I just wanted to reply to say that the Dependabot automation has been helpful. 
It's a lot of work to manually review this kind of thing. Thank you for taking 
the time to automate it. I'd be interested in learning more about your setup, 
if you've written about it somewhere, or intend to.

Gian

On 2026/07/31 04:00:51 Frank Chen wrote:
> Hi everyone,
> 
> Previously I set up a local pipeline to use my Codex subscription to review
> all open PRs on a daily basis. It's really helpful as I see authors of PRs
> accept most of the comments raised by AI.
> 
> Now I'm using Codex to address two recurring maintenance challenges in
> Apache Druid.
> 
> First, Dependabot raises many dependency-upgrade PRs, most of them related
> to security vulnerabilities. Java dependency PRs frequently fail CI because
> the upgrade also requires updates to license declarations such as
> licenses.yaml. When this happens, the PR waits for human intervention.
> 
> Second, although CodeQL is configured, we rarely have enough time to
> investigate and resolve its findings. GitHub currently records
> approximately 3,900 security and code-quality findings. Some are false
> positives, but many are valid issues, and it is difficult to determine
> which findings should be addressed first.
> 
> This is where AI assistance can help. Thanks to the generous and frequent
> usage reset from OpenAI recently, I now have enough token budget to help
> address these problems.
> 
> Another local Codex-driven pipeline is set up to inspect Dependabot
> compatibility, investigate CI failures, propose or implement focused fixes,
> and run targeted validation.
> 
> For Dependabot PRs, the operating principles are:
> 
>    - Java and web-console dependency updates will generally be *APPROVED*
>    after CI passes and compatibility checks confirm that the upgrade is safe.
>    - Large or breaking upgrades will be *CLOSED* automatically. For
>    example, #19799 <https://github.com/apache/druid/pull/19799>, the Guice
>    6-to-7 upgrade, was closed because it would require a broader Jakarta
>    migration(even though we can use AI to help the migration but it would
>    require some extra work)
>    - Website dependency updates should follow #19788
>    <https://github.com/apache/druid/pull/19788>, which changes validation
>    to npm ci. Therefore, #19814 <https://github.com/apache/druid/pull/19814>
>    should be merged only after #19788.
> 
> Recently, I reviewed and merged the following 36 Dependabot PRs.
> Merged Java/Maven Dependabot PRs
> 
>    - #19794 <https://github.com/apache/druid/pull/19794> —
>    proto-google-common-protos 2.48.0 → 2.73.0
>    - #19795 <https://github.com/apache/druid/pull/19795> — JDBI 2.63.1 →
>    2.78
>    - #19796 <https://github.com/apache/druid/pull/19796> — AWS SDK 2.40.0 →
>    2.49.6
>    - #19797 <https://github.com/apache/druid/pull/19797> — Hamcrest 2.2 →
>    3.0
>    - #19798 <https://github.com/apache/druid/pull/19798> — Scrooge 19.10.0
>    → 21.2.0
>    - #19800 <https://github.com/apache/druid/pull/19800> — Rhino Engine
>    1.8.1 → 1.9.1
>    - #19777 <https://github.com/apache/druid/pull/19777> — Animal Sniffer
>    Maven Plugin 1.23 → 1.27
>    - #19780 <https://github.com/apache/druid/pull/19780> — Curator 5.8.0 →
>    5.9.0
>    - #19781 <https://github.com/apache/druid/pull/19781> — Quidem 0.11 →
>    0.12
>    - #19783 <https://github.com/apache/druid/pull/19783> — Avatica 1.27.0 →
>    1.28.0
>    - #19784 <https://github.com/apache/druid/pull/19784> — Async HTTP
>    Client 3.0.10 → 3.0.11
>    - #19785 <https://github.com/apache/druid/pull/19785> — Maven Assembly
>    Plugin 3.1.0 → 3.8.0
>    - #19786 <https://github.com/apache/druid/pull/19786> — Protobuf 4.33.0
>    → 4.35.1
>    - #18588 <https://github.com/apache/druid/pull/18588> — gRPC Netty
>    Shaded 1.65.1 → 1.75.0
>    - #18650 <https://github.com/apache/druid/pull/18650> — Protobuf 3.25.8
>    → 4.33.0
>    - #18714 <https://github.com/apache/druid/pull/18714> — Protobuf Maven
>    Plugin 3.7.0 → 3.10.2
>    - #18271 <https://github.com/apache/druid/pull/18271> — Maven Artifact
>    3.6.0 → 3.9.11
>    - #19756 <https://github.com/apache/druid/pull/19756> — LZ4 Java 1.10.2
>    → 1.11.1
>    - #19757 <https://github.com/apache/druid/pull/19757> — Jetty 12.1.8 →
>    12.1.11
>    - #19763 <https://github.com/apache/druid/pull/19763> — Thrift 0.13.0 →
>    0.23.0
>    - #19760 <https://github.com/apache/druid/pull/19760> — PostgreSQL
>    42.7.11 → 42.7.12
>    - #19764 <https://github.com/apache/druid/pull/19764> — Thrift 0.13.0 →
>    0.23.0
>    - #19546 <https://github.com/apache/druid/pull/19546> — Vert.x 4.5.24 →
>    4.5.27
>    - #19490 <https://github.com/apache/druid/pull/19490> — Commons
>    Configuration 2.10.1 → 2.15.0
>    - #19476 <https://github.com/apache/druid/pull/19476> — Async HTTP
>    Client 3.0.2 → 3.0.10
>    - #18956 <https://github.com/apache/druid/pull/18956> — AssertJ Core
>    3.24.2 → 3.27.7
> 
> Merged web-console Dependabot PRs
> 
>    - #19506 <https://github.com/apache/druid/pull/19506> —
>    serialize-javascript and terser-webpack-plugin
>    - #19708 <https://github.com/apache/druid/pull/19708> — Axios 1.15.2 →
>    1.18.0
>    - #19610 <https://github.com/apache/druid/pull/19610> — Webpack Dev
>    Server 5.2.2 → 5.2.6
>    - #19256 <https://github.com/apache/druid/pull/19256> — Lodash 4.17.21 →
>    4.18.1
>    - #19621 <https://github.com/apache/druid/pull/19621> — Form Data 4.0.5
>    → 4.0.6
>    - #19694 <https://github.com/apache/druid/pull/19694> — Websocket Driver
>    0.7.4 → 0.7.5
>    - #19710 <https://github.com/apache/druid/pull/19710> — Shell Quote
>    1.8.1 → 1.10.0
>    - #19733 <https://github.com/apache/druid/pull/19733> — Immutable 4.3.0
>    → 4.3.9
>    - #19761 <https://github.com/apache/druid/pull/19761> — ws
>    - #19762 <https://github.com/apache/druid/pull/19762> — HTTP Proxy
>    Middleware 2.0.9 → 2.0.10
> 
> I also used a one-time pipeline to raise PRs to address CodeQL problems.
> Besides addressing existing problems, some static checks rules have also
> been updated to prevent some problems in future.These PRs are listed as
> follows. If anyone can approve them, I will appreciate it.Security and
> dependency vulnerabilities
> 
>    - #19806 <https://github.com/apache/druid/pull/19806> — Exclude
>    vulnerable SnakeYAML from Cassandra storage
>    - #19807 <https://github.com/apache/druid/pull/19807> — Upgrade Nimbus
>    JOSE JWT
>    - #19808 <https://github.com/apache/druid/pull/19808> — Address Jackson
>    1 and Netty vulnerabilities
>    - #19809 <https://github.com/apache/druid/pull/19809> — Remove
>    vulnerable legacy LZ4 dependency
>    - #19812 <https://github.com/apache/druid/pull/19812> — Reject newlines
>    in redirect locations
>    - #19813 <https://github.com/apache/druid/pull/19813> — Guard segment
>    info paths against traversal
>    - #19814 <https://github.com/apache/druid/pull/19814> — Address website
>    dependency vulnerabilities
>    - #19815 <https://github.com/apache/druid/pull/19815> — Address
>    web-console dependency vulnerabilities
>    - #19822 <https://github.com/apache/druid/pull/19822> — Secure temporary
>    files and resource lookups
>    - #19828 <https://github.com/apache/druid/pull/19828> — Strengthen
>    cryptographic operations
> 
> CodeQL and code-quality improvements
> 
>    - #19816 <https://github.com/apache/druid/pull/19816> — Address
>    resource-lifetime warnings
>    - #19818 <https://github.com/apache/druid/pull/19818> — Harden
>    arithmetic and bounds checks
>    - #19819 <https://github.com/apache/druid/pull/19819> — Replace
>    deprecated JUnit assertions
>    - #19820 <https://github.com/apache/druid/pull/19820> — Address
>    control-flow and API warnings
>    - #19821 <https://github.com/apache/druid/pull/19821> — Detect unused
>    parameters and local variables
>    - #19823 <https://github.com/apache/druid/pull/19823> — Address nullness
>    and type warnings
>    - #19825 <https://github.com/apache/druid/pull/19825> — Disambiguate
>    method names and overloads
>    - #19826 <https://github.com/apache/druid/pull/19826> — Address
>    formatting warnings
>    - #19827 <https://github.com/apache/druid/pull/19827> — Address
>    concurrency warnings
>    - #19829 <https://github.com/apache/druid/pull/19829> — Remove redundant
>    Python assignments
> 
> Reliability and supporting work
> 
>    - #19810 <https://github.com/apache/druid/pull/19810> — Avoid sleeping
>    while holding lifecycle locks
>    - #19811 <https://github.com/apache/druid/pull/19811> — Release the
>    record-supplier lock on validation failure
>    - #19817 <https://github.com/apache/druid/pull/19817> — Wait for Kafka
>    partitions before publishing
>    - #19788 <https://github.com/apache/druid/pull/19788> — Use npm ci for
>    website checks
>    - #18301 <https://github.com/apache/druid/pull/18301> — Improve offset
>    auto-reset behavior
> 
> The goal is to make dependency and security maintenance more continuous and
> scalable while keeping compatibility assessment, breaking-change decisions,
> and final responsibility with human maintainers.
> 
> Best regards,
> Frank
> 

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to