diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 7bd03239..daf7ca88 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -15,9 +15,18 @@ updates: schedule: interval: "weekly" groups: + # mache's thirteen pins move together in a pull request of their own. + # Its releases can change what a match plays: v0.6.0 moved the default + # book table, and the bump had to name scripts/book.sh to keep it. A + # bump grouped with the other actions would hide that line + mache: + patterns: + - "aywrite/mache*" actions: patterns: - "*" + exclude-patterns: + - "aywrite/mache*" # The workflows pin a commit sha with the version in a trailing comment, # because a tag is mutable and a release hands these actions a token that # can write to the repository and the package registry. Dependabot diff --git a/docs/DEVELOPMENT.md b/docs/DEVELOPMENT.md index df0f2f86..d8505020 100644 --- a/docs/DEVELOPMENT.md +++ b/docs/DEVELOPMENT.md @@ -607,6 +607,12 @@ its own. Both match workflows get them from its composite action, which also builds fastchess and fetches the books. What each tool computes, and why the pooling cannot be left to fastchess, is written there. +The workflows pin mache's actions at a commit, and Dependabot moves the pins in +a weekly pull request of their own. Read mache's changelog for a breaking line +before merging one. A breaking release changes what a match plays or how it is +read, and the bump then has to name the old behaviour where the workflows +relied on it, as the `book_table` inputs did at v0.6.0. + The release workflow calls Strength with five hundred games at 30+0.3 across five shards, about ninety minutes of wall clock, and that run is the only one that appends its result to the release notes. The slower control is the point: