Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
# Every ecosystem tracks its latest stable release, majors included.
# Minor/patch bumps are grouped per directory; majors get their own PR so the
# migration can be reviewed on its own, except packages that only resolve
# together (react, EF Core), which are always grouped.
# together (react, EF Core, dotnet images), which are always grouped.
# Held-back dependencies must be declared with an `ignore` rule here, with a
# comment giving the reason and the condition for removing it.
version: 2
Expand Down Expand Up @@ -55,6 +55,10 @@ updates:
- "/databases/postgre"
schedule:
interval: "weekly"
groups:
# The SDK (build stage) and ASP.NET runtime images must share a major.
dotnet-images:
patterns: ["dotnet/*"]

- package-ecosystem: "docker-compose"
directory: "/"
Expand Down
3 changes: 3 additions & 0 deletions docs/adr/ADR-004-latest-dependency-versions.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,9 @@ Every dependency is kept on its latest stable release, major versions included.
- Major version bumps are migrated, not ignored: the pull request is completed with the required code changes and tests covering any behavior change, then merged.
- A dependency may be held back only when no compatible migration path exists yet (for example an unreleased upstream fix). The exception is recorded in `.github/dependabot.yml` next to the `ignore` rule, with the reason and the condition for removing it.
- Pre-release versions (alpha, beta, rc) are out of scope.
- CI tests each service on the runtime version its Dockerfile ships (Node, Python, .NET), resolved by `.devops/runtime-version.js` and enforced by `.devops/tests/consistency/runtime-versions.test.js`. An image bump is therefore tested on the new runtime by its own pull request.
- Upgrades that only work together land together: coupled packages and images are grouped in `.github/dependabot.yml` (for example react with react-dom, EF Core packages, the `dotnet/*` images). When an update is still split, or also needs code or configuration changes (for example a `TargetFramework` bump), the split pull requests are closed in favor of one migration pull request that references them.
- Database images follow ADR-005: a major that changes the data format ships with a tested data migration.

# Consequences
Benefits: security fixes land without back-porting, migrations stay small and incremental, and lockfile conflicts between stale update pull requests are avoided. Costs: a steady stream of update pull requests to review (code owner review is required), and regular migration work on major releases that would otherwise be postponed. We accept these costs because a continuously current stack is cheaper to maintain than periodic large upgrades.
Loading