Keep Dependabot NuGet updates behind the HL7 pin and the internal mirror - #5870
Merged
Mikael Weaver (mikaelweave) merged 2 commits intoSep 24, 2026
Merged
Conversation
The Hl7.Fhir.* ignore rule stops Dependabot proposing Firely SDK updates, but it still bumps an ignored package when another update requires it. #5869 moved Microsoft.Health.Fhir.Anonymizer.* from 4.1.1.3 to 4.3.3.5, whose nuspec requires Hl7.Fhir.Base, Hl7.Fhir.R4 and Hl7.Fhir.STU3 >= 5.12.0, so the pinned Hl7FhirVersion went from 5.11.4 to 5.12.0 with it. Anonymizer 4.2.2.5 still requires only 5.11.3, so ignore >= 4.3 rather than freezing the package outright. Ignixa.Extensions.FirelySdk5 also depends on Hl7.Fhir.Base and can do the same; that is left updating by choice, and the props comment says to close such a PR. AB#207007 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4d055287-83a3-4073-979e-207b73aa028b
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #5870 +/- ##
==========================================
+ Coverage 78.67% 78.99% +0.32%
==========================================
Files 1020 1020
Lines 37371 37375 +4
Branches 5716 5718 +2
==========================================
+ Hits 29401 29524 +123
+ Misses 6540 6447 -93
+ Partials 1430 1404 -26 🚀 New features to boost your workflow:
|
Some consumers of this repository restore packages through mirrors that hold back newly published NuGet versions for about a week. If Dependabot bumps a package to a version still inside that window, those consumers cannot restore it. Dependabot's built-in cooldown is only 3 days. Raise the NuGet cooldown to 8 days, a little past a week so the two clocks cannot race, and to 14 days for major versions. Security updates are exempt from cooldown by design, so a security bump can still reference a version a mirror has not released yet. AB#207007 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4d055287-83a3-4073-979e-207b73aa028b
Mikael Weaver (mikaelweave)
force-pushed
the
mikaelweave-pin-anonymizer-for-hl7
branch
from
September 24, 2026 14:09
83cc08a to
7badf65
Compare
Paul Taladay (PTaladay)
approved these changes
Sep 24, 2026
Mikael Weaver (mikaelweave)
deleted the
mikaelweave-pin-anonymizer-for-hl7
branch
September 24, 2026 15:33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two Dependabot NuGet fixes: stop Anonymizer from dragging the
Hl7.Fhirpin forward, and give package mirrors time to catch up before proposing new versions.AB#207007
1. Block Anonymizer ≥ 4.3
#5869 bumped
Hl7FhirVersion5.11.4 → 5.12.0 despite theHl7.Fhir.*ignore rule from #5863.ignorestops Dependabot proposing an update, but it still bumps an ignored package when another update requires it. #5869 movedMicrosoft.Health.Fhir.Anonymizer.*4.1.1.3 → 4.3.3.5, which requires Firely ≥ 5.12.0:Hl7.Fhir.BaseIgnoring
>= 4.3still lets Anonymizer move to 4.2.2.5. Lift it together with theHl7.Fhir.*rule.Known gap:
Ignixa.Extensions.FirelySdk5also depends onHl7.Fhir.Base. It's left updating by choice; close any Ignixa PR that drags HL7 forward. The props comment says so.2. NuGet cooldown: 8 days, 14 for majors
Some consumers of this repository restore through package mirrors that hold back newly published NuGet versions for about a week. Dependabot's built-in cooldown is only 3 days, so it could bump a package to a version those mirrors can't serve yet.
8 days sits a little past a week so the two clocks can't race.
Verification
Hl7.Fhir.*.>= 4.3checked withGem::Requirement(what Dependabot's NuGet parser uses): 4.2.2.5 allowed, 4.3.3.5 / 4.4 / 5.0 blocked. Rule matches exactly the 2 Anonymizer packages.default-daysandsemver-major-days(options reference). Other ecosystems unchanged.ValidateDependabotCoveragepasses.After merge
Close #5869. It regenerates without the Anonymizer and HL7 bumps.