Skip to content

chore(deps): apply estate dependabot policy — ignore semver-major (standards#301)#24

Merged
hyperpolymath merged 1 commit into
mainfrom
claude/dependabot-policy-conformance
May 30, 2026
Merged

chore(deps): apply estate dependabot policy — ignore semver-major (standards#301)#24
hyperpolymath merged 1 commit into
mainfrom
claude/dependabot-policy-conformance

Conversation

@hyperpolymath
Copy link
Copy Markdown
Owner

Summary

Adds canonical `ignore: "*" semver-major` to 5 non-actions ecosystems. Brings mylangiser into conformance with standards#301.

Closes #22 (toml 0.8.23→1.1.2, 0.x→1.x major) as superseded — needs paired call-site updates for the toml 1.x API.

Test plan

  • CI green

…andards#301)

Adds the canonical ignore "*" semver-major block to 5 ecosystems (cargo, mix, npm, pip, nix). github-actions left as-is.

Conformance with standards#301 / docs/DEPENDABOT-POLICY.adoc.
Supersedes #22 (toml 0.8.23→1.1.2 — 0.x→1.x crossing, major).
@hyperpolymath hyperpolymath enabled auto-merge (squash) May 30, 2026 18:51
@hyperpolymath hyperpolymath merged commit feea9ec into main May 30, 2026
7 of 17 checks passed
@hyperpolymath hyperpolymath deleted the claude/dependabot-policy-conformance branch May 30, 2026 18:53
@github-actions
Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 86 issues detected

Severity Count
🔴 Critical 1
🟠 High 12
🟡 Medium 73

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Action perpolymath/standards/.github/workflows/governance-reusable.yml@main\n needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "codeql.yml lists `language: javascript-typescript` but the repo has no source files in any CodeQL-scannable language. The analyze job will exit 'no source files' on every run. Switch the matrix to `actions` (which scans workflow files — every repo has those).",
    "type": "codeql_language_matrix_mismatch",
    "file": "codeql.yml",
    "action": "switch_codeql_matrix_to_actions",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in boj-build.yml",
    "type": "missing_timeout_minutes",
    "file": "boj-build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in codeql.yml",
    "type": "missing_timeout_minutes",
    "file": "codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant