From 6e4f54aa5d1d415c0ef506b1b36e37d0dc996da1 Mon Sep 17 00:00:00 2001 From: David Gamero Date: Thu, 13 Aug 2026 13:59:27 -0400 Subject: [PATCH] chore: enforce 7-day dependency freshness period and check signed commits (#277) Adopts the dependency bake period standardized in aks-set-context #258, k8s-lint #228 and k8s-bake #295: newly published packages are not picked up until they have been available for at least 7 days. - dependabot: 7-day cooldown, scheduled on the 1st and 15th via cron, with minor/patch grouped into one PR so majors still get individual review. - .npmrc: min-release-age=7 applies the same rule to local installs. - adds the shared check_signed_commits reusable workflow. Matches k8s-bake and deliberately omits the engines/engine-strict npm guard used by the two earlier repos. Node 24 (this action's runtime) bundles npm 11.17, so the gate would only fire for contributors already off the target runtime, and dependabot's cooldown enforces the bake server-side regardless of anyone's local npm. --- .github/dependabot.yml | 20 ++++++++++++++++---- .github/workflows/check-signed-commits.yml | 12 ++++++++++++ .npmrc | 1 + README.md | 21 +++++++++++++++++++++ 4 files changed, 50 insertions(+), 4 deletions(-) create mode 100644 .github/workflows/check-signed-commits.yml create mode 100644 .npmrc diff --git a/.github/dependabot.yml b/.github/dependabot.yml index d806d99..daf937c 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -3,16 +3,28 @@ updates: - package-ecosystem: npm directory: / schedule: - interval: weekly + interval: cron + cronjob: '0 8 1,15 * *' + cooldown: + default-days: 7 groups: - actions: + minor-and-patch: patterns: - '*' + update-types: + - minor + - patch - package-ecosystem: github-actions directory: .github/workflows schedule: - interval: weekly + interval: cron + cronjob: '0 8 1,15 * *' + cooldown: + default-days: 7 groups: - actions: + minor-and-patch: patterns: - '*' + update-types: + - minor + - patch diff --git a/.github/workflows/check-signed-commits.yml b/.github/workflows/check-signed-commits.yml new file mode 100644 index 0000000..a8fdb30 --- /dev/null +++ b/.github/workflows/check-signed-commits.yml @@ -0,0 +1,12 @@ +name: Check Signed Commits + +on: + pull_request: + +permissions: + contents: read + pull-requests: write + +jobs: + signed: + uses: Azure/action-release-workflows/.github/workflows/check_signed_commits.yaml@2ff084415c5af591fd13d95ddbfc4cdb5ed2012e diff --git a/.npmrc b/.npmrc new file mode 100644 index 0000000..7253a5c --- /dev/null +++ b/.npmrc @@ -0,0 +1 @@ +min-release-age=7 diff --git a/README.md b/README.md index 5f46487..11cc970 100644 --- a/README.md +++ b/README.md @@ -94,6 +94,27 @@ kubectl get secret -n -o yaml resource-group: ``` +## Development + +This repository enforces a **7-day dependency freshness ("bake") period**: newly +published npm packages are not adopted until they have been available for at +least 7 days, giving the ecosystem time to catch broken or malicious releases. + +- **Dependabot** uses a 7-day `cooldown` and opens PRs on the 1st and 15th of + each month, grouping minor/patch updates into a single PR. Major updates are + still raised individually so they get their own review. +- **`.npmrc`** sets `min-release-age=7` (days), which applies the same rule to + local `npm install`. This requires npm >= 11.10.0; the version bundled with + Node 24 (this action's runtime) satisfies that. On older npm the setting is + ignored, so Dependabot's `cooldown` remains the authoritative control. + +**Security exception:** to adopt an urgent patch that is less than 7 days old, +install it once with the age check disabled: + +```sh +npm install --min-release-age=0 +``` + ## Contributing This project welcomes contributions and suggestions. Most contributions require you to agree to a