Repository navigation
fix(deps): let major bumps reach pip and npm, and clear the cryptography advisory #338
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,15 +1,34 @@ | ||
| # Dependabot — weekly grouped updates, single PR per ecosystem. | ||
| # Dependabot — weekly grouped updates; minor/patch batched, majors isolated. | ||
| # | ||
| # Rationale (HIVE-115 follow-up, 2026-05-22): | ||
| # - We pin ``mcp >= 1.26, < 2.0`` in pyproject.toml because | ||
| # - We pin ``mcp >= 1.27, < 3.0`` in pyproject.toml because | ||
| # src/hive/_compat.py monkey-patches private internals of | ||
| # mcp.shared.session.RequestResponder (upstream tracker: | ||
| # modelcontextprotocol/python-sdk#2610). Dependabot's `ignore` | ||
| # modelcontextprotocol/python-sdk#2416). Dependabot's `ignore` | ||
| # block below keeps it from trying to lift that cap automatically; | ||
| # any mcp bump must be a deliberate code review against the shim. | ||
| # - Grouping all routine bumps into ONE PR per ecosystem per week | ||
| # avoids the "20 stale Dependabot PRs" noise pattern. Pairs with | ||
| # - Grouping routine bumps per ecosystem per week avoids the | ||
| # "20 stale Dependabot PRs" noise pattern. Pairs with | ||
| # release-please for ergonomic batch merges. | ||
| # | ||
| # Amended 2026-08-07 (#334): a `*`-pattern group restricted to | ||
| # minor+patch does not merely batch majors — it EXCLUDES them. `pip` | ||
| # and `npm` had one such group each, so no major bump could reach | ||
| # either ecosystem, including a security bump that requires one. That | ||
| # is how a high-severity `cryptography` advisory (48.0.1 -> 50.0.0, | ||
| # transitive via authlib <- fastmcp) sat with no PR while an earlier | ||
| # *patch* advisory on the same package had sailed through (#137). | ||
| # | ||
| # Fix: a second group per affected ecosystem, matching the same `*` | ||
| # but claiming `major` only. Two groups with identical patterns are | ||
| # non-overlapping when their update-types are disjoint, so minors stay | ||
| # batched while a major arrives as its OWN reviewable PR — which is | ||
| # what a breaking bump deserves. `open-pull-requests-limit` is raised | ||
| # to 2 so the two groups do not compete for one slot; the noise | ||
| # ceiling stays bounded (2 per ecosystem, not 20). | ||
|
Comment on lines
+14
to
+28
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/usr/bin/env bash
set -euo pipefail
repo="$(gh repo view --json nameWithOwner -q .nameWithOwner)"
rg -n -A 12 -B 2 \
'python-all|python-major|site-all|site-major|open-pull-requests-limit' \
.github/dependabot.yml
gh api "repos/${repo}/dependabot/alerts/57" \
--jq '[.dependabot_alert.number, .dependency.package.name, .state, .security_advisory.severity] | `@tsv`'
gh pr list \
--repo "$repo" \
--state all \
--search 'author:app/dependabot cryptography' \
--json number,title,state,url \
--jq '.[] | [.number, .state, .title, .url] | `@tsv`'Repository: mlorentedev/hive Length of output: 3835 🏁 Script executed: #!/usr/bin/env bash
set -euo pipefail
python3 - <<'PY'
from pathlib import Path
p = Path('.github/dependabot.yml')
text = p.read_text().splitlines()
for i, line in enumerate(text, start=1):
if i in {14,24,65,121}:
print(f'{i}: {line}')
PYRepository: mlorentedev/hive Length of output: 451 🌐 Web query:
💡 Result: In GitHub Dependabot, the Citations:
🌐 Web query:
💡 Result: Dependabot treats version updates and security updates differently regarding open pull request limits [1][2]. The open-pull-requests-limit configuration option specifically controls the maximum number of open pull requests for version updates [1][3]. The default limit for version updates is five [1][2][4]. If this limit is reached, Dependabot will not open further version update pull requests until existing ones are merged or closed [1][2][4]. Setting this limit to zero effectively disables version updates for that package manager [1][5][6]. Security update pull requests operate under a different system and are not constrained by the open-pull-requests-limit [1][7]. They do not count toward the version update limit [1][8]. While some historical documentation (such as for GitHub Enterprise Server 3.5) mentioned an internal limit for security updates [4], current authoritative GitHub documentation states that there is no limit on the number of open pull requests for security updates [1][7][8]. Security updates are triggered by vulnerability advisories rather than the schedule that governs version updates [3][9]. If you wish to manage the volume of security update pull requests, you can use the grouping feature in your dependabot.yml file [5][3]. By using the groups option with the applies-to: security-updates key, you can consolidate multiple security updates into a single pull request [5][10][9]. Citations:
Correct the Dependabot grouping notes. A [correct_review_comment] 🤖 Prompt for AI Agents |
||
| # | ||
| # github-actions and docker were already unfiltered and so unaffected; | ||
| # they are deliberately left with a single all-types group. | ||
| # - github-actions ecosystem is included so CI workflows stay | ||
| # on supported runners + action versions. | ||
| # - site/ has its own package.json (Astro + Starlight); covered as a | ||
|
|
@@ -30,7 +49,7 @@ updates: | |
| day: "monday" | ||
| time: "07:00" | ||
| timezone: "America/Denver" | ||
| open-pull-requests-limit: 1 | ||
| open-pull-requests-limit: 2 | ||
| commit-message: | ||
| prefix: "chore(deps)" | ||
| include: "scope" | ||
|
|
@@ -43,10 +62,18 @@ updates: | |
| update-types: | ||
| - "minor" | ||
| - "patch" | ||
| # Disjoint update-types from python-all, so majors are isolated | ||
| # into their own PR rather than excluded entirely (#334). | ||
| python-major: | ||
| patterns: | ||
| - "*" | ||
| update-types: | ||
| - "major" | ||
| ignore: | ||
| # _compat.py patches mcp internals; major bumps must be reviewed | ||
| # by hand against tests/test_compat_shim.py. Track upstream at | ||
| # modelcontextprotocol/python-sdk#2610. | ||
| # modelcontextprotocol/python-sdk#2416 (NOT #2610 — the __exit__ | ||
| # patch for that one was removed; see hive#127 and hive#336). | ||
| - dependency-name: "mcp" | ||
| update-types: | ||
| - "version-update:semver-major" | ||
|
|
@@ -78,7 +105,7 @@ updates: | |
| day: "monday" | ||
| time: "07:00" | ||
| timezone: "America/Denver" | ||
| open-pull-requests-limit: 1 | ||
| open-pull-requests-limit: 2 | ||
| commit-message: | ||
| prefix: "chore(site)" | ||
| include: "scope" | ||
|
|
@@ -91,6 +118,12 @@ updates: | |
| update-types: | ||
| - "minor" | ||
| - "patch" | ||
| # Same fix as python-major (#334): majors were excluded, not batched. | ||
| site-major: | ||
| patterns: | ||
| - "*" | ||
| update-types: | ||
| - "major" | ||
|
|
||
| # ── Docker base image (Dockerfile) ──────────────────────────── | ||
| - package-ecosystem: "docker" | ||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.