Skip to content

Fix the dependabot.yml validation error that has kept version updates from ever running - #251

Merged
jeremy merged 1 commit into
mainfrom
fix-dependabot-docker-cooldown
Aug 22, 2026
Merged

jeremy merged 1 commit into
mainfrom
fix-dependabot-docker-cooldown

Conversation

@jeremy

@jeremy jeremy commented Aug 21, 2026

Copy link
Copy Markdown
Member

.github/dependabot.yml has been invalid since it landed in #248. GitHub reports it on Insights → Dependency graph → Dependabot:

Your .github/dependabot.yml contained invalid details
The property #/updates/2/cooldown/semver-major-days is not supported for the package ecosystem docker.
The property #/updates/2/cooldown/semver-minor-days is not supported for the package ecosystem docker.
The property #/updates/2/cooldown/semver-patch-days is not supported for the package ecosystem docker.

The docker block copied bundler's cooldown wholesale; those three keys only apply to ecosystems whose versions Dependabot classifies as semver, and container tags aren't. An invalid property invalidates the whole file, so bundler and github-actions have been dead too — this repo has never opened a version-update PR, and its only four Dependabot runs ever are single-gem security bumps, which don't read this file.

Consequences that are now explained:

docker keeps default-days: 7, which every ecosystem supports.

Worth watching after merge: the base image is FROM docker.io/library/ruby:$RUBY_VERSION-slim with ARG RUBY_VERSION=3.4.5. Dependabot handles parameterised tags poorly, so if bundler and github-actions start producing PRs and docker stays silent, that's a separate issue, not this one.

No other repo in the fleet configures a docker ecosystem, so this shape is unique to once-campfire.

The docker block copied bundler's cooldown wholesale, but Dependabot only
accepts semver-major/minor/patch-days for ecosystems whose versions it
classifies as semver, and container tags aren't. One invalid property
invalidates the entire file rather than the block it sits in, so since
this config landed in #248 the version updater has not run for any
ecosystem at all:

  Your .github/dependabot.yml contained invalid details
  The property '#/updates/2/cooldown/semver-major-days' is not supported
  for the package ecosystem 'docker'. (and -minor-, -patch-)

That is why #249's cooldown exclude for brakeman never took effect, and
why #250 had to bump the workflow linter pins by hand while every other
repo got a Dependabot PR. It also left `bin/brakeman --ensure-latest 15`
armed with nothing to disarm it: the lock pins brakeman 8.0.6, and CI
would have gone red roughly 15 days after 8.0.7 shipped.

Security updates were never affected — those don't read this file, which
is why the only four Dependabot runs here are single-gem security bumps.

docker keeps default-days, which is supported for every ecosystem.
Copilot AI balanced review requested due to automatic review settings August 21, 2026 21:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes Dependabot configuration validation so automated version updates can run.

Changes:

  • Removes unsupported semver cooldown keys from Docker updates while retaining the supported 7-day default.

Tip

If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@jeremy
jeremy merged commit 9310b00 into main Aug 22, 2026
13 checks passed
@jeremy
jeremy deleted the fix-dependabot-docker-cooldown branch August 22, 2026 04:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants