Skip to content
d3 Wiki
07.05

Dependency and vulnerability updates

Stay patched without spending every Monday on version bumps.

Updated
Oct 3, 2026
On this page

Purpose

Stay patched without spending every Monday on version bumps.

The standard

  • Dependabot enabled on every repo: security updates immediately; version updates grouped weekly ([TEAM: Monday]).

  • Critical/high vulnerabilities: fix within 7 days; moderate within 30.

  • Lockfiles committed; CI fails on npm audit --audit-level=high / pip-audit.

  • Major version upgrades of framework or Supabase libraries get their own PR with a test pass and a preview check.

  • Plugins: track Revit/Rhino yearly releases; add the new target configuration within [TEAM: 60 days] of release.

Procedure — weekly

Owner merges green Dependabot PRs after a glance at changelogs; anything failing CI becomes an issue.

Owner: [TEAM] · Last reviewed: 2026-09