chore: enforce 7-day dependency freshness period and check signed commits (#277)

Adopts the dependency bake period standardized in aks-set-context #258,
k8s-lint #228 and k8s-bake #295: newly published packages are not picked
up until they have been available for at least 7 days.

- dependabot: 7-day cooldown, scheduled on the 1st and 15th via cron,
  with minor/patch grouped into one PR so majors still get individual
  review.
- .npmrc: min-release-age=7 applies the same rule to local installs.
- adds the shared check_signed_commits reusable workflow.

Matches k8s-bake and deliberately omits the engines/engine-strict npm
guard used by the two earlier repos. Node 24 (this action's runtime)
bundles npm 11.17, so the gate would only fire for contributors already
off the target runtime, and dependabot's cooldown enforces the bake
server-side regardless of anyone's local npm.
This commit is contained in:
David Gamero
2026-08-13 13:59:27 -04:00
committed by GitHub
parent 1d64d212a1
commit 6e4f54aa5d
4 changed files with 50 additions and 4 deletions
+16 -4
View File
@@ -3,16 +3,28 @@ updates:
- package-ecosystem: npm
directory: /
schedule:
interval: weekly
interval: cron
cronjob: '0 8 1,15 * *'
cooldown:
default-days: 7
groups:
actions:
minor-and-patch:
patterns:
- '*'
update-types:
- minor
- patch
- package-ecosystem: github-actions
directory: .github/workflows
schedule:
interval: weekly
interval: cron
cronjob: '0 8 1,15 * *'
cooldown:
default-days: 7
groups:
actions:
minor-and-patch:
patterns:
- '*'
update-types:
- minor
- patch
@@ -0,0 +1,12 @@
name: Check Signed Commits
on:
pull_request:
permissions:
contents: read
pull-requests: write
jobs:
signed:
uses: Azure/action-release-workflows/.github/workflows/check_signed_commits.yaml@2ff084415c5af591fd13d95ddbfc4cdb5ed2012e
+1
View File
@@ -0,0 +1 @@
min-release-age=7
+21
View File
@@ -94,6 +94,27 @@ kubectl get secret <service-account-secret-name> -n <namespace> -o yaml
resource-group: <resource-group>
```
## Development
This repository enforces a **7-day dependency freshness ("bake") period**: newly
published npm packages are not adopted until they have been available for at
least 7 days, giving the ecosystem time to catch broken or malicious releases.
- **Dependabot** uses a 7-day `cooldown` and opens PRs on the 1st and 15th of
each month, grouping minor/patch updates into a single PR. Major updates are
still raised individually so they get their own review.
- **`.npmrc`** sets `min-release-age=7` (days), which applies the same rule to
local `npm install`. This requires npm >= 11.10.0; the version bundled with
Node 24 (this action's runtime) satisfies that. On older npm the setting is
ignored, so Dependabot's `cooldown` remains the authoritative control.
**Security exception:** to adopt an urgent patch that is less than 7 days old,
install it once with the age check disabled:
```sh
npm install <pkg> --min-release-age=0
```
## Contributing
This project welcomes contributions and suggestions. Most contributions require you to agree to a