chore(deps): add the fleet dependabot config - #45
Merged
Conversation
This repository had no .github/dependabot.yml, so it has never received a dependency update. Eight of fourteen audited fleet repos were in that state. The absence is silent by nature: a repo with no config looks exactly like one whose dependencies happen to be current. It cannot be fixed at the org level. Unlike community health files, Dependabot does not inherit a config from the .github repository -- version updates require a per-repo file. Matches the fleet form: weekly, patch and minor grouped separately so a green group merges as one PR, github-actions watched alongside the package ecosystem, forkwright on review. The WARNING about enumerating every lockfile is carried deliberately. A dependency graph watched by no entry never updates, and nothing reports it -- thumos lost nine releases of fuzz/Cargo.lock exactly that way. Root cause of the class is kanon#3640: the CI template ships dependabot-auto-merge.yml, the workflow that MERGES dependency PRs, and no dependabot.yml to produce any. Every repo scaffolded from canon inherits an auto-merger with nothing to merge.
forkwright
added a commit
that referenced
this pull request
Aug 24, 2026
) sphragis received its first dependabot config today (#45) and immediately had six update PRs open. Nothing merges them. This adds the auto-merger. ## A caller, not a copy Sixteen lines delegating to `forkwright/.github`, the same way theatron already consumes it. The logic worth not duplicating is real — the reusable workflow polls for check *groups* to appear rather than calling `gh pr checks --watch`, because `--watch` returns as soon as the fast checks report and would approve a PR whose gate had not started building yet. ## Why this is NOT being copied into the other five repos koinon, epitelesis, logismos, dioptron and typikon all gained dependabot configs today too. They are **deliberately excluded**, and this is the part worth reading. The reusable workflow waits on four check groups — gate, `cargo deny`, `cargo audit`, osv — and **fails when a group never reports**. That is intentional: a verification check that silently goes missing is precisely the case it exists to catch. Measured against live PRs in each repo, not inferred from workflow filenames: | repo | gate | cargo deny | cargo audit | osv | adoptable | |---|---|---|---|---|---| | **sphragis** | `gate / gate` | ✓ | ✓ | `osv scanner / osv-scan` | **yes** | | epitelesis | `gate / gate-attestation` | ✓ | ✓ | — | no | | logismos | `gate / gate` | ✓ | ✓ | — | no | | koinon | `gate / gate` | ✓ | — | — | no | | dioptron | gate-attestation only | — | — | — | no | | typikon | gate-attestation only | — | — | — | no | Copying this file into those five would not give them auto-merge. It would give them a job that times out and reports failure on every dependabot PR — worse than having no auto-merger, because it turns a green PR red. **The gap to close there is security scanning, not this workflow.** koinon has neither `cargo audit` nor osv; dioptron and typikon have no `security.yml` at all. Tracked separately. ## Pin choice Pinned at `d5685976`, the current tip of `forkwright/.github`. Deliberately **not** theatron's `54f1af7c`. That revision predates the normalised check-name matching: it compared exact suffixes, so `endswith("osv-scan")` could not match a check actually named `osv scanner / osv-scan`. sphragis reports both spellings, and the current revision strips non-alphanumerics from both sides before testing containment, which matches the whole spelling class rather than the two spellings seen so far. theatron pinning a pre-fix revision is its own small drift, noted and not fixed here. Co-authored-by: forkwright <cody@forkwright.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This repository has no
.github/dependabot.yml, so it has never received a dependency update.Eight of fourteen audited fleet repos are in that state — typikon, logismos, epitelesis, koinon, sphragis, kanon, gnomon, dioptron. The absence is silent by nature: a repo with no config looks exactly like one whose dependencies happen to be current.
It cannot be fixed at the org level. Unlike community health files (
SECURITY.md,CONTRIBUTING.md), Dependabot does not inherit a config from the.githubrepository — version updates require a per-repo file.What this adds
The fleet form, matching aletheia and harmonia:
github-actionswatched alongside the package ecosystemforkwrighton reviewThe warning in the file is load-bearing
Every lockfile needs its own row. A dependency graph watched by no entry never updates, and nothing reports it —
thumoslost nine releases offuzz/Cargo.lockexactly that way, with two path-dependencies missing entirely and invisible tocargo auditandcargo denythe whole time (forkwright/thumos#768).Where a repo has more than one lockfile the correct form is
directories(plural) in one entry, not one entry per directory. Three separate entries cover the same graphs but guarantee a separate PR each, and a bump declared in the root manifest spans all of them — so every PR regenerates one lockfile, leaves the others stale, and fails the repo's drift gates. That is exactly what happened to thumos's smoltcp bump (#923/#924/#925, none mergeable, hand-consolidated into #926, config fixed in #927).Root cause of the class
kanon#3640:
workflow/templates/ci/shipsdependabot-auto-merge.yml— the workflow that merges dependency PRs — and nodependabot.ymlto produce any. Every repo scaffolded from canon inherits an auto-merger with nothing to merge. Fixing the template is tracked there; this PR fixes the instance.Scope
One file. No dependency versions change here — this is the mechanism that will propose them.