Skip to content

ci: regenerate image locks on Dependabot PRs, hold eslint 9 - #83

Merged
arodiss merged 1 commit into
mainfrom
chore/dependabot-locks-eslint
Sep 29, 2026
Merged

arodiss merged 1 commit into
mainfrom
chore/dependabot-locks-eslint

Conversation

@arodiss

@arodiss arodiss commented Sep 29, 2026 •

Copy link
Copy Markdown

Why

The last round of Dependabot PRs (#75–#82) were all red. This fixes two of the causes.

What changed

  • .github/dependabot.yml
    • uv: exclude-paths: packages/sandbox-images/locks/** so Dependabot stops editing generated lock files.
    • npm: ignore eslint and @eslint/js >= 10.0.0, same style as the existing better-auth entry.
  • New .github/workflows/dependabot-image-locks.yml: on Dependabot PRs that touch sandbox-runtime/uv.lock, runs sandbox:images lock (uv 0.9.7, same as CI) and pushes the regenerated locks back to the PR branch.

Required setup

The push uses a GitHub App token so the new commit re-triggers CI (a GITHUB_TOKEN push would not). Dependabot-triggered runs only see Dependabot secrets, so GH_APP_ID and GH_APP_PRIVATE_KEY need to be added under Settings → Secrets → Dependabot. The app needs Contents: write on this repo.

Not covered

The npm-major group still contains TypeScript 7, Tailwind 4, Vitest 5 etc., and the npm minor/patch and Litestream 0.5 PRs had their own code-level breakages. Those are separate.

Verification

  • Ran the workflow's regeneration step against the closed chore: bump the python-minor-patch group across 5 directories with 24 updates #82 head with uv 0.9.7: lock --check fails before (same runtime.txt is stale error as CI) and passes after.
  • test:node-version-workflow-contract and test:terraform-workflow-contract pass; Prettier clean; YAML parses.
  • The workflow itself can only be exercised by the next Dependabot uv PR.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Dependency updates are now limited to compatible ESLint versions, and generated sandbox image lock files are excluded from routine update checks.
    • Sandbox image lock files are automatically refreshed when relevant runtime or dependency files change, and updates are committed only when the generated files differ.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Team

Run ID: 29d74a6b-d9a4-4ca5-8baa-9c9fc3bbbe7d

📥 Commits

Reviewing files that changed from the base of the PR and between d11d981 and c6d9420.

📒 Files selected for processing (2)
  • .github/dependabot.yml
  • .github/workflows/dependabot-image-locks.yml

Comment @coderabbitai help to get the list of available commands.

@arodiss
arodiss merged commit e9b3655 into main Sep 29, 2026
1 of 3 checks passed
@arodiss
arodiss deleted the chore/dependabot-locks-eslint branch September 29, 2026 13:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant