Category: DevOps, CI/CD & Observability
Description: Improve .github/dependabot.yml and scripts/check-dependencies.mjs into a full policy: grouped updates, auto-merge of low-risk updates only when CI is green, mandatory extra checks for wallet/crypto-related packages and automated release-note/breaking-change summaries.
Problem Statement & Context: Dependency PR noise leads to neglect, and neglected dependencies (Next.js, Stellar SDK, Freighter API) become security debt; conversely, blindly merging crypto-adjacent updates is dangerous.
Scope & Acceptance Criteria:
- Dependabot grouping (dev tooling, testing, next/react, stellar) with schedule and ignore rules documented; GitHub Actions versions updated too and pinned by SHA.
- Auto-merge workflow: patch/minor updates of dev-only dependencies auto-merge after required checks pass; production and crypto-related packages (
@stellar/*, next, react) require human review with an auto-generated checklist comment (changelog links, diff of package-lock, install-scripts diff, provenance status).
check-dependencies.mjs extended: new/changed install scripts detection, maintainer/ownership change heuristics (when data available), license policy, and a machine-readable report artifact.
- Policy doc (
docs/dependency-policy.md) covering criteria, SLAs (critical advisories patched within N days) and an emergency-update runbook; weekly scheduled npm audit summary issue.
- Out of scope: vendoring dependencies.
Implementation Guidelines (Suggested Execution):
- Key Files/Modules:
.github/dependabot.yml, scripts/check-dependencies.mjs, new .github/workflows/dependabot-automerge.yml, SECURITY.md.
- Design/Architecture: Decision logic in a pure module (
classifyUpdate(pkg, from, to, type) → auto|review|block) with fixtures.
- Edge Cases/Constraints:
pull_request_target security (only use dependabot/fetch-metadata, no checkout of PR code with secrets), major bumps, peer dependency conflicts, lockfile-only changes.
- Testing: Table tests for the classifier; workflow linted with
actionlint; evidence from a dry-run on a sample Dependabot PR.
Definition of "Done": Baseline DoD, plus documented policy and evidence of an auto-merged and a human-review PR path.
Resources: Dependabot grouping docs, dependabot/fetch-metadata action docs.
Complexity: High (200 points)
Baseline Definition of Done (applies to every Wave issue)
Each issue's own "Definition of Done" is in addition to this baseline:
- Code, tests and documentation are included in one PR that references the issue.
npm run lint, npm run typecheck, npm test, npm run check:i18n and npm run check:editorconfig pass locally and in CI. (If a command is broken by pre-existing repo debris, see the Repository Health & Build Integrity issues — do not silence the check; note the blocker in the PR.)
- No new
any, no // @ts-ignore / eslint-disable without a justification comment, and no new console.* (use secureLogger from src/lib/secureLogging.ts).
- All new user-facing strings go through the i18n catalog (
src/lib/i18n/messages/en.ts and es.ts).
- New interactive UI is keyboard-operable, has visible focus, correct ARIA semantics, and works in both the dark and light palettes defined in
src/app/globals.css.
- UI changes include before/after screenshots (desktop and ~400px mobile). Behaviour changes include a short screen recording or test output.
- Relevant docs under
docs/ (and README.md if routes/scripts/env vars change) are updated.
- The PR is reviewed and approved by a maintainer listed in
.github/CODEOWNERS.
Category: DevOps, CI/CD & Observability
Description: Improve
.github/dependabot.ymlandscripts/check-dependencies.mjsinto a full policy: grouped updates, auto-merge of low-risk updates only when CI is green, mandatory extra checks for wallet/crypto-related packages and automated release-note/breaking-change summaries.Problem Statement & Context: Dependency PR noise leads to neglect, and neglected dependencies (Next.js, Stellar SDK, Freighter API) become security debt; conversely, blindly merging crypto-adjacent updates is dangerous.
Scope & Acceptance Criteria:
@stellar/*,next,react) require human review with an auto-generated checklist comment (changelog links, diff ofpackage-lock, install-scripts diff, provenance status).check-dependencies.mjsextended: new/changed install scripts detection, maintainer/ownership change heuristics (when data available), license policy, and a machine-readable report artifact.docs/dependency-policy.md) covering criteria, SLAs (critical advisories patched within N days) and an emergency-update runbook; weekly schedulednpm auditsummary issue.Implementation Guidelines (Suggested Execution):
.github/dependabot.yml,scripts/check-dependencies.mjs, new.github/workflows/dependabot-automerge.yml,SECURITY.md.classifyUpdate(pkg, from, to, type)→auto|review|block) with fixtures.pull_request_targetsecurity (only usedependabot/fetch-metadata, no checkout of PR code with secrets), major bumps, peer dependency conflicts, lockfile-only changes.actionlint; evidence from a dry-run on a sample Dependabot PR.Definition of "Done": Baseline DoD, plus documented policy and evidence of an auto-merged and a human-review PR path.
Resources: Dependabot grouping docs,
dependabot/fetch-metadataaction docs.Complexity: High (200 points)
Baseline Definition of Done (applies to every Wave issue)
Each issue's own "Definition of Done" is in addition to this baseline:
npm run lint,npm run typecheck,npm test,npm run check:i18nandnpm run check:editorconfigpass locally and in CI. (If a command is broken by pre-existing repo debris, see the Repository Health & Build Integrity issues — do not silence the check; note the blocker in the PR.)any, no// @ts-ignore/eslint-disablewithout a justification comment, and no newconsole.*(usesecureLoggerfromsrc/lib/secureLogging.ts).src/lib/i18n/messages/en.tsandes.ts).src/app/globals.css.docs/(andREADME.mdif routes/scripts/env vars change) are updated..github/CODEOWNERS.