Skip to content

Guardrails / build

Dependency updates are automated ​

build/dependency-updates-configured@v1

The repository configures a tool that opens dependency updates, so upgrades arrive as pull requests you can review instead of as a chore nobody has time for.

Idbuild/dependency-updates-configured
Versionv1
Categorybuild
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsfiles

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
filesPresence, size and line counts of the well known files a repository is expected to carry, plus any extra path the guardrail asks for.paths

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "build/dependency-updates-configured@v1",
              "severity": "warning",
              "with": {
                  "paths": ".github/dependabot.yml,.github/dependabot.yaml,renovate.json,renovate.json5,.renovaterc,.renovaterc.json,.github/renovate.json"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
pathsComma separated paths, any one of which satisfies the guardrail..github/dependabot.yml,.github/dependabot.yaml,renovate.json,renovate.json5,.renovaterc,.renovaterc.json,.github/renovate.jsonGUARDRAIL_INPUT_PATHS

How to fix ​

Configure Dependabot with .github/dependabot.yml:

yaml
version: 2
updates:
  - package-ecosystem: gradle
    directory: "/"
    schedule:
      interval: weekly
  - package-ecosystem: github-actions
    directory: "/"
    schedule:
      interval: weekly

Renovate, configured with renovate.json, works just as well. Either way, each upgrade arrives as a pull request your tests run against, which is the only form in which it competes for attention with the rest of the work. A dependency nobody automates gets upgraded when a vulnerability forces it, and that is the worst moment to jump several major versions at once.

More in build ​

  • build/gradle-version-floor. The Gradle version the wrapper pins is at or above the floor your team sets, so the build runs on a toolchain that is still supported.
  • build/runs-on-hosted-ci. The artifact was built on a CI platform, not on someone's workstation, so the build is attributable and repeatable.
  • build/wrapper-distribution-verified. The Gradle wrapper pins the checksum of the distribution it downloads, so nobody can swap the toolchain underneath the build.

All 4 build guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412