Wave 40: harden Dependabot Docker discovery - #405
Conversation
|
ty-everett
left a comment
There was a problem hiding this comment.
Exact-head maintainer self-review completed as ty-everett at 9b74e6cc19e199a674580ce54efe271eb33d88b1. GitHub prohibits an author from submitting an APPROVE review on their own PR, so this anchored review records the assessment without waiting for another maintainer. The three-file change is narrowly scoped: it excludes only digest-only runtime Dockerfiles from duplicate Dependabot discovery, retains the canonical versioned Node discovery manifest and all deployment/database/image monitoring, adds a zero-install regression assertion, and documents the boundary. All applicable local and hosted checks are terminal and green, with zero Sonar or CodeQL findings and no review threads.



Program and scope
nodebases and ended withdocker/library/node unknown_error9b74e6cc19e199a674580ce54efe271eb33d88b1Impact
Affected packages/services and intended patch versions: no package candidate changes; this is repository-only Dependabot policy and documentation.
Verification
pnpm health:check113/113 with 0 findings/control errors;pnpm lint;pnpm format:check;pnpm typecheck;pnpm docs:build;pnpm audit:securityall passedSecurity and dependencies
exclude-pathsbehavior were reviewedDependency evidence
mainRelease and operations
Completion evidence
mainis green, and the managed Dependabot validation no longer reports the digest-only Node failureFix boundary
governance/Dockerfile.container-basesremains the readable, versioned Node discovery source.