Repository navigation
Fix the dependabot.yml validation error that has kept version updates from ever running - #251
Merged
Merged
Conversation
The docker block copied bundler's cooldown wholesale, but Dependabot only accepts semver-major/minor/patch-days for ecosystems whose versions it classifies as semver, and container tags aren't. One invalid property invalidates the entire file rather than the block it sits in, so since this config landed in #248 the version updater has not run for any ecosystem at all: Your .github/dependabot.yml contained invalid details The property '#/updates/2/cooldown/semver-major-days' is not supported for the package ecosystem 'docker'. (and -minor-, -patch-) That is why #249's cooldown exclude for brakeman never took effect, and why #250 had to bump the workflow linter pins by hand while every other repo got a Dependabot PR. It also left `bin/brakeman --ensure-latest 15` armed with nothing to disarm it: the lock pins brakeman 8.0.6, and CI would have gone red roughly 15 days after 8.0.7 shipped. Security updates were never affected — those don't read this file, which is why the only four Dependabot runs here are single-gem security bumps. docker keeps default-days, which is supported for every ecosystem.
Contributor
There was a problem hiding this comment.
Pull request overview
Fixes Dependabot configuration validation so automated version updates can run.
Changes:
- Removes unsupported semver cooldown keys from Docker updates while retaining the supported 7-day default.
Tip
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
.github/dependabot.ymlhas been invalid since it landed in #248. GitHub reports it on Insights → Dependency graph → Dependabot:The docker block copied bundler's cooldown wholesale; those three keys only apply to ecosystems whose versions Dependabot classifies as semver, and container tags aren't. An invalid property invalidates the whole file, so
bundlerandgithub-actionshave been dead too — this repo has never opened a version-update PR, and its only four Dependabot runs ever are single-gem security bumps, which don't read this file.Consequences that are now explained:
cooldown.exclude: brakemanhas never been exercised.bin/brakemanforces--ensure-latest 15against a lock pinned to brakeman 8.0.6. Nothing here could ever bump it, so CI was set to go red about 15 days after 8.0.7 ships.dockerkeepsdefault-days: 7, which every ecosystem supports.Worth watching after merge: the base image is
FROM docker.io/library/ruby:$RUBY_VERSION-slimwithARG RUBY_VERSION=3.4.5. Dependabot handles parameterised tags poorly, so ifbundlerandgithub-actionsstart producing PRs anddockerstays silent, that's a separate issue, not this one.No other repo in the fleet configures a
dockerecosystem, so this shape is unique to once-campfire.