Skip to content

chore(deps): add dependabot version updates for the five npm lockfiles - #2312

Merged
chaliy merged 1 commit into
mainfrom
claude/pensive-hypatia-veez7o
Aug 19, 2026
Merged

chaliy merged 1 commit into
mainfrom
claude/pensive-hypatia-veez7o

Conversation

@chaliy

@chaliy chaliy commented Aug 19, 2026

Copy link
Copy Markdown
Contributor

What changed

Dependabot now opens weekly version-update PRs for the repo's five committed
pnpm lockfiles, which previously had no updates: entry at all:

Entry Directory Resolved deps
site-npm /site 500
js-npm /crates/bashkit-js 352
examples-npm /examples, /examples/browser, /examples/bashkit-pi 131

One grouped PR per entry per week, chore(deps) prefix — the same shape as the
existing cargo entries, so this adds three PRs a week at most, not thirty.

@everruns/* is ignored in every entry. Those are this repo's own published
packages, pinned to the workspace version (0.16.0) in site/package.json and
examples/browser/package.json and bumped by the release process. Dependabot
moving them independently would race that process and produce PRs that go stale
the moment a release lands.

knowledge/operations/maintenance.md gains the coverage table and, more
usefully, the deliberate exclusions: crates/bashkit-wasm (a package.json
with no dependencies and no lockfile), .deepsec/ (updated by hand during the
security pass, because the scan runs against whatever version that pass pulls),
and Python (pyproject.toml declares only optional extras with open >= bounds
and no lockfile, so a pip entry would have nothing to pin).

Why

This is not about Dependabot alerts. Alerts and security updates run off the
repository dependency graph and need no config — they already saw these trees.
The gap is routine freshness, and the two interact: an ecosystem that only ever
moves when an advisory forces it drifts until the fix is a multi-major jump that
can't be landed under time pressure. /site is the sharpest case, being a
deployed Cloudflare Worker and the only npm surface here reachable from the
public internet at runtime.

The cargo and github-actions ecosystems have had this coverage since the config
was written; npm was simply never added as the JS surface grew from one package
to five.

Before / After

Preventative, not a fix — all five trees are clean as of this commit:

$ for d in site crates/bashkit-js examples examples/browser examples/bashkit-pi; do
    (cd $d && pnpm audit --json | jq -c '.metadata.vulnerabilities')
  done
{"info":0,"low":0,"moderate":0,"high":0,"critical":0}   # site (500 deps)
{"info":0,"low":0,"moderate":0,"high":0,"critical":0}   # crates/bashkit-js (352)
{"info":0,"low":0,"moderate":0,"high":0,"critical":0}   # examples (44)
{"info":0,"low":0,"moderate":0,"high":0,"critical":0}   # examples/browser (79)
{"info":0,"low":0,"moderate":0,"high":0,"critical":0}   # examples/bashkit-pi (8)

Config coverage before → after:

before: cargo:/  cargo:/crates/bashkit/fuzz  github-actions:/
after:  cargo:/  cargo:/crates/bashkit/fuzz  github-actions:/
        npm:/site  npm:/crates/bashkit-js
        npm:[/examples, /examples/browser, /examples/bashkit-pi]

Knowledge checks pass:

$ just check-okf
knowledge: OKF v0.2 conformant (38 concepts, 7 index files, 1 log file)

$ just check-doc-links
docs OK: 157 relative links and 6 dependency versions across 45 files

Risk

  • Low
  • No source, build, or runtime code is touched; the change is CI configuration
    plus a knowledge doc.
  • The realistic downside is PR volume from the fast-moving AI SDKs in
    /examples (ai, openai, @langchain/*). Grouping holds that to one PR a
    week; if it still proves noisy, that entry can move to monthly without
    affecting the other two.
  • directories (plural) is used for the examples entry. It is current
    Dependabot v2 syntax and the file parses as valid YAML, but unlike the rest of
    this repo's CI it is only truly exercised once Dependabot next runs — worth a
    glance at the Dependabot job log after merge.

Checklist

  • Tests added or updated — no test surface; validated via just check-okf,
    just check-doc-links, and a YAML schema parse of the config
  • Backward compatibility considered — additive config only; existing cargo
    and github-actions entries are untouched

Generated by Claude Code

The repo has five committed pnpm lockfiles (`/site`, `/crates/bashkit-js`,
`/examples`, `/examples/browser`, `/examples/bashkit-pi`) and none of them
had an `updates:` entry, so nothing kept them fresh.

This is separate from Dependabot alerts and security updates, which run off
the dependency graph and need no config — those already saw these trees. The
gap is routine freshness: without version updates a tree drifts until the
eventual security bump is a multi-major jump that cannot be landed quickly.
`/site` is the sharpest case, since it is a deployed Cloudflare Worker.

All five trees audit clean today (`pnpm audit`: 0 vulnerabilities across 983
resolved dependencies), so this is preventative, not a fix.

One grouped entry per lockfile, matching the cargo entries' shape, so a week
of bumps arrives as a single reviewable PR. `@everruns/*` is ignored
everywhere: those are this repo's own published packages, pinned to the
workspace version by the release process, and letting dependabot move them
independently races it.

Records the coverage table and the deliberate exclusions (`.deepsec/`,
`crates/bashkit-wasm`, Python) in knowledge/operations/maintenance.md.
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
bashkit 758dbad Commit Preview URL

Branch Preview URL
Aug 19 2026, 09:13 AM

@chaliy
chaliy merged commit 41ac169 into main Aug 19, 2026
21 checks passed
@chaliy
chaliy deleted the claude/pensive-hypatia-veez7o branch August 19, 2026 09:27
chaliy pushed a commit that referenced this pull request Aug 19, 2026
First bump surfaced by the npm dependabot coverage added in #2312, and a
two-major jump — exactly the drift that coverage was meant to stop
accumulating.

No CI job builds examples/browser, so the green checks on this PR say nothing
about it. Verified by hand under Node 22 instead:

- pnpm install --frozen-lockfile: clean, vite 8.2.1
- npx vite build: 8 modules transformed, wasm asset emitted
  (dist/assets/bashkit_wasm_bg-*.wasm 8,016 kB), built in 477ms
- npx vite (dev server): ready in 346ms, GET / returns HTTP 200 with the
  demo page
- node --test *.test.js: 8 of 9 pass

The one failing test, dependency-security.test.js "dependencies are
reproducible", fails identically on main: it requires exact versions and
package.json already carried "vite": "^6.4.3". This PR keeps the caret rather
than introducing it. Tracked as a follow-up, together with the reason nobody
noticed — nothing in CI runs that suite.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant