diff --git a/.planning/ROADMAP.md b/.planning/ROADMAP.md index d5f68dd..5366af2 100644 --- a/.planning/ROADMAP.md +++ b/.planning/ROADMAP.md @@ -549,3 +549,16 @@ Plans: Plans: - [ ] TBD (promote with /gsd-review-backlog when ready) + +### Phase 999.18: Update dependencies as found during CI (BACKLOG) + +**Goal:** [Captured for future planning] When the CI dependency-audit gate (Phase 16) surfaces outdated or vulnerable packages, bump them rather than letting the report accumulate. Establish a lightweight, recurring "act on the CI dependency report" loop so the two-person household app doesn't drift onto stale/CVE-bearing deps. Scope is the upkeep workflow (review → bump → verify gate green), not a one-time audit. + +**Context:** Captured 2026-06-13 during Phase 10 work. Companion to the audit *reporting* shipped in Phase 16 (CI Dependency Audit) — that phase makes outdated/vulnerable deps *visible*; this item is the standing follow-through to *resolve* what it finds. Tags: ci, dependencies, maintenance, security, upkeep. + +**Requirements:** TBD +**Plans:** 0 plans + +Plans: + +- [ ] TBD (promote with /gsd-review-backlog when ready) diff --git a/.planning/phases/999.18-update-dependencies-as-found-during-ci/.gitkeep b/.planning/phases/999.18-update-dependencies-as-found-during-ci/.gitkeep new file mode 100644 index 0000000..e69de29