Skip to content

ci: maintain native lockfiles for both apps - #1631

Draft
mrousavy wants to merge 1 commit into
ci/group-app-dependency-updatesfrom
ci/maintain-benchmark-lockfiles
Draft

ci: maintain native lockfiles for both apps#1631
mrousavy wants to merge 1 commit into
ci/group-app-dependency-updatesfrom
ci/maintain-benchmark-lockfiles

Conversation

@mrousavy

@mrousavy mrousavy commented Sep 7, 2026

Copy link
Copy Markdown
Member

Stacked on #1626.

Dependency lock maintenance currently refreshes only the example app, and Gemfile-only updates do not trigger it. Refresh and stage both apps' Gemfile.lock and Podfile.lock files, and include Gemfile/Gemfile.lock changes in the pull-request paths.

Apply the same two-app loop to the release lockfile hook, with explicit lockfile staging and its existing best-effort behavior.

Validation: actionlint, ShellCheck, Bash syntax, and diff checks pass. Disposable fixtures exercised the actual workflow shell commands before publishing and the release hook: both apps' commands and all five staged lockfiles are correct; CI stops on an install failure while the release hook continues. App script paths and Gemfile triggers were also checked.

The live maintenance job runs only for dependabot[bot], so it will skip this human-authored PR. Native dependency installation and bot publishing still need validation on a Dependabot PR.

@vercel

vercel Bot commented Sep 7, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
nitro-docs Ready Ready Preview Sep 7, 2026 7:03pm UTC

Request Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant