Skip to content

Wave 40: harden Dependabot Docker discovery - #405

Merged
ty-everett merged 1 commit into
mainfrom
codex/dependabot-docker-discovery
Jul 30, 2026
Merged

Wave 40: harden Dependabot Docker discovery#405
ty-everett merged 1 commit into
mainfrom
codex/dependabot-docker-discovery

Conversation

@ty-everett

@ty-everett ty-everett commented Jul 30, 2026

Copy link
Copy Markdown
Collaborator

Local and hosted validation are complete on the exact head. Every applicable check is terminal and successful; there are no unresolved findings or review threads.

Program and scope

Impact

  • No public package source or manifest changed
  • Public package source or manifest changed; affected packages are listed below
  • Infrastructure dependency automation configuration changed
  • Public API, exports, types, runtime targets, or browser/mobile behavior changed
  • Security-sensitive boundary changed
  • Documentation changed

Affected packages/services and intended patch versions: no package candidate changes; this is repository-only Dependabot policy and documentation.

Verification

  • Local commands and results: targeted container governance 5/5; pnpm health:check 113/113 with 0 findings/control errors; pnpm lint; pnpm format:check; pnpm typecheck; pnpm docs:build; pnpm audit:security all passed
  • Hosted CI run: CI 30569950897 completed successfully; every exact-head PR check is terminal and green
  • Conformance evidence: hosted structural and TypeScript conformance passed; no protocol or runtime behavior changed
  • Coverage delta: no coverable production source changed; the merge gate validated the scope-based coverage/platform skips
  • Lint/typecheck delta: zero warnings; TypeScript profiles pass
  • Browser/mobile/packed-consumer evidence: no package artifact changed; the merge gate validated the scope selection
  • Performance or bundle-size delta: no runtime or bundle path changed; measured impact is zero
  • I self-reviewed the complete diff for correctness, security, compatibility, public API, artifacts, dependencies, docs, and operations
  • All applicable checks are terminal and successful on the exact head

Security and dependencies

  • No dependency or lockfile change
  • The failed updater logs and GitHub's official exclude-paths behavior were reviewed
  • No trust boundary or runtime code changed; exact-head CodeQL still passed
  • The exact-head CodeQL analysis has no new alert
  • The exact-head repository quality gate and Sonar report show zero new issues, zero accepted issues, and zero unreviewed hotspots
  • No new override, advisory dismissal, quality suppression, or skipped test
  • No temporary exception is introduced
  • Workflow permissions and lifecycle-script behavior remain least privilege

Dependency evidence

  • Release notes and necessity: no dependency release; this fixes GitHub Dependabot discovery behavior observed on main
  • Runtime, build, and peer compatibility: no dependency or runtime version changes
  • Deduplicated lockfile: unchanged; no dependency graph changed
  • Audit and CodeQL: local high/critical audit is clean; exact-head Actions and JavaScript/TypeScript CodeQL passed
  • Package and consumer tests: no package bytes changed; full governance, build/test, and documentation validation passed
  • Bundle and performance impact: No runtime source, dependency, bundle, or performance path changed; measured impact is zero.
  • Affected public package versions: no public package version changes

Release and operations

  • No npm publication was performed from a workstation or from this PR
  • No npm patch bump is required because no package artifact changed
  • Image/SBOM/provenance/deployment/rollback impact is documented: runtime images and release controls are unchanged
  • Documentation and operator guidance are current

Completion evidence

  • Tracker [RETIRED] TypeScript stack health, security, standardization, testing, docs, and performance #324 will be retired only after this exact head is merged, main is green, and the managed Dependabot validation no longer reports the digest-only Node failure
  • Review conversations are resolved; the thread-aware audit found zero review threads and zero requested changes
  • Documentation and dependency-governance rationale are current
  • No pending or failed check is being handed off as complete
  • One qualified maintainer approval is sufficient; no last-pusher restriction is assumed

Fix boundary

  • Runtime Dockerfiles remain immutable digest-only build inputs.
  • governance/Dockerfile.container-bases remains the readable, versioned Node discovery source.
  • Dependabot continues monitoring deployment images, MySQL/Mongo patch/minor releases, code generators, GitHub Actions, root/infra npm dependencies, and security updates.
  • A zero-install repository-health test prevents the Dockerfile exclusion from drifting.

@ty-everett
ty-everett requested a review from sirdeggen as a code owner July 30, 2026 18:20
@sonarqubecloud

Copy link
Copy Markdown

@ty-everett ty-everett left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head maintainer self-review completed as ty-everett at 9b74e6cc19e199a674580ce54efe271eb33d88b1. GitHub prohibits an author from submitting an APPROVE review on their own PR, so this anchored review records the assessment without waiting for another maintainer. The three-file change is narrowly scoped: it excludes only digest-only runtime Dockerfiles from duplicate Dependabot discovery, retains the canonical versioned Node discovery manifest and all deployment/database/image monitoring, adds a zero-install regression assertion, and documents the boundary. All applicable local and hosted checks are terminal and green, with zero Sonar or CodeQL findings and no review threads.

@ty-everett
ty-everett merged commit 0e7dbc7 into main Jul 30, 2026
30 checks passed
@ty-everett
ty-everett deleted the codex/dependabot-docker-discovery branch July 30, 2026 18:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant