Skip to content

ci: disable the swift Dependabot ecosystem until its image ships Swift 6.4 - #217

Merged
KevinTCoughlin merged 1 commit into
mainfrom
fix/dependabot-swift-toolchain-gate
Sep 24, 2026
Merged

KevinTCoughlin merged 1 commit into
mainfrom
fix/dependabot-swift-toolchain-gate

Conversation

@KevinTCoughlin

Copy link
Copy Markdown
Contributor

The problem

Dependabot's weekly swift run has failed every week since 2026-08-10 — seven consecutive runs — producing no PRs and no notification. A failed Dependabot run isn't a failed check on anything, so there's no red X anywhere; it's only visible via gh run list.

error: 'browsefeaturecore': package 'browsefeaturecore' is using Swift tools
version 6.4.0 but the installed version is 6.3.1

Dependabot resolves Swift packages inside its own container, and dependabot-core's swift/Dockerfile pins ARG SWIFT_VERSION=6.3.1. All 19 manifests under Packages/ are swift-tools-version: 6.4, so resolution aborts before reading a single dependency.

Why not just lower the tools version

Not available — and not for a taste reason. The manifests use PackageDescription API that doesn't exist before 6.4:

  • .iOS(.v26) as a platform
  • swiftSettings: [.defaultIsolation(MainActor.self)] in BrowseFeatureCore and SearchFeatureCore

A 6.3 toolchain wouldn't parse them. That would trade a failing updater for a tree that doesn't build.

What this does

Disables the ecosystem, commented out verbatim rather than deleted. The comments on that block are load-bearing — which directories exist only because Factory is exact-pinned and must move as a group, and why PlaybackEngineAudioStreaming is listed separately since #122. Re-deriving that later is how the factory group silently stops covering a directory.

Adds dependabot-swift-watch.yml to close the gap that disabling opens. Factory is exact: "3.3.2"-pinned in seven manifests and AudioStreaming exact: "1.4.4" in an eighth, and nothing watches them now — trading a silent failure for a silent gap would be no improvement. The watch polls that ARG SWIFT_VERSION line weekly and opens a single issue when it reaches 6.4. Same shape and reasoning as the existing runner-image-watch.yml; it costs ~15s of free ubuntu time.

It errors rather than reporting no-change if the ARG line ever moves upstream — a watch that quietly stops watching is precisely the failure it exists to prevent.

Verification

  • Extraction returns 6.3.1 against the live upstream Dockerfile.
  • sort -V comparison checked across 6.3/6.3.1/6.4/6.4.0/6.5/6.10/7.0/5.9 — 6.10 correctly ranks above 6.4.
  • actionlint clean on the new workflow (and on the unmodified runner-image-watch.yml as a baseline).
  • .github/dependabot.yml still parses; github-actions remains the only active ecosystem.

Note: this and runner-image-watch.yml are now waiting on the same Swift 6.4 / Xcode 27 transition from different directions. Neither should be closed assuming the other landing settled it.

🤖 Generated with Claude Code

https://claude.ai/code/session_013U8tNXdjZpFPUTWpABee5y

Dependabot's Swift updater resolves inside its own container, and
dependabot-core's swift/Dockerfile pins ARG SWIFT_VERSION=6.3.1. Every
manifest under Packages/ is swift-tools-version: 6.4, so resolution
aborts before reading a dependency:

  error: 'browsefeaturecore': package 'browsefeaturecore' is using Swift
  tools version 6.4.0 but the installed version is 6.3.1

This failed weekly from 2026-08-10 to 2026-09-21 — seven runs, no PRs,
no notification, because a failed Dependabot run is not a failed check
on anything.

Lowering the manifests is not available: they use PackageDescription API
that predates no earlier toolchain — .iOS(.v26) and
.defaultIsolation(MainActor.self) — so 6.3 would not parse them.

So the block is commented out verbatim rather than deleted (its comments
record why the directory list and the factory group are shaped as they
are), and dependabot-swift-watch.yml polls that ARG line weekly and
opens an issue when it reaches 6.4. The watch errors rather than
reporting no-change if the ARG line moves upstream.

Verified: extraction returns 6.3.1 against the live Dockerfile, sort -V
ranks 6.10 above 6.4, and actionlint is clean on the new workflow.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013U8tNXdjZpFPUTWpABee5y
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@KevinTCoughlin
KevinTCoughlin merged commit 791cfcd into main Sep 24, 2026
10 checks passed
@KevinTCoughlin
KevinTCoughlin deleted the fix/dependabot-swift-toolchain-gate branch September 24, 2026 05:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant