Dependency Policy¶
ZapTrace uses standard package-manager metadata, lockfiles, and automated dependency review to select, obtain, and track dependencies.
Dependency sources¶
| Ecosystem | Source files |
|---|---|
| Python | pyproject.toml, uv.lock |
| Rust | zaptrace_core/Cargo.toml, zaptrace_core/Cargo.lock |
| Containers | Dockerfile, docker-compose.yml, requirements/container-runtime.txt, requirements/container-apk.txt |
| GitHub Actions | .github/workflows/*.yml |
Selection principles¶
New dependencies should be:
- necessary for a clear feature, security, or maintainability goal;
- actively maintained;
- compatible with the current PolyForm Noncommercial distribution model and any separately licensed third-party content;
- available from standard package indexes or trusted upstreams;
- pinned or locked where practical;
- reviewed with extra caution when they affect parsing, export, MCP/API, plugin execution, CI, or release workflows.
Tracking and update automation¶
uv.locktracks resolved Python dependencies.requirements/container-runtime.txtis a hash-complete export of the container runtime subset; CI rejects drift fromuv.lock.requirements/container-apk.txtrecords exact Alpine runtime package versions for the pinned base image.Cargo.locktracks resolved Rust dependencies.- Renovate produces dependency update and vulnerability-remediation pull requests.
- GitHub Dependabot alerts and dependency review remain enabled; routine Dependabot version-update PRs are not generated.
- Low-risk Renovate updates labeled
automerge:enabledjoin the protected Mergify queue only after all required checks succeed. Major, native, runtime-sensitive, security-labeled, CI and container changes require manual review. - Security scan workflows run dependency audit and static-analysis jobs.
- The locked Renovate configuration validator under
.github/renovate-validation/is a development/CI-only copy of the CLI, not the hosted Renovate bot. Its npmglobal-agent4.x override replaces the legacyglobal-agent3 ->roarr-> unpatchedsprintf-jschain; the override must be revalidated when Renovate changes its proxy APIs. Renovate 44.148.4 also includes the patched Handlebars 4.7.10 release. From the repository root, install the validator withnpm ci --prefix .github/renovate-validation --ignore-scripts --no-audit --no-fund, then run.github/renovate-validation/node_modules/.bin/renovate-config-validator --strictfrom that root directory. CI uses the equivalentworking-directoryfor installation. - Remaining upstream
braces<=3.0.3 recursive-pattern DoS risk in Renovate's validation-only dependency graph has no upstream patched release as of 2026-10-09; do not treat a clean GitHub Dependabot alert list as a comprehensive npm audit. Do not force an unreviewed third-party fork or downgrade Renovate to evade the advisory.
Review policy¶
Dependency update pull requests should include CI results and, for major/runtime-sensitive updates, release note review. Updates that touch parser, plugin, MCP/API, release, or CI behavior should be treated as security-sensitive until reviewed.
Release evidence¶
Official release workflows produce checksums and SBOM evidence and verify container build provenance that binds the source commit, pinned base digest, built wheel digest, and dependency-manifest digest. See Release Verification Guide.