Skip to content

[High] Automate dependency governance: grouped updates, safe auto-merge and breaking-change verification #513

Description

@james2177

Category: DevOps, CI/CD & Observability

Description: Improve .github/dependabot.yml and scripts/check-dependencies.mjs into a full policy: grouped updates, auto-merge of low-risk updates only when CI is green, mandatory extra checks for wallet/crypto-related packages and automated release-note/breaking-change summaries.

Problem Statement & Context: Dependency PR noise leads to neglect, and neglected dependencies (Next.js, Stellar SDK, Freighter API) become security debt; conversely, blindly merging crypto-adjacent updates is dangerous.

Scope & Acceptance Criteria:

  • Dependabot grouping (dev tooling, testing, next/react, stellar) with schedule and ignore rules documented; GitHub Actions versions updated too and pinned by SHA.
  • Auto-merge workflow: patch/minor updates of dev-only dependencies auto-merge after required checks pass; production and crypto-related packages (@stellar/*, next, react) require human review with an auto-generated checklist comment (changelog links, diff of package-lock, install-scripts diff, provenance status).
  • check-dependencies.mjs extended: new/changed install scripts detection, maintainer/ownership change heuristics (when data available), license policy, and a machine-readable report artifact.
  • Policy doc (docs/dependency-policy.md) covering criteria, SLAs (critical advisories patched within N days) and an emergency-update runbook; weekly scheduled npm audit summary issue.
  • Out of scope: vendoring dependencies.

Implementation Guidelines (Suggested Execution):

  1. Key Files/Modules: .github/dependabot.yml, scripts/check-dependencies.mjs, new .github/workflows/dependabot-automerge.yml, SECURITY.md.
  2. Design/Architecture: Decision logic in a pure module (classifyUpdate(pkg, from, to, type) → auto|review|block) with fixtures.
  3. Edge Cases/Constraints: pull_request_target security (only use dependabot/fetch-metadata, no checkout of PR code with secrets), major bumps, peer dependency conflicts, lockfile-only changes.
  4. Testing: Table tests for the classifier; workflow linted with actionlint; evidence from a dry-run on a sample Dependabot PR.

Definition of "Done": Baseline DoD, plus documented policy and evidence of an auto-merged and a human-review PR path.

Resources: Dependabot grouping docs, dependabot/fetch-metadata action docs.

Complexity: High (200 points)

Baseline Definition of Done (applies to every Wave issue)

Each issue's own "Definition of Done" is in addition to this baseline:

  • Code, tests and documentation are included in one PR that references the issue.
  • npm run lint, npm run typecheck, npm test, npm run check:i18n and npm run check:editorconfig pass locally and in CI. (If a command is broken by pre-existing repo debris, see the Repository Health & Build Integrity issues — do not silence the check; note the blocker in the PR.)
  • No new any, no // @ts-ignore / eslint-disable without a justification comment, and no new console.* (use secureLogger from src/lib/secureLogging.ts).
  • All new user-facing strings go through the i18n catalog (src/lib/i18n/messages/en.ts and es.ts).
  • New interactive UI is keyboard-operable, has visible focus, correct ARIA semantics, and works in both the dark and light palettes defined in src/app/globals.css.
  • UI changes include before/after screenshots (desktop and ~400px mobile). Behaviour changes include a short screen recording or test output.
  • Relevant docs under docs/ (and README.md if routes/scripts/env vars change) are updated.
  • The PR is reviewed and approved by a maintainer listed in .github/CODEOWNERS.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    complexity: highHigh complexity Drips Wave issue (200 points)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions