bcgov / bcgov/entity

Dependabot merge criteria caused CD failure

Open
#34,479 0 comments 0 reactions 0 assignees View on GitHub
Pay
Dominant language
JavaScript
Stars
23
Forks
62
Avg merge
24m
Merged PRs (30d)
1

Description

**What happened**

PRs #3846 and #3849 triggered Auth API CD failures (#1671, #1672) — DB migration job failed, traffic auto-rolled back to previous revision. No prod/customer impact. Both PRs reverted, CD confirmed healthy after.

**Root cause**

Both PRs only updated poetry.lock, not pyproject.toml, Mis-judged during batch cleanup.

Also: cryptography was a 2-major-version jump (48→50), pulled in indirectly (via db driver). Changelog likely affected SSL/TLS handshake used by the migration job's DB connection. "Indirect dependency, lock-only" ≠ low risk when it's a crypto/db-adjacent library.

**Proposed fixes**

Tighten merge rule: require actual version bump in pyproject.toml/package.json, not just lock file
Group Dependabot PRs via dependabot.yml (groups, cross-directory grouping) to reduce PR volume and manual triage errors
Review branch protection rules — currently blocking Dependabot's own dependabot/** branches, causing @dependabot rebase/recreate to fail and forcing manual close/recreate workarounds
Maintain a watchlist of high-risk deps (cryptography, psycopg2, SQLAlchemy, alembic, etc.) that always require manual review regardless of dependency type

**Action items**

- [ ] Align team on updated merge criteria
- [ ] Configure dependabot.yml grouping
- [ ] Review/adjust branch protection scope

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by locating dependabot.yml, pyproject.toml, package.json, and the repository's branch protection settings; compare them with the proposed merge criteria and grouping changes. Done means the criteria, Dependabot grouping, branch protection scope, and high-risk dependency review process are aligned, with CD remaining healthy after dependency updates.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, postgresql, python, sqlalchemy
Domain
ci-cd, databases, devops
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.