mirror of
https://github.com/Azure/k8s-set-context.git
synced 2026-10-09 09:59:57 +08:00
chore: enforce 7-day dependency freshness period and check signed commits (#277)
Adopts the dependency bake period standardized in aks-set-context #258, k8s-lint #228 and k8s-bake #295: newly published packages are not picked up until they have been available for at least 7 days. - dependabot: 7-day cooldown, scheduled on the 1st and 15th via cron, with minor/patch grouped into one PR so majors still get individual review. - .npmrc: min-release-age=7 applies the same rule to local installs. - adds the shared check_signed_commits reusable workflow. Matches k8s-bake and deliberately omits the engines/engine-strict npm guard used by the two earlier repos. Node 24 (this action's runtime) bundles npm 11.17, so the gate would only fire for contributors already off the target runtime, and dependabot's cooldown enforces the bake server-side regardless of anyone's local npm.
This commit is contained in:
+16
-4
@@ -3,16 +3,28 @@ updates:
|
||||
- package-ecosystem: npm
|
||||
directory: /
|
||||
schedule:
|
||||
interval: weekly
|
||||
interval: cron
|
||||
cronjob: '0 8 1,15 * *'
|
||||
cooldown:
|
||||
default-days: 7
|
||||
groups:
|
||||
actions:
|
||||
minor-and-patch:
|
||||
patterns:
|
||||
- '*'
|
||||
update-types:
|
||||
- minor
|
||||
- patch
|
||||
- package-ecosystem: github-actions
|
||||
directory: .github/workflows
|
||||
schedule:
|
||||
interval: weekly
|
||||
interval: cron
|
||||
cronjob: '0 8 1,15 * *'
|
||||
cooldown:
|
||||
default-days: 7
|
||||
groups:
|
||||
actions:
|
||||
minor-and-patch:
|
||||
patterns:
|
||||
- '*'
|
||||
update-types:
|
||||
- minor
|
||||
- patch
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
name: Check Signed Commits
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
pull-requests: write
|
||||
|
||||
jobs:
|
||||
signed:
|
||||
uses: Azure/action-release-workflows/.github/workflows/check_signed_commits.yaml@2ff084415c5af591fd13d95ddbfc4cdb5ed2012e
|
||||
@@ -94,6 +94,27 @@ kubectl get secret <service-account-secret-name> -n <namespace> -o yaml
|
||||
resource-group: <resource-group>
|
||||
```
|
||||
|
||||
## Development
|
||||
|
||||
This repository enforces a **7-day dependency freshness ("bake") period**: newly
|
||||
published npm packages are not adopted until they have been available for at
|
||||
least 7 days, giving the ecosystem time to catch broken or malicious releases.
|
||||
|
||||
- **Dependabot** uses a 7-day `cooldown` and opens PRs on the 1st and 15th of
|
||||
each month, grouping minor/patch updates into a single PR. Major updates are
|
||||
still raised individually so they get their own review.
|
||||
- **`.npmrc`** sets `min-release-age=7` (days), which applies the same rule to
|
||||
local `npm install`. This requires npm >= 11.10.0; the version bundled with
|
||||
Node 24 (this action's runtime) satisfies that. On older npm the setting is
|
||||
ignored, so Dependabot's `cooldown` remains the authoritative control.
|
||||
|
||||
**Security exception:** to adopt an urgent patch that is less than 7 days old,
|
||||
install it once with the age check disabled:
|
||||
|
||||
```sh
|
||||
npm install <pkg> --min-release-age=0
|
||||
```
|
||||
|
||||
## Contributing
|
||||
|
||||
This project welcomes contributions and suggestions. Most contributions require you to agree to a
|
||||
|
||||
Reference in New Issue
Block a user