Skip to content

fix(deps): ignore nix-lib in dependabot nix updates - #733

Merged
Teebor-Choka merged 2 commits into
mainfrom
kauki/fix/dependabot/nix-lib-ignore
Jul 30, 2026
Merged

fix(deps): ignore nix-lib in dependabot nix updates#733
Teebor-Choka merged 2 commits into
mainfrom
kauki/fix/dependabot/nix-lib-ignore

Conversation

@Teebor-Choka

Copy link
Copy Markdown
Contributor

Dependabot's nix ecosystem support rewrites version-pinned flake.nix refs and proposed a downgrade of nix-lib from v1.3.0 to v1.2.0 (hoprnet/hoprnet#8281), breaking tests that rely on runNextest added in v1.3.0. Adds an ignore rule so Dependabot skips nix-lib version pins; upgrades remain manual alongside any breaking API changes.

Dependabot's nix support rewrites version-pinned flake.nix refs and
proposed a downgrade nix-lib v1.3.0 → v1.2.0 (hoprnet#8281), breaking
tests using runNextest added in v1.3.0. Exclude nix-lib from automated
updates.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017xim73dASEdW3DsqawZ9aT
@Teebor-Choka Teebor-Choka self-assigned this Jul 30, 2026
@coderabbitai

coderabbitai Bot commented Jul 30, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@Teebor-Choka, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 28 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: a75879c9-3d0f-4a71-bf7e-77ecea10aa5d

📥 Commits

Reviewing files that changed from the base of the PR and between 8d8d095 and 249b9d9.

📒 Files selected for processing (1)
  • .github/dependabot.yml
📝 Walkthrough

Walkthrough

Updated the Dependabot Nix configuration to ignore automated updates for the nix-lib dependency in the root directory. Added comments documenting version-pinned reference comparison behavior and noting that related upgrades are managed manually.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly matches the change: ignoring nix-lib Dependabot updates in the Nix ecosystem.
Description check ✅ Passed The description is directly related to the changeset and explains the Dependabot ignore rule and why it was added.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 30, 2026

Copy link
Copy Markdown

🔎 Trivy Security Report

Target Package Installed Severity CVE
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) c-ares 1.34.6-r0 HIGH CVE-2026-33630
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) curl 8.17.0-r1 HIGH CVE-2026-5773
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) curl 8.17.0-r1 HIGH CVE-2026-6276
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) libcrypto3 3.5.6-r0 HIGH CVE-2026-45447
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) libcurl 8.17.0-r1 HIGH CVE-2026-5773
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) libcurl 8.17.0-r1 HIGH CVE-2026-6276
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) libexpat 2.7.5-r0 HIGH CVE-2026-45186
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) libexpat 2.7.5-r0 HIGH CVE-2026-56131
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) libexpat 2.7.5-r0 HIGH CVE-2026-56408
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) libssl3 3.5.6-r0 HIGH CVE-2026-45447
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) libxml2 2.13.9-r0 HIGH CVE-2026-6732
europe-west3-docker.pkg.dev/hoprassociation/docker-images/hopr-admin:4.0.0-rc.2-commit.249b9d9-linux-amd64 (alpine 3.23.4) nghttp2-libs 1.68.0-r0 HIGH CVE-2026-27135

@Teebor-Choka
Teebor-Choka marked this pull request as ready for review July 30, 2026 20:58
@Teebor-Choka
Teebor-Choka merged commit ecc5497 into main Jul 30, 2026
17 of 19 checks passed
@Teebor-Choka
Teebor-Choka deleted the kauki/fix/dependabot/nix-lib-ignore branch July 30, 2026 20:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant