From ca6947cfbf05654d7fec79258c3aa7cbf647a993 Mon Sep 17 00:00:00 2001 From: Lucas Berger Date: Sat, 13 Jun 2026 13:23:32 -0400 Subject: [PATCH] =?UTF-8?q?docs:=20add=20backlog=20item=20999.18=20?= =?UTF-8?q?=E2=80=94=20update=20dependencies=20as=20found=20during=20ci?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .planning/ROADMAP.md | 13 +++++++++++++ .../.gitkeep | 0 2 files changed, 13 insertions(+) create mode 100644 .planning/phases/999.18-update-dependencies-as-found-during-ci/.gitkeep diff --git a/.planning/ROADMAP.md b/.planning/ROADMAP.md index d5f68dd..5366af2 100644 --- a/.planning/ROADMAP.md +++ b/.planning/ROADMAP.md @@ -549,3 +549,16 @@ Plans: Plans: - [ ] TBD (promote with /gsd-review-backlog when ready) + +### Phase 999.18: Update dependencies as found during CI (BACKLOG) + +**Goal:** [Captured for future planning] When the CI dependency-audit gate (Phase 16) surfaces outdated or vulnerable packages, bump them rather than letting the report accumulate. Establish a lightweight, recurring "act on the CI dependency report" loop so the two-person household app doesn't drift onto stale/CVE-bearing deps. Scope is the upkeep workflow (review → bump → verify gate green), not a one-time audit. + +**Context:** Captured 2026-06-13 during Phase 10 work. Companion to the audit *reporting* shipped in Phase 16 (CI Dependency Audit) — that phase makes outdated/vulnerable deps *visible*; this item is the standing follow-through to *resolve* what it finds. Tags: ci, dependencies, maintenance, security, upkeep. + +**Requirements:** TBD +**Plans:** 0 plans + +Plans: + +- [ ] TBD (promote with /gsd-review-backlog when ready) diff --git a/.planning/phases/999.18-update-dependencies-as-found-during-ci/.gitkeep b/.planning/phases/999.18-update-dependencies-as-found-during-ci/.gitkeep new file mode 100644 index 0000000..e69de29