Skip to content

Keep Dependabot NuGet updates behind the HL7 pin and the internal mirror - #5870

Merged
Mikael Weaver (mikaelweave) merged 2 commits into
mainfrom
mikaelweave-pin-anonymizer-for-hl7
Sep 24, 2026
Merged

Mikael Weaver (mikaelweave) merged 2 commits into
mainfrom
mikaelweave-pin-anonymizer-for-hl7

Conversation

@mikaelweave

@mikaelweave Mikael Weaver (mikaelweave) commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Two Dependabot NuGet fixes: stop Anonymizer from dragging the Hl7.Fhir pin forward, and give package mirrors time to catch up before proposing new versions.

AB#207007

1. Block Anonymizer ≥ 4.3

#5869 bumped Hl7FhirVersion 5.11.4 → 5.12.0 despite the Hl7.Fhir.* ignore rule from #5863. ignore stops Dependabot proposing an update, but it still bumps an ignored package when another update requires it. #5869 moved Microsoft.Health.Fhir.Anonymizer.* 4.1.1.3 → 4.3.3.5, which requires Firely ≥ 5.12.0:

Anonymizer requires Hl7.Fhir.Base
4.1.1.3 (current) ≥ 5.11.3
4.2.2.5 ≥ 5.11.3
4.3.3.5 ≥ 5.12.0

Ignoring >= 4.3 still lets Anonymizer move to 4.2.2.5. Lift it together with the Hl7.Fhir.* rule.

Known gap: Ignixa.Extensions.FirelySdk5 also depends on Hl7.Fhir.Base. It's left updating by choice; close any Ignixa PR that drags HL7 forward. The props comment says so.

2. NuGet cooldown: 8 days, 14 for majors

Some consumers of this repository restore through package mirrors that hold back newly published NuGet versions for about a week. Dependabot's built-in cooldown is only 3 days, so it could bump a package to a version those mirrors can't serve yet.

8 days sits a little past a week so the two clocks can't race.

⚠️ Security updates skip cooldown by design, so a security bump can still reference a version a mirror hasn't released yet.

Verification

  • Anonymizer nuspecs read from the Microsoft Health OSS feed. Scanned every catalog package in the local NuGet cache: only Anonymizer and Ignixa.Extensions.FirelySdk5 depend on Hl7.Fhir.*.
  • >= 4.3 checked with Gem::Requirement (what Dependabot's NuGet parser uses): 4.2.2.5 allowed, 4.3.3.5 / 4.4 / 5.0 blocked. Rule matches exactly the 2 Anonymizer packages.
  • NuGet supports both default-days and semver-major-days (options reference). Other ecosystems unchanged.
  • YAML and XML parse, ValidateDependabotCoverage passes.

After merge

Close #5869. It regenerates without the Anonymizer and HL7 bumps.

The Hl7.Fhir.* ignore rule stops Dependabot proposing Firely SDK updates, but
it still bumps an ignored package when another update requires it. #5869 moved
Microsoft.Health.Fhir.Anonymizer.* from 4.1.1.3 to 4.3.3.5, whose nuspec
requires Hl7.Fhir.Base, Hl7.Fhir.R4 and Hl7.Fhir.STU3 >= 5.12.0, so the pinned
Hl7FhirVersion went from 5.11.4 to 5.12.0 with it.

Anonymizer 4.2.2.5 still requires only 5.11.3, so ignore >= 4.3 rather than
freezing the package outright.

Ignixa.Extensions.FirelySdk5 also depends on Hl7.Fhir.Base and can do the same;
that is left updating by choice, and the props comment says to close such a PR.

AB#207007

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4d055287-83a3-4073-979e-207b73aa028b
@codecov-commenter

Codecov Comments Bot (codecov-commenter) commented Sep 23, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 78.99%. Comparing base (275828c) to head (7badf65).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #5870      +/-   ##
==========================================
+ Coverage   78.67%   78.99%   +0.32%     
==========================================
  Files        1020     1020              
  Lines       37371    37375       +4     
  Branches     5716     5718       +2     
==========================================
+ Hits        29401    29524     +123     
+ Misses       6540     6447      -93     
+ Partials     1430     1404      -26     

see 18 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mikaelweave Mikael Weaver (mikaelweave) changed the title Stop Anonymizer updates from dragging the Hl7.Fhir pin forward Keep Dependabot NuGet updates behind the HL7 pin and the internal mirror Sep 24, 2026
Some consumers of this repository restore packages through mirrors that hold
back newly published NuGet versions for about a week. If Dependabot bumps a
package to a version still inside that window, those consumers cannot restore
it.

Dependabot's built-in cooldown is only 3 days. Raise the NuGet cooldown to 8
days, a little past a week so the two clocks cannot race, and to 14 days for
major versions.

Security updates are exempt from cooldown by design, so a security bump can
still reference a version a mirror has not released yet.

AB#207007

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4d055287-83a3-4073-979e-207b73aa028b
@mikaelweave
Mikael Weaver (mikaelweave) force-pushed the mikaelweave-pin-anonymizer-for-hl7 branch from 83cc08a to 7badf65 Compare September 24, 2026 14:09
@mikaelweave
Mikael Weaver (mikaelweave) merged commit b319676 into main Sep 24, 2026
49 of 51 checks passed
@mikaelweave
Mikael Weaver (mikaelweave) deleted the mikaelweave-pin-anonymizer-for-hl7 branch September 24, 2026 15:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants