From fbfa870b95bbf14a57e1f9525021873b6d2d276a Mon Sep 17 00:00:00 2001 From: "pulse-triage[bot]" <249995291+pulse-triage[bot]@users.noreply.github.com> Date: Sun, 20 Sep 2026 03:23:38 +0100 Subject: [PATCH] build(deps): pin Playwright to the offline browser runtime line The npm-minor-patch group (Dependabot #2115) has been held since 17 Sep because it bundles @playwright/test, playwright and playwright-core 1.56.1 -> 1.63.0 with 12 safe frontend updates. The offline browser-verification runtime is pinned to Playwright 1.56.1, so a lockfile bump breaks browser-proof parity; holding the whole group blocked the safe updates instead. Ignore Playwright version updates on the governed 1.56.1 line, matching the docker governed-tag policy, so the remaining grouped updates can be reviewed on their own. Security updates stay covered by the weekly npm-audit scan and the frontend dependencySecurity proof. Extend the dependabot config guard to lock the policy in. Change-source: pulse-maintainer --- .github/dependabot.yml | 20 ++++++++++++++++++++ scripts/tests/test_dependabot_config.py | 16 ++++++++++++++++ 2 files changed, 36 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 89929dd43..fcd4a579f 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -76,6 +76,26 @@ updates: applies-to: "security-updates" patterns: - "*" + # The offline browser-verification runtime is pinned to Playwright 1.56.1, + # so frontend browser proofs require lockfile parity. Keep Playwright on the + # governed 1.56.1 line; review upgrades as explicit work alongside a runtime + # change, matching the docker governed-tag policy. + ignore: + - dependency-name: "playwright" + update-types: + - "version-update:semver-major" + - "version-update:semver-minor" + - "version-update:semver-patch" + - dependency-name: "playwright-core" + update-types: + - "version-update:semver-major" + - "version-update:semver-minor" + - "version-update:semver-patch" + - dependency-name: "@playwright/test" + update-types: + - "version-update:semver-major" + - "version-update:semver-minor" + - "version-update:semver-patch" - package-ecosystem: "docker" directories: diff --git a/scripts/tests/test_dependabot_config.py b/scripts/tests/test_dependabot_config.py index 114063ddd..ce8b6a180 100644 --- a/scripts/tests/test_dependabot_config.py +++ b/scripts/tests/test_dependabot_config.py @@ -136,6 +136,22 @@ class DependabotConfigTest(unittest.TestCase): ], ) + def test_npm_updates_preserve_browser_runtime_parity(self) -> None: + all_semver = { + "version-update:semver-major", + "version-update:semver-minor", + "version-update:semver-patch", + } + ignored = { + item["dependency-name"]: set(item["update-types"]) + for item in self.updates["npm"]["ignore"] + } + self.assertEqual( + set(ignored), + {"playwright", "playwright-core", "@playwright/test"}, + ) + self.assertTrue(all(types == all_semver for types in ignored.values())) + def test_weekly_scan_covers_the_same_lockfiles(self) -> None: workflow = yaml.safe_load(SECURITY_SCAN.read_text(encoding="utf-8")) jobs = workflow["jobs"]