Skip to content

Commit e0532d4

Browse files
authored
chore(deps): add composer cooldown to dependabot.yml (#873)
Composer had no package-ecosystem entry at all, so composer dependencies got no release-age cooldown whatsoever, unlike npm which has had one for a while. Adds cooldown.default-days: 2 with a conduction/* exclude, matching the fleet-wide floor gate-93 (composer-cooldown-config) enforces. See ConductionNL/hydra openspec/changes/composer-dependency-cooldown and ADR-093 (proposed, ConductionNL/hydra#591).
1 parent 0a366df commit e0532d4

1 file changed

Lines changed: 26 additions & 0 deletions

File tree

‎.github/dependabot.yml‎

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,3 +12,29 @@ updates:
1212
- "*"
1313
exclude:
1414
- "@conduction/*"
15+
16+
# Composer had NO entry at all, so PHP dependencies were updated with no
17+
# cooldown whatsoever — the window in which a compromised release is still
18+
# published is exactly the window an instant update walks into. `npm` above
19+
# has had one for a while; composer was simply never added, which is not a
20+
# decision anyone made.
21+
#
22+
# Two days rather than one: that is the floor gate-93 enforces, and the npm
23+
# entry's single day predates it.
24+
#
25+
# Our own packages are excluded from the wait on purpose. A cooldown protects
26+
# against a compromised upstream release; `conduction/*` comes from this
27+
# fleet's own CI, and delaying it would only slow the loop between a fix
28+
# being released here and arriving here.
29+
- package-ecosystem: "composer"
30+
directory: "/"
31+
target-branch: "development"
32+
schedule:
33+
interval: "weekly"
34+
open-pull-requests-limit: 10
35+
cooldown:
36+
default-days: 2
37+
include:
38+
- "*"
39+
exclude:
40+
- "conduction/*"

0 commit comments

Comments
 (0)