feat: submit the dependency graph so Dependabot alerts work again - #119
Merged
Merged
Conversation
GitHub's dependency graph does not parse uv.lock, so this repository's graph has
been empty since the poetry -> uv migration on 2026-08-12 — its SBOM contained
exactly one package, the repository itself. Alerts are generated from the graph
and security updates are triggered by alerts, so both have been silently off,
and the poetry.lock alerts left behind could never resolve. They were dismissed
as inaccurate once each package was confirmed present in uv.lock at or past its
patched version.
package-ecosystem: "uv" in dependabot.yml did not cover this, which is why
nothing looked wrong. That entry configures Dependabot updates, which read the
manifest directly; with open-pull-requests-limit: 0 it leaves only the security
path, and that runs through alerts.
Calls the shared workflow from common-guidelines v1.7.0. It gets a workflow of
its own containing nothing else, because the shared job runs a third-party
action with contents: write and that grant cannot be narrowed — there is no
dependency-graph permission scope. permissions: {} at workflow level keeps the
grant on the single job that needs it.
Triggers on uv.lock changes rather than every push, with a weekly floor so a
broken submission surfaces on its own instead of waiting for the next
dependency bump. Deliberately not on pull_request, so nothing from a fork
influences a run holding that grant.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This repository's dependency graph has been empty since the poetry → uv migration on
2026-08-12 — its SBOM contained exactly one package, the repository itself. GitHub's graph does
not parse
uv.lock.Alerts are generated from the graph and security updates are triggered by alerts, so both
have been silently off, and the orphaned
poetry.lockalerts could never resolve. (Those weredismissed as
inaccurateafter confirming each package is still present inuv.lockat or pastits patched version — they were genuinely fixed, not unused.)
package-ecosystem: "uv"did not cover this, which is why nothing looked wrong: it configuresDependabot updates, and with
open-pull-requests-limit: 0the only path it leaves open issecurity updates, which run through alerts.
Calls the shared workflow from iglootools/common#32 (v1.7.0).
Why this is a workflow of its own
The shared job runs a third-party action with
contents: write, and that grant cannot benarrowed — there is no
dependency-graphpermission scope, and the snapshot API sits behindcontents: write. So:permissions: {}at workflow level;contents: writeon the single job that needs ituv.lockchanges + a weekly floor + manual; deliberately notpull_request,so nothing from a fork influences a run holding that grant
A Renovate PR bumping that pin is not a routine dependency update. The shared workflow's
header says what to check before approving one.
actionlintclean.