From b64bcaad4a3b44fcdeafe1b0ab3057fe78c2c9d8 Mon Sep 17 00:00:00 2001 From: mark Date: Thu, 10 Sep 2026 18:28:24 +0000 Subject: [PATCH 1/3] ci: track the github-actions ecosystem in Dependabot Add a github-actions block so action pins are bumped automatically. Unlike the other ecosystems in this file, semver-major updates are not ignored: action majors are mostly runner-runtime bumps (node20 -> node24) that GitHub forces anyway, and suppressing them is what let these pins go stale in the first place. --- .github/dependabot.yml | 28 +++++++++++++++++++++++++++- CHANGELOG.md | 4 ++++ 2 files changed, 31 insertions(+), 1 deletion(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index e3a44ecb0..df5501496 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -3,7 +3,8 @@ # Please see the documentation for all configuration options: # https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file # -# Major version updates are disabled for now across every ecosystem/directory. +# Major version updates are disabled for now across every ecosystem/directory, +# except `github-actions` (see the note on that block below). # Security updates are unaffected (Dependabot ignores `ignore` rules for # security advisories), so majors still land when they fix a vulnerability. @@ -217,3 +218,28 @@ updates: applies-to: 'version-updates' patterns: - '*' + + # Enable version updates for GitHub Actions + # + # Deliberately *not* ignoring `version-update:semver-major` here, unlike the + # ecosystems above. Actions majors are mostly runner-runtime bumps (e.g. + # node20 -> node24) that GitHub eventually forces anyway; blocking them means + # the pins rot until someone does a manual pass. Actions are also SHA-pinned + # and reviewed here, so a bad major cannot land silently. + # + # Note: Dependabot bumps the action SHA only. Tool versions passed *into* an + # action (e.g. the `version:` input of zizmorcore/zizmor-action, or the image + # digest inside boostsecurityio/poutine-action) still need a manual bump. + - package-ecosystem: 'github-actions' + directory: '/' + schedule: + interval: 'weekly' + cooldown: + default-days: 7 + labels: + - 'dependencies' + - 'dependabot' + groups: + github-actions: + patterns: + - '*' diff --git a/CHANGELOG.md b/CHANGELOG.md index 6b315c3b6..dd1579852 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -49,6 +49,10 @@ For more information about each release including git tags and artifacts, see [R - Passwords are hashed with Argon2id instead of bcrypt at cost factor 5 ([#901](https://github.com/roostorg/coop/pull/901) by [@serendipty01](https://github.com/serendipty01), closes [#900](https://github.com/roostorg/coop/issues/900)) - Minimum password length raised to 15 and enforced server-side ([#1065](https://github.com/roostorg/coop/pull/1065), [#1094](https://github.com/roostorg/coop/pull/1094) by [@serendipty01](https://github.com/serendipty01)) +### CI & infrastructure + +- Dependabot now tracks the `github-actions` ecosystem, and every action pin was bumped to its current release + ## [1.0.2] - 2026-06-30 This release addresses reported security advisories, improves NCMEC CyberTipline reporting, and includes front-end quality-of-life improvements. From f8f6479509029f2ff8be6bc1feb64a332743e460 Mon Sep 17 00:00:00 2001 From: mark Date: Thu, 10 Sep 2026 18:32:10 +0000 Subject: [PATCH 2/3] docs: add PR links to the CHANGELOG entry --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index dd1579852..0212017f4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -51,7 +51,7 @@ For more information about each release including git tags and artifacts, see [R ### CI & infrastructure -- Dependabot now tracks the `github-actions` ecosystem, and every action pin was bumped to its current release +- Dependabot now tracks the `github-actions` ecosystem, and every action pin was bumped to its current release ([#1157](https://github.com/roostorg/coop/pull/1157)–[#1168](https://github.com/roostorg/coop/pull/1168) by [@reitblatt](https://github.com/reitblatt)) ## [1.0.2] - 2026-06-30 From 1d4e527762444371f60627686107404beb61c210 Mon Sep 17 00:00:00 2001 From: Cassidy James Date: Thu, 17 Sep 2026 17:08:32 -0600 Subject: [PATCH 3/3] Revert CHANGELOG.md update --- CHANGELOG.md | 4 ---- 1 file changed, 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 47bd50374..bc13d7c8b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -51,10 +51,6 @@ For more information about each release including git tags and artifacts, see [R - Passwords are hashed with Argon2id instead of bcrypt at cost factor 5 ([#901](https://github.com/roostorg/coop/pull/901) by [@serendipty01](https://github.com/serendipty01), closes [#900](https://github.com/roostorg/coop/issues/900)) - Minimum password length raised to 15 and enforced server-side ([#1065](https://github.com/roostorg/coop/pull/1065), [#1094](https://github.com/roostorg/coop/pull/1094) by [@serendipty01](https://github.com/serendipty01)) -### CI & infrastructure - -- Dependabot now tracks the `github-actions` ecosystem, and every action pin was bumped to its current release ([#1157](https://github.com/roostorg/coop/pull/1157)–[#1168](https://github.com/roostorg/coop/pull/1168) by [@reitblatt](https://github.com/reitblatt)) - ## [1.0.2] - 2026-06-30 This release addresses reported security advisories, improves NCMEC CyberTipline reporting, and includes front-end quality-of-life improvements.