced by `.devops/tests/consistency/runtime-versions.test.js`. An image bump is therefore tested on the new runtime by its own pull request. +- Upgrades that only work together land together: coupled packages and images are grouped in `.github/dependabot.yml` (for example react with react-dom, EF Core packages, the `dotnet/*` images). When an update is still split, or also needs code or configuration changes (for example a `TargetFramework` bump), the split pull requests are closed in favor of one migration pull request that references them. +- Database images follow ADR-005: a major that changes the data format ships with a tested data migration. # Consequences Benefits: security fixes land without back-porting, migrations stay small and incremental, and lockfile conflicts between stale update pull requests are avoided. Costs: a steady stream of update pull requests to review (code owner review is required), and regular migration work on major releases that would otherwise be postponed. We accept these costs because a continuously current stack is cheaper to maintain than periodic large upgrades.