Skip to content

docs(policy): always-current dependency updates + (updates) deed vocabulary - #1110

Merged
hyperpolymath merged 3 commits into
mainfrom
feat/always-current-update-policy
Oct 1, 2026
Merged

hyperpolymath merged 3 commits into
mainfrom
feat/always-current-update-policy

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Implements owner ruling D269 (#787 comment): the estate stays current by default, majors included, gated on a real build check.

What changes

  • docs/DEPENDABOT-POLICY.adoc is rewritten.
    • Majors auto-merge on green only where the base branch's effective rules carry a required build/test context.
    • Repos with required: [] are never armed. Arming there merges instantly; see cicd-squabbler#121.
    • Arming uses only GraphQL enablePullRequestAutoMerge (SQUASH), never gh pr merge --auto.
    • New sections: deed opt-out, changelog, failure feedback (marker-deduped issue), rollback (revert PR plus deed hold).
    • Fixed the grouped-hold example. A hold inside groups: must be an exclude-patterns entry, because ignore is not honoured there (48 open Dependabot PRs re-introduce the codeql-action v4.38.1 startup-killer, and the dependabot.yml ignore rule is being bypassed in 15 repos #1037).
    • An implementation-status table marks every unbuilt component (squabble bump/rollback, the reusable workflow, hypatia UG001/DA005, the render sweep) as specified, not built, so nobody reads the doc as describing live tooling.
  • 1-formats/deed/vocabulary/updates.adoc is new. It defines the (updates …) repo-deed clause: :enabled, :majors, :soak-days, (hold …), (exclude …).
    • The grammar is unchanged; this is a clause under deed.abnf v1.0.0.
    • Readers fail closed on unknown terms.
  • fixtures/valid/updates-clause_chora.deed exercises every term.
    • deed_lint.py --fixtures reports FIXTURES OK.
    • Negative control: :enabled true is rejected.
  • templates/cliff.toml gains a Dependencies group for chore(deps):, build(deps): and Dependabot's unprefixed Bump X from a to b. It sits before ^chore, since the first matching parser wins.
    • Tested with git-cliff 2.13.1.
    • Negative control: a chore(deps)x subject is not filed under Dependencies.

Not in this PR

The reusable workflow, the deed-read crate, squabbler bump/rollback, hypatia rules and the rsr-template caller follow as separate PRs, in the order the policy's status table lists.

🤖 Generated with Claude Code

https://claude.ai/code/session_019nbmPnyCN2ccVhiS7NZD1V

Implements owner ruling D269 (standards#787):

- DEPENDABOT-POLICY.adoc: majors auto-merge on green where the base branch
  has a required build/test context; repos with required: [] are never
  armed. Adds an implementation-status table (only this document, the
  vocabulary and the cliff group have landed), the deed opt-out, changelog,
  failure-feedback and rollback sections. Fixes the grouped-hold example:
  holds inside groups must be exclude-patterns (standards#1037).
- 1-formats/deed/vocabulary/updates.adoc: the (updates ...) repo-deed
  clause, with a fail-closed reader rule. No grammar change.
- fixtures/valid/updates-clause_chora.deed: exercises every term.
- templates/cliff.toml: a Dependencies group for chore(deps):,
  build(deps): and Dependabot's unprefixed "Bump X from a to b"; ahead of
  ^chore (first match wins). Tested with git-cliff 2.13.1 including a
  "chore(deps)x" negative control.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019nbmPnyCN2ccVhiS7NZD1V
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 8 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 7bd503a5-585e-47e1-a746-36cd5fad081a

📥 Commits

Reviewing files that changed from the base of the PR and between 2c06ddf and 574e078.

📒 Files selected for processing (4)
  • 1-formats/deed/tools/fixtures/valid/updates-clause_chora.deed
  • 1-formats/deed/vocabulary/updates.adoc
  • docs/DEPENDABOT-POLICY.adoc
  • templates/cliff.toml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

hyperpolymath added a commit to hyperpolymath/deed-ecosystem that referenced this pull request Oct 1, 2026
…#70)

## What

A new crate, `rs/deed-read`. It is its own Cargo root and does not touch
the legacy `a2ml` package in `rs/`.

- **`syntax`**: the parser for the normative DEED grammar, extracted
from `launch-scaffolder` `crates/launcher-common/src/deed.rs` @
`154b9b61` (#36), together with its vendored corpus and corpus tests.
The code is unchanged; only the header, the import path and added
one-line `///` docstrings (§5d) differ.
- **`updates`**: a reader for the `(updates …)` repo-deed clause, the
per-repo switch for automated dependency updates (ruling D269c; spec
`standards` `1-formats/deed/vocabulary/updates.adoc`,
hyperpolymath/standards#1110).
- It **fails closed**: an unknown, repeated, mistyped or missing term is
an error, and the caller then arms nothing.
  - No clause, or no deed, means the defaults.
- **`tests/hub_conformance.rs`** runs this hub's own
`conformance/*.deed`: the 4 valid deeds must parse and the 5 invalid
ones must be rejected. It also reads the updates fixture end to end.
Nothing is added to `conformance/`, because `run-deed-tests.sh` asserts
exact counts.
- **`.github/workflows/deed-read.yml`** runs test, clippy (`-D
warnings`) and docs (`-D warnings`).
- It reuses the checkout pin already used by this repo's other workflows
(`3d3c42e5…`, v7.0.1) with `persist-credentials: false`.
- It has no `paths:` filter, so the check can later be made required
without deadlocking unrelated PRs. It is **not** required now.

## Why

This is the deed reader for the always-current dependency pipeline
(D269). `cicd-squabbler`'s `squabble bump`/`rollback` and hypatia's
dependabot render sweep consume it, so the repo-deed toggle has one
parser rather than three.

## Verified locally (cargo 1.97.1)

- `cargo test --locked`: 44 passed, 0 failed.
- `cargo clippy --all-targets -D warnings`: clean.
- `cargo doc -D warnings`: clean.
- Mutation check: three hand-planted mutants were each killed by exactly
their own test:
  - ignoring unknown fields;
  - making `:reason` optional;
  - coercing non-booleans.

## Known windows (stated, not hidden)

- **Duplication with launch-scaffolder.** Until launch-scaffolder
replaces its `deed.rs` with a dependency on this crate, two copies
exist. Both are tested against the same `MANIFEST.sha256` corpus. That
swap is the follow-up.
- **Unmerged fixture.**
`tests/fixtures/deed/valid/updates-clause_chora.deed` is vendored from
**unmerged** hyperpolymath/standards#1110 (head `70e3e220`). If #1110
changes the fixture before it merges, refresh it here and regenerate
`MANIFEST.sha256`. The other files were re-checked byte-identical
against standards.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_019nbmPnyCN2ccVhiS7NZD1V

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 1, 2026 15:19
@hyperpolymath
hyperpolymath merged commit 1b6e19e into main Oct 1, 2026
50 checks passed
@hyperpolymath
hyperpolymath deleted the feat/always-current-update-policy branch October 1, 2026 15:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant