
The Ceiling I Never Wrote
A pip install fixed it. Then a measured bisect showed the line between working and breaking sat in a dependency, not in my code. And along the way, twelve copies of a five-line function became a single helper.
4 posts

A pip install fixed it. Then a measured bisect showed the line between working and breaking sat in a dependency, not in my code. And along the way, twelve copies of a five-line function became a single helper.

Nine libraries, a test runner major bump and a GitHub action updated in a single day. What it took to merge 11 dependabot pull requests on the Portfolio without breaking the suite — and the one that almost turned into a false alarm.

The alarm hunts, the gate blocks, the dog attacks. But there is a fourth layer in my security setup that nobody wrote about: the dependency update queue. On August 31st, the bot delivered five fix proposals. Three days later, all five are still open. The queue became the surface.

pnpm audit on the Portfólio screamed 61 vulnerabilities. Instead of updating dependency by dependency or trusting audit fix, I solved it with 5 lines of pnpm.overrides in package.json. Result: 61 → 2, with the remaining 2 having no published fix at all.