Skip to content

chore(ci): keep Dependabot security updates off the deliberately vulnerable fixture - #188

Merged
Rwanbt merged 1 commit into
mainfrom
fix/dependabot-fixture-ignore
Sep 17, 2026
Merged

Rwanbt merged 1 commit into
mainfrom
fix/dependabot-fixture-ignore

Conversation

@Rwanbt

@Rwanbt Rwanbt commented Sep 17, 2026

Copy link
Copy Markdown
Owner

Resolves the false positive behind #155. No code, no AC.

stack/agents/anti-debt/tests/corpus/fixtures/fixture4-py-secure/requirements.txt pins requests==2.18.0 on purpose: it is a scanner target whose EXPECTED_FINDINGS.json expects the dependency scanner to detect the known-vulnerable pin. Dependabot's security updates (which do not need a dependabot.yml entry) therefore proposed to 'fix' the fixture (#155) and raised five alerts on it.

  • Adds a scoped pip entry for the fixture directory with ignore: requests (GitHub documents ignore as covering version and security updates), with the WHY inline.
  • The five alerts are dismissed with a pointer to the fixture's purpose; the alerts' history stays auditable.
  • The github-actions entry is unchanged.

@Rwanbt
Rwanbt merged commit 2fc8091 into main Sep 17, 2026
52 checks passed
@Rwanbt
Rwanbt deleted the fix/dependabot-fixture-ignore branch September 17, 2026 10:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant