From 64c1bc4fbfcf72407aadc8b0fe50cf136dce29aa Mon Sep 17 00:00:00 2001 From: Claude Date: Sun, 4 Oct 2026 09:44:45 +0000 Subject: [PATCH] ci(ci): Give the mache pins a Dependabot pull request of their own The workflows pin mache's actions at thirteen places, and the last three moves of those pins were made by hand. Dependabot already watches the actions, but it put every action in one weekly group, so a mache bump would have arrived beside unrelated ones. That matters because mache's releases can change what a match plays: v0.6.0 moved the default book table, and the hand bump had to add six book_table lines to keep the table the engine's book input describes. mache now has a group of its own and is excluded from the rest. The development doc says to read mache's changelog for a breaking line before merging one. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01MStzRapxqqqByoFQmfA69p --- .github/dependabot.yml | 9 +++++++++ docs/DEVELOPMENT.md | 6 ++++++ 2 files changed, 15 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 7bd03239..daf7ca88 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -15,9 +15,18 @@ updates: schedule: interval: "weekly" groups: + # mache's thirteen pins move together in a pull request of their own. + # Its releases can change what a match plays: v0.6.0 moved the default + # book table, and the bump had to name scripts/book.sh to keep it. A + # bump grouped with the other actions would hide that line + mache: + patterns: + - "aywrite/mache*" actions: patterns: - "*" + exclude-patterns: + - "aywrite/mache*" # The workflows pin a commit sha with the version in a trailing comment, # because a tag is mutable and a release hands these actions a token that # can write to the repository and the package registry. Dependabot diff --git a/docs/DEVELOPMENT.md b/docs/DEVELOPMENT.md index df0f2f86..d8505020 100644 --- a/docs/DEVELOPMENT.md +++ b/docs/DEVELOPMENT.md @@ -607,6 +607,12 @@ its own. Both match workflows get them from its composite action, which also builds fastchess and fetches the books. What each tool computes, and why the pooling cannot be left to fastchess, is written there. +The workflows pin mache's actions at a commit, and Dependabot moves the pins in +a weekly pull request of their own. Read mache's changelog for a breaking line +before merging one. A breaking release changes what a match plays or how it is +read, and the bump then has to name the old behaviour where the workflows +relied on it, as the `book_table` inputs did at v0.6.0. + The release workflow calls Strength with five hundred games at 30+0.3 across five shards, about ninety minutes of wall clock, and that run is the only one that appends its result to the release notes. The slower control is the point: