Skip to content

Configure Dependabot for automated dependency updates - #99

Merged
RetroHazard merged 2 commits into
mainfrom
cc/sleepy-bardeen-q8o6ip
Oct 2, 2026
Merged

RetroHazard merged 2 commits into
mainfrom
cc/sleepy-bardeen-q8o6ip

Conversation

@RetroHazard

Copy link
Copy Markdown
Owner

Summary

This PR sets up Dependabot to automatically check for npm package and GitHub Actions updates on a monthly schedule, with security updates enabled in repository settings to open immediately when advisories are published.

Key Changes

  • Added .github/dependabot.yml: Configures Dependabot to run monthly checks for npm packages and GitHub Actions, grouped by update type (minor/patch vs major) to limit the number of PRs per ecosystem per run. Security updates are grouped along the same minor/patch vs major line.
  • Updated DEVELOPMENT.md: Added "Automated Updates" section documenting the Dependabot schedule, grouping strategy, and the requirement to re-shake npm lockfiles before CI passes.
  • Updated ARCHITECTURE.md: Removed "Dependencies — Automated dependency update checks (Dependabot)" from the Future Improvements list since this is now implemented.

Implementation Details

  • Monthly schedule keeps dependency updates manageable while staying current
  • Separate groups for minor/patch and major updates ensure major version bumps are reviewed separately before merging
  • Security updates bypass the schedule and open immediately when advisories are published
  • Documentation notes that npm PRs require running npm install locally to update the lockfile before verify.yaml passes, as Dependabot installs without lifecycle scripts

https://claude.ai/code/session_01EDadxCzrbML6jH3mM4J54d

The repo had no dependabot.yml, so the only Dependabot activity was security
updates enabled in the repository settings, one PR per package.

Version updates for npm and GitHub Actions (workflows plus the composite
setup action) now run monthly. Each ecosystem opens at most two PRs a run:
minor and patch bumps together, majors in a separate group. npm security
updates are grouped along the same line; they still open when an advisory
lands, since the schedule doesn't apply to them.

DEVELOPMENT.md documents the cadence and the lockfile re-shake those PRs
need; ARCHITECTURE.md drops Dependabot from its future-work list.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EDadxCzrbML6jH3mM4J54d

Copy link
Copy Markdown
Owner Author

Policy events audit (scheduled check, unrelated to this PR's Dependabot changes — flagging here since no other PR touches src/constants/policyEvents.ts right now)

A real, dated fee change takes effect today that POLICY_EVENTS doesn't yet cover.

Needed: POLICY_EVENTS (Application Processing) — new entry

Effective 2026-10-01, the Immigration Services Agency raised fees for change-of-status, extension-of-period-of-stay, and permanent-residence applications:

  • Extension/change of status: flat ¥6,000 → tiered by granted period, up to ¥75,000 (online discount retained)
  • Permanent residence: ¥10,000 → ¥200,000
  • Applications accepted through 2026-09-30 keep the old fee even if granted later (transition rule)

This is the companion to the existing act2026 entry (which only raised the statutory ceiling) — this is the actual amount set under that ceiling, same relationship as act2023 → act2023Effect.

{
  // Effective 2026-10-01: extension/change of status 6,000 → tiered up to
  // 75,000 yen by granted period; permanent residence 10,000 → 200,000 yen.
  period: '2026-10',
  category: 'fees',
  titleKey: 'policy.feeRevision2026.title',
  descriptionKey: 'policy.feeRevision2026.description',
  href: 'https://www.moj.go.jp/isa/content/001469200.pdf',
},

Needs matching policy.feeRevision2026.title / .description keys added to all locales in src/i18n/locales (not just en.ts), e.g.:

  • title: "Application fees raised again"
  • description: "Extensions now tiered by period up to 75,000 yen; permanent residence rose to 200,000 yen."

Not needed: RESIDENT_EVENTS (Resident Population)

Fee changes don't move who's counted as a resident — neither the 2025-04 fee revision nor the act2026 ceiling law got a resident-table marker, so this one shouldn't either.

Watching, not yet actionable (don't add now)

Two other 2026 changes surfaced in research but aren't in force yet, so they fail the file's own "only actual changes, not publications" rule:

  • 特定技能2号 (SSW Type 2) residency period → 5 years: ordinance amendment announced 2026-08-04, still in public comment, scheduled to take effect January 2027. Revisit for a 2027-01 Application Processing entry (and likely a 2027-06 Resident Population entry per the file's "first snapshot that could show it" rule) once it's actually in force.
  • Permanent-residence guideline tightening (income/pension/language/national-interest criteria): guideline revised 2026-10-01, but the substantive criteria phase in on 2027-04 applications (income threshold partially retroactive to 2026-04 filings). Dated enough to revisit once the phase-in details settle — the split effective dates make this one worth a maintainer judgment call rather than a mechanical add.

Generated by Claude Code

@RetroHazard
RetroHazard merged commit a19d061 into main Oct 2, 2026
1 check passed
@RetroHazard
RetroHazard deleted the cc/sleepy-bardeen-q8o6ip branch October 2, 2026 00:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants