Skip to content

build(deps): prevent Expo patch cooldown from blocking CI - #28

Open
johnpacino wants to merge 1 commit into
open-flight:mainfrom
johnpacino:codex/dependabot-expo-cooldown
Open

johnpacino wants to merge 1 commit into
open-flight:mainfrom
johnpacino:codex/dependabot-expo-cooldown

Conversation

@johnpacino

Copy link
Copy Markdown
Contributor

What does this PR do?

  • Updates the current Expo SDK 57 patch baseline required by Expo Doctor:
    • expo to ~57.0.25
    • expo-linking to ~57.0.11
    • expo-router to ~57.0.23
  • Runs npm Dependabot checks daily instead of weekly.
  • Retains Dependabot's three-day cooldown for other dependencies, while allowing expo, expo-*, and @expo/* packages to update immediately.

Why was this required?

Expo Doctor began requiring these newly released patches immediately, causing the required Quality check on unrelated PRs to fail. Dependabot found the same releases but filtered them out under GitHub's default three-day release cooldown, so manually requesting an update produced no PR.

The current package alignment restores green CI. Exempting only Expo-owned packages from cooldown aligns future Dependabot behavior with Expo Doctor without removing the stabilization delay for the rest of the dependency graph. Daily checks reduce the remaining delay between an Expo baseline change and the grouped lockfile PR.

Evidence: Dependabot update job and the Quality failure on #27.

Automated tests

No application tests were added because this changes dependency automation and SDK-compatible patch versions without changing application behavior.

Commands run:

  • npm ci — passed
  • npm run doctor — 21/21 checks passed
  • CI=1 npx expo install --check — dependencies are up to date
  • npm run lint — passed
  • npm run format:check — passed
  • npm run typecheck — passed
  • npm run test:ci — 18 suites and 262 tests passed on the isolated rerun
  • npm run bundle:check — iOS, Android, and web exports passed

The first full-suite run was executed concurrently with the three-platform bundle and one existing Device-screen test exceeded its five-second timeout. The immediate isolated rerun passed all 262 tests.

Manual (human) testing

Not performed. No physical device, simulator, or Expo Go session was used because this is dependency automation and compatible patch alignment only.

Server/API contract impact

None.

AI assistance

Codex inspected the GitHub and Dependabot job logs, identified the cooldown mismatch, prepared the focused configuration and dependency changes, removed unrelated lockfile churn, and ran the validation listed above. Human review of the final diff is pending.

Checklist

  • This PR has one coherent objective and contains no unrelated changes
  • New or changed behavior has automated tests, or I explained why none apply
  • I documented manual human testing with the actual platform/build used
  • I documented any OpenFlight server contract impact
  • I disclosed substantive AI assistance and personally reviewed every change (human review pending)
  • npm ci succeeds
  • npx expo-doctor passes
  • npx tsc --noEmit passes
  • npm test -- --ci --runInBand passes
  • npx expo export --platform all succeeds when application code changed
  • Documentation was updated where required (none required)
  • No policy documents are mixed into a product-feature PR
  • No unrelated generated files, formatting, or dependency updates are included

@tristanheilman

Copy link
Copy Markdown

I installed on my machine and tested and expo doctor no longer passes. The versions are stale as of Oct. 6th due to Expo SDK 57 patches. #31 addresses why the expo-doctor breakage keeps coming back and breaking CI. With #31 the normal Dependabot schedule is enough imo. More details and test results there.

20/21 checks passed. 1 checks failed. Possible issues detected:
Use the --verbose flag to see more details about passed checks.

✖ Check that packages match versions required by installed Expo SDK

🔧 Patch version mismatches
package         expected  found    
expo            ~57.0.27  57.0.25  
expo-constants  ~57.0.21  57.0.19  
expo-linking    ~57.0.12  57.0.11  
expo-router     ~57.0.25  57.0.23  
expo-sqlite     ~57.0.4   57.0.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants