Skip to content

Cross-check dependabot ecosystems against the manifests each repo ships #360

Description

@exploreriii

🧑‍💻 Intermediate Issue — a complex task spanning multiple modules, with real design decisions to own.
Time: ~25 hours · Prerequisites: comfortable navigating this repo (a completed beginner issue is the usual route; demonstrated CI/CD proficiency substitutes for workflow-focused issues).
We expect more than "it works": maintainable code that fits the existing architecture.

The task

Blocked by #359 — the ci_health engine and findings contract must exist first.

Problem:

The audit checklist requires dependabot to cover all relevant ecosystems, but a presence check on .github/dependabot.yml can't see the real failure: a repo declaring pip while also shipping package.json, Dockerfiles, and GitHub Actions workflows. The gap between declared and needed ecosystems is the finding.

What done looks like:

A dependabot_ecosystems check in the ci_health engine: parse the repo's dependabot.yml (missing file = its own finding), detect present ecosystems from the same .github/tree fetch the engine already makes (no extra quota) — npm, pip/uv, docker, github-actions, gomod at minimum — and emit one findings row per uncovered ecosystem with the manifest path as evidence. Repos with no manifests for an ecosystem are na, not pass. Tests cover declared-but-unneeded, needed-but-undeclared, and no-config cases.

Modules involved / constraints: the ci_health pipeline from #359 (copy its seed-check pattern); ecosystem→manifest mapping should be data, not if-chains, since the supported-ecosystems list grows.

How to work on this

  1. Claim it: comment /assign and wait to be assigned — unassigned PRs are closed automatically.
  2. Get a plan: once assigned, comment @coderabbitai plan for a draft plan, then do your own investigation — docs/architecture.md maps the layers and their rules.
  3. Propose your approach as a comment before coding. A paragraph is enough; early feedback here routinely saves days of rework.

🤖 AI: tools are welcome; verified work is required — you can explain every line and defend every design choice. See the AI policy. Fully automated bot PRs are closed.

Worth knowing about this repo before you design:

  • The layer rules in docs/architecture.md are strict — review will hold your solution to them.
  • Tests mirror src (tests/<pkg>/test_<module>.py), and the output-contract test pins the pipeline output surface — if your change adds or renames outputs, update the contract deliberately.

Before opening your PR:

  • I proposed my approach on this issue and incorporated any feedback
  • The solution fits the existing architecture and layer rules, and is clear enough for others to debug without me
  • Tests cover the happy path, edge cases, and error handling (testing guide)
  • I reviewed my own diff line by line; scope is limited to this issue
  • Workflow checks pass — CI green, signed commits, linked issue

Stuck? Comment here with what you've tried — see getting help.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    intermediateA broader or larger issue requiring self-research and often, testing.pythonTouches Python code (src/, tests/)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions