mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-10-03 04:38:48 +00:00
build(deps): pin Playwright to the offline browser runtime line
The npm-minor-patch group (Dependabot #2115) has been held since 17 Sep because it bundles @playwright/test, playwright and playwright-core 1.56.1 -> 1.63.0 with 12 safe frontend updates. The offline browser-verification runtime is pinned to Playwright 1.56.1, so a lockfile bump breaks browser-proof parity; holding the whole group blocked the safe updates instead. Ignore Playwright version updates on the governed 1.56.1 line, matching the docker governed-tag policy, so the remaining grouped updates can be reviewed on their own. Security updates stay covered by the weekly npm-audit scan and the frontend dependencySecurity proof. Extend the dependabot config guard to lock the policy in. Change-source: pulse-maintainer
This commit is contained in:
parent
042431dd20
commit
fbfa870b95
2 changed files with 36 additions and 0 deletions
20
.github/dependabot.yml
vendored
20
.github/dependabot.yml
vendored
|
|
@ -76,6 +76,26 @@ updates:
|
|||
applies-to: "security-updates"
|
||||
patterns:
|
||||
- "*"
|
||||
# The offline browser-verification runtime is pinned to Playwright 1.56.1,
|
||||
# so frontend browser proofs require lockfile parity. Keep Playwright on the
|
||||
# governed 1.56.1 line; review upgrades as explicit work alongside a runtime
|
||||
# change, matching the docker governed-tag policy.
|
||||
ignore:
|
||||
- dependency-name: "playwright"
|
||||
update-types:
|
||||
- "version-update:semver-major"
|
||||
- "version-update:semver-minor"
|
||||
- "version-update:semver-patch"
|
||||
- dependency-name: "playwright-core"
|
||||
update-types:
|
||||
- "version-update:semver-major"
|
||||
- "version-update:semver-minor"
|
||||
- "version-update:semver-patch"
|
||||
- dependency-name: "@playwright/test"
|
||||
update-types:
|
||||
- "version-update:semver-major"
|
||||
- "version-update:semver-minor"
|
||||
- "version-update:semver-patch"
|
||||
|
||||
- package-ecosystem: "docker"
|
||||
directories:
|
||||
|
|
|
|||
|
|
@ -136,6 +136,22 @@ class DependabotConfigTest(unittest.TestCase):
|
|||
],
|
||||
)
|
||||
|
||||
def test_npm_updates_preserve_browser_runtime_parity(self) -> None:
|
||||
all_semver = {
|
||||
"version-update:semver-major",
|
||||
"version-update:semver-minor",
|
||||
"version-update:semver-patch",
|
||||
}
|
||||
ignored = {
|
||||
item["dependency-name"]: set(item["update-types"])
|
||||
for item in self.updates["npm"]["ignore"]
|
||||
}
|
||||
self.assertEqual(
|
||||
set(ignored),
|
||||
{"playwright", "playwright-core", "@playwright/test"},
|
||||
)
|
||||
self.assertTrue(all(types == all_semver for types in ignored.values()))
|
||||
|
||||
def test_weekly_scan_covers_the_same_lockfiles(self) -> None:
|
||||
workflow = yaml.safe_load(SECURITY_SCAN.read_text(encoding="utf-8"))
|
||||
jobs = workflow["jobs"]
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue