Skip to content

deal with dependabot updates and failures #12923

Description

@DaanHoogland

As a developer/release manager I would like for dependabot's updates to be applicable. At the moment all GHA for dependabot's PRs fail the updates do not seem to be appropriate even when the simplest tiny upgrades are attempted. It would be nice to be able to just apply these.
This situation mostly applies to the JS updates, but also mvn updates fail when attempted.

Activity

  1. added this to the 4.23.0 milestone on Mar 31, 2026
  2. dheeraj12347 commented on Apr 14, 2026

    @dheeraj12347
    Contributor

    I’d like to investigate why Dependabot PRs are failing (JS and Maven) and propose fixes to make these updates applicable. I’ll start by analyzing recent Dependabot PR CI logs.

  3. dheeraj12347 commented on Apr 20, 2026

    @dheeraj12347
    Contributor

    Hi @DaanHoogland
    I looked into a few recent Dependabot PRs to see why they’re failing CI.

    JS / UI PRs

    #13036 (dompurify 3.2.6 → 3.4.0 in /ui):

    build.yml passes; only “TestHook interrupted while sleeping” shows up in the logs.

    ui.yml fails in the codecov/codecov-action@v4 step. The Codecov CLI logs show {"message":"Token required because branch is protected"} for the branch dependabot/npm_and_yarn/ui/dompurify-3.4.0, and the action exits with code 1.

    I don’t see npm ci / npm run build failing here, so this looks like a Codecov + protected-branch issue, not a dompurify issue.

    #12987 (fast-xml-parser 4.3.0 → 4.5.6 in /ui):

    build.yml also passes with the same “TestHook interrupted while sleeping” messages.

    The red checks come from UI Build and simulator/coverage workflows, not from the main Maven build.

    Maven PRs

    #12916 (maven-dependency-plugin 3.9.0 → 3.10.0):

    ui.yml again fails at codecov/codecov-action@v4 with the same pattern: Codecov runs create-commit, gets HTTP 400 with {"message":"Token required because branch is protected"}, and fails the job.

    #12915 (org.springframework.version 5.3.26 → 7.0.6):

    ui.yml shows the same Codecov failure and Node 20 deprecation warning for codecov/codecov-action@v4.

    From these, it looks like many Dependabot PRs (JS and Maven) are being marked failed mainly because Codecov cannot operate on protected Dependabot branches without a token, and because of shared simulator/coverage workflow issues, rather than because the underlying dependency bumps immediately break the main build.

  4. winterhazel commented on May 7, 2026

    @winterhazel
    Member

    (copied from #13042)

    The failures seems to be related to https://github.com/codecov/codecov-action?tab=readme-ov-file#dependabot.

    @dependabot opens PRs from the original repository instead of a fork, which requires it to have access to the Codecov token for the coverage check to execute. The Codecov token is probably not present in the @dependabot secrets.

    We need to ask someone with enough permission to configure the @dependabot secrets and grant it access to the Codecov token.

  5. modified the milestones: 4.23.0, 4.24.0 on Jun 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Projects

Relationships

None yet

Development

No branches or pull requests

Issue actions