Stop Dependabot from updating the vulnerable spec fixtures - #463
Merged
Merged
Conversation
simi
reviewed
Sep 22, 2026
Dependabot security updates scanned every Gemfile.lock in the repo, including the spec fixtures that are deliberately vulnerable. The job failed on spec/bundle/insecure_sources, where websocket-driver has no reachable fixed version, and elsewhere it opened pull requests that defeat the fixture (#456). Ignore every dependency in the three vulnerable fixture directories. spec/bundle/secure is left alone; it asserts a clean scan. [Fix #462] Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
flavorjones
force-pushed
the
fix-dependabot-537
branch
from
September 27, 2026 13:59
029de44 to
0a1c54a
Compare
simi
reviewed
Sep 27, 2026
| default-days: 7 | ||
|
|
||
| # These fixtures are insecure on purpose: the specs assert that the | ||
| # advisories are reported. See #462. |
Contributor
There was a problem hiding this comment.
Maybe share the full link over #462 reference?
Contributor
|
@flavorjones would you mind (if that makes sense) to remove the AI attribution from commit itself? 🤔 |
Member
Author
|
@simi Sorry - this got merged before your comments registered. In future I will omit AI attribution. |
Contributor
No worries, all good. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Dependabot security updates scan every
Gemfile.lockin the repository, including the fixture bundles underspec/bundle/that are deliberately vulnerable so the specs can assert the advisories are reported.On
spec/bundle/insecure_sourcesthe job fails outright. The lockfile pins Rails 6.1, sowebsocket-drivercannot reach the fixed 0.8.2, and Dependabot reportssecurity_update_not_possible. That is the broken run in #462. Elsewhere it opens pull requests that defeat the fixture, such as #456.Details
Add a
bundlerentry covering the three deliberately-vulnerable fixture directories, ignoring every dependency.ignoreapplies to security updates as well as version updates, so this suppresses both.open-pull-requests-limit: 0would not, because security updates are exempt from that limit.spec/bundle/secureis left out on purpose: it asserts a clean scan, so its dependencies should keep being updated.Additional information
Dependabot alerts on the fixture lockfiles come from the dependency graph and are unaffected by this change. Silencing those would need auto-triage rules in repository settings.
🤖 Generated with Claude Code