dependabot: close three config gaps this sweep exposed - #1046
Conversation
Each of these let a bump arrive in a shape that could not land. 1. Composite actions were never scanned. `directory: "/"` on the github-actions ecosystem covers only `.github/workflows/*`, so `.github/actions/fc-setup/action.yml` kept setup-oras@v1 and actions/cache@v4 while #1026 moved the workflows to v2/v6. That is a silent split-brain in the `oras pull` path fc-setup shares with bake-images.yml. Switch to `directories:` and add `/.github/actions/*`, then bump the two stale pins. The oras CLI gets an explicit `version: 1.3.0` pin at the same time: setup-oras v2 changed its default from 1.3.0 to 1.3.1, and every call site in the repo is a bare `uses:`. A tool that feeds the GHCR retry loops should move deliberately, not as a side effect. 2. sha2 and hmac are version-locked and were arriving separately. They share a `digest`/`crypto-common` generation: sha2 0.11 and hmac 0.13 both need digest 0.11; sha2 0.10 and hmac 0.12 both need digest 0.10. `Hmac<Sha256>` needs its Sha256 to implement the same digest crate's traits, so a mixed pair does not compile: sha2 0.11 + hmac 0.12 -> error[E0599] `new_from_slice` exists for `CoreWrapper<HmacCore<Sha256>>` but its trait bounds were not satisfied, at crates/engram-coordinator/src/oauth_redirect.rs:314 That makes #10 (sha2 0.11) and #1031 (hmac 0.13) individually unbuildable — the same situation the `grpc` group already documents for tonic/prost. Group them, and add them to cargo-minor-patch's `exclude-patterns` so a lone sha2 patch cannot split the pair via first-match ordering. 3. Node odd majors were being proposed. #130 got `node:25-alpine`: a Current-only line already EOL (2026-06-01) when the PR opened, and the release that stopped shipping corepack (nodejs/node#57617) — which is what web.Dockerfile used to install pnpm, so it could not build. Only even Node majors become LTS; ignore the odd ones.
|
✅ engrams review — complete. 0 findings posted. · View details |
|
The latest Buf updates on your PR. Results from workflow CI / buf (pull_request).
|
`workspace-hack/Cargo.toml` is output of `cargo hakari generate`, but it is also a workspace member, so the cargo ecosystem scans it and Dependabot opens PRs for crates declared only there. #1032 is the live example: it moves axum-core 0.4 -> 0.5, and `grep -rn axum-core --include=Cargo.toml` finds exactly one declaration — the hakari-generated line. That bump can never land. The next `just hakari` overwrites it, and axum-core's version is not independently choosable: axum 0.7 requires axum-core 0.4, axum 0.8 requires 0.5. It moves when `axum` moves, as part of that upgrade. Ignore axum-core so it stops arriving as its own PR.
|
|
|
Pushed a fourth gap of the same kind, found while triaging the rest of the queue. #1032 (axum-core 0.4 → 0.5) bumps a generated file. That is the only declaration in the repo. The bump cannot land for two independent reasons: the next Added an |
|
Pushed a fourth gap of the same kind, found while triaging the rest of the queue. #1032 (axum-core 0.4 → 0.5) bumps a generated file. That is the only declaration in the repo. The bump cannot land for two independent reasons: the next Added an |
Third family with the same structural lock as tonic/prost and sha2/hmac. The OTel Rust crates ship as one release set: the SDK and exporter crates depend on an exact `opentelemetry` core minor, and tracing-opentelemetry runs one minor ahead of the core it targets (0.29 -> core 0.28, 0.33 -> core 0.32). So a single-crate bump puts two cores in the graph at once. #446 bumps opentelemetry_sdk 0.28 -> 0.32.1 on its own; that release requires `opentelemetry 0.32.0`, while the workspace still declares opentelemetry and opentelemetry-otlp at 0.28. Its lockfile ends up carrying opentelemetry 0.28.0 AND 0.32.0, so the SDK being configured speaks a different API than the exporter consuming it — which is why that PR fails clippy, check, tests and the musl cross lane together rather than failing one of them. #1033 (tracing-opentelemetry 0.29 -> 0.33) is the mirror image. Group them at every update level, and add the patterns to cargo-minor-patch's exclude list so first-match ordering cannot peel one crate off the set.
|
👀 engrams review — acknowledged, queued. |
Fourth version-locked family in this repo's cargo graph. Every kube API type is generic over k8s-openapi's generated resource types, so kube pins an exact k8s-openapi minor. #1030 bumps kube 0.99 -> 4.2 on its own. kube 4.2.0 requires `k8s-openapi 0.28.0`, while the workspace declares k8s-openapi 0.24, so the PR's lockfile carries 0.24.0 AND 0.28.0 — the operator's Pod/Node types no longer unify with the client that fetches them. Grouping makes the pair one PR, which is the only shape that can build.
|
✅ engrams review — complete. 0 findings posted. · View details |
Three separate config gaps, each of which let a Dependabot bump arrive in a
shape that could not land. Found while working the queue today; fixing the
config rather than re-fixing the symptom every sweep.
1. Composite actions were never scanned
package-ecosystem: github-actionswithdirectory: "/"scans only.github/workflows/*. Composite actions under.github/actions/**are aseparate directory as far as Dependabot is concerned
(dependabot-core #4178,
#6704,
#7495).
So while #1026 moves the workflows to
setup-oras@v2andactions/cache@v6,.github/actions/fc-setup/action.ymlwould have stayed on@v1and@v4permanently. That file is used by all four Firecracker lanes
(
ci.yml:830,:898,:940,:1067), and it shares theoras pullpathwith
bake-images.yml— so the skew would leave the FC lanes pulling theforked Firecracker with oras CLI 1.3.0 while the bake pushed it with 1.3.1.
Functionally harmless today; a silent split-brain in exactly one shared code
path is not a thing to leave lying around.
Switched to
directories:with/and/.github/actions/*, and bumped thetwo stale pins in the same change.
The oras CLI also gets an explicit
version: 1.3.0pin. setup-oras v2changed its default CLI from 1.3.0 to 1.3.1, and every call site in this repo
is a bare
uses:with nowith:block — so the action bump silently swaps theorasbinary under every push/tag/pull/login, including the GHCReventual-consistency retry loops added after the 2026-08-01 red-main incident.
Pinning keeps the tool moving on purpose. If you would rather track the
action's default, drop the
with:block — but then it should be a deliberatechoice, not a side effect.
Note
.github/actions/is inCI_SELF_PATHS, so this PR forces all lanes,which means
setup-oras@v2actually gets exercised here. It gets zerocoverage on #1026 (the image lanes are skipped there and
bake-images.ymldoes not run from a PR at all).
2. sha2 and hmac are version-locked and were arriving separately
This is the one with teeth. Both crates sit on a shared
digest/crypto-commongeneration:Hmac::<Sha256>requires itsSha256to implement the same digest crate'straits, so a mixed pair does not compile. Verified both directions locally
against
crates/engram-coordinator/src/oauth_redirect.rs:314:and with the pair moved together, that error is replaced by a single
mechanical one (
use hmac::KeyInit;— v0.13 no longer surfacesnew_from_slicethroughMac), after which the crate compiles.So neither #10 (sha2 0.11) nor #1031 (hmac 0.13) can ever go green alone.
The pair is the smallest buildable review unit — precisely the situation the
existing
grpcgroup already documents for tonic/prost:Same exception, same reasoning, new family. They are also added to
cargo-minor-patch'sexclude-patterns, because that group is declared firstand Dependabot uses first-match ordering — without the exclude, a lone
sha2patch would land there and split the pair again.
3. Node odd majors were being proposed
#130 was offered
node:25-alpine. Node 25:corepack(nodejs/node#57617), which is
what
web.Dockerfileused to install pnpm.So it was unbuildable and the wrong line to adopt. Ignoring odd majors; the
even ones (26, 28, …) still arrive normally. #1045 moves CI to 24, the newest
active LTS.
Verification
Config-only plus two action pins — no runtime surface to drive. Both files
re-parsed with a real YAML parser after editing:
What a reviewer should look at closely
versions:list for Node is enumerated, not a rule. Dependabot hasno "LTS only" predicate, so odd majors are listed literally through 33.x.
Someone will need to extend it eventually. Alternatives were an
update-types: [version-update:semver-major]ignore (too broad — blocks theeven LTS majors too) or nothing (which is how we got a proposal for an EOL
runtime).
auto-merge gate correctly leaves for a human. That is intended.
bake-images.yml:170andci.yml:1721that nameactions/cache@v4/upload-artifact@v4, to avoidconflicting with chore(deps): bump the actions group across 1 directory with 12 updates #1026 which is in the merge queue. Follow-up once it lands.