Skip to content

Stop Dependabot from updating the vulnerable spec fixtures - #463

Merged
flavorjones merged 1 commit into
masterfrom
fix-dependabot-537
Sep 27, 2026
Merged

flavorjones merged 1 commit into
masterfrom
fix-dependabot-537

Conversation

@flavorjones

Copy link
Copy Markdown
Member

Motivation

Dependabot security updates scan every Gemfile.lock in the repository, including the fixture bundles under spec/bundle/ that are deliberately vulnerable so the specs can assert the advisories are reported.

On spec/bundle/insecure_sources the job fails outright. The lockfile pins Rails 6.1, so websocket-driver cannot reach the fixed 0.8.2, and Dependabot reports security_update_not_possible. That is the broken run in #462. Elsewhere it opens pull requests that defeat the fixture, such as #456.

Details

Add a bundler entry covering the three deliberately-vulnerable fixture directories, ignoring every dependency. ignore applies to security updates as well as version updates, so this suppresses both. open-pull-requests-limit: 0 would not, because security updates are exempt from that limit.

spec/bundle/secure is left out on purpose: it asserts a clean scan, so its dependencies should keep being updated.

Additional information

Dependabot alerts on the fixture lockfiles come from the dependency graph and are unaffected by this change. Silencing those would need auto-triage rules in repository settings.

🤖 Generated with Claude Code

@jasnow
jasnow requested a review from simi September 22, 2026 22:58

@jasnow jasnow left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Comment thread .github/dependabot.yml Outdated
Dependabot security updates scanned every Gemfile.lock in the repo,
including the spec fixtures that are deliberately vulnerable. The job
failed on spec/bundle/insecure_sources, where websocket-driver has no
reachable fixed version, and elsewhere it opened pull requests that
defeat the fixture (#456).

Ignore every dependency in the three vulnerable fixture directories.
spec/bundle/secure is left alone; it asserts a clean scan.

[Fix #462]

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Comment thread .github/dependabot.yml
default-days: 7

# These fixtures are insecure on purpose: the specs assert that the
# advisories are reported. See #462.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe share the full link over #462 reference?

@simi

simi commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

@flavorjones would you mind (if that makes sense) to remove the AI attribution from commit itself? 🤔

@flavorjones
flavorjones merged commit 527edf4 into master Sep 27, 2026
11 checks passed
@flavorjones
flavorjones deleted the fix-dependabot-537 branch September 27, 2026 14:03
@flavorjones

Copy link
Copy Markdown
Member Author

@simi Sorry - this got merged before your comments registered. In future I will omit AI attribution.

@simi

simi commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

@simi Sorry - this got merged before your comments registered. In future I will omit AI attribution.

No worries, all good.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants