From 3225127f7b35d46160fb3babe6ad8dca23c5abc9 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 6 Oct 2026 21:45:41 +0000 Subject: [PATCH 1/4] [CHORE](deps)(deps): Bump lowlydba/sustainable-npm from 3.0.0 to 4.0.0 Bumps [lowlydba/sustainable-npm](https://github.com/lowlydba/sustainable-npm) from 3.0.0 to 4.0.0. - [Release notes](https://github.com/lowlydba/sustainable-npm/releases) - [Commits](https://github.com/lowlydba/sustainable-npm/compare/31d51025884f424f58f22e4e6578178bb4e79632...4cc1da285e5a589a7b3816122f791c21ec6ff3e6) --- updated-dependencies: - dependency-name: lowlydba/sustainable-npm dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/ci.yml | 4 ++-- .github/workflows/production_deploy_documentation.yml | 2 +- .github/workflows/staging_deploy.yaml | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 261446d1..f117be4a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -28,7 +28,7 @@ jobs: node-version-file: package.json - name: Configure sustainable npm - uses: lowlydba/sustainable-npm@31d51025884f424f58f22e4e6578178bb4e79632 # v3.0.0 + uses: lowlydba/sustainable-npm@4cc1da285e5a589a7b3816122f791c21ec6ff3e6 # v4.0.0 - name: Install NPM dependencies run: npm ci @@ -51,7 +51,7 @@ jobs: node-version-file: package.json - name: Configure sustainable npm - uses: lowlydba/sustainable-npm@31d51025884f424f58f22e4e6578178bb4e79632 # v3.0.0 + uses: lowlydba/sustainable-npm@4cc1da285e5a589a7b3816122f791c21ec6ff3e6 # v4.0.0 - name: Install NPM dependencies run: npm ci diff --git a/.github/workflows/production_deploy_documentation.yml b/.github/workflows/production_deploy_documentation.yml index e3eb0600..8c6419d4 100644 --- a/.github/workflows/production_deploy_documentation.yml +++ b/.github/workflows/production_deploy_documentation.yml @@ -34,7 +34,7 @@ jobs: node-version-file: package.json - name: Configure sustainable npm - uses: lowlydba/sustainable-npm@31d51025884f424f58f22e4e6578178bb4e79632 # v3.0.0 + uses: lowlydba/sustainable-npm@4cc1da285e5a589a7b3816122f791c21ec6ff3e6 # v4.0.0 - name: Install NPM dependencies run: npm ci --prefer-dedupe diff --git a/.github/workflows/staging_deploy.yaml b/.github/workflows/staging_deploy.yaml index c586c0b3..79299116 100644 --- a/.github/workflows/staging_deploy.yaml +++ b/.github/workflows/staging_deploy.yaml @@ -48,7 +48,7 @@ jobs: with: node-version-file: 'package.json' - - uses: lowlydba/sustainable-npm@31d51025884f424f58f22e4e6578178bb4e79632 # v3.0.0 + - uses: lowlydba/sustainable-npm@4cc1da285e5a589a7b3816122f791c21ec6ff3e6 # v4.0.0 - run: npm ci --omit=dev From 5a25ae5200280aae2ff9e0e21623da5e4b0ba6b4 Mon Sep 17 00:00:00 2001 From: John McCall <16843041+lowlydba@users.noreply.github.com> Date: Wed, 7 Oct 2026 09:27:56 -0400 Subject: [PATCH 2/4] Update ci.yml Signed-off-by: John McCall <16843041+lowlydba@users.noreply.github.com> --- .github/workflows/ci.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f117be4a..424f43f8 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -65,7 +65,7 @@ jobs: npx --yes wait-on@9 --timeout 60000 http://localhost:3000/ - name: Run accessibility tests - uses: lowlysre/pa11y-ci-action@9cfc00c514ae1d06afa84ce15d3959f8bbca2e73 # v1.0.0 + uses: lowlysre/pa11y-ci-action@84174759cd514bd3ea3bcaa30dc1798dde81f713 # v1.1.0 query-tests: name: DuckDB query smoke tests From 5500823b541a6193b38a6bf9ef252276623fc44e Mon Sep 17 00:00:00 2001 From: John McCall Date: Wed, 7 Oct 2026 09:40:27 -0400 Subject: [PATCH 3/4] [DOCS] Shorten blog list preview of workshop post Move the truncate marker so axe can resolve the background on /blog/. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: John McCall --- blog/2026-10-06-cng-workshop.mdx | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/blog/2026-10-06-cng-workshop.mdx b/blog/2026-10-06-cng-workshop.mdx index 1aa5fe0b..5786c4cb 100644 --- a/blog/2026-10-06-cng-workshop.mdx +++ b/blog/2026-10-06-cng-workshop.mdx @@ -16,10 +16,11 @@ You do have a model. You just wrote it in a place nothing else can read. The dat We had the same problem at Overture, at a larger scale. The [Overture Schema]() started as JSON Schema, hand-written as YAML, with reference docs written separately and validation that only ran on JSON. When the schema changed, the docs had to catch up by hand, and they didn't always. So we asked how we could write the model so that the data, the validation, and the reference material all derive from it and can't diverge. Our answer was code. [Last month we published v2.0.0 of the schema]() as a Python library built on Pydantic. The model is the source, and the JSON Schema, the reference docs, and the validation checks are all generated from it. +{/* truncate */} + This post follows the workshop we're teaching today at the [CNG Forum in Snowbird](). If you're in the room, it's the written version of what we're doing together. If you're not, it's an invitation: the packages are on PyPI, the workshop material is in [a public repo](https://github.com/OvertureMaps/workshop/tree/cng-snowbird) with a [Codespace that has everything installed](https://bit.ly/4jH4Rp8), and you can work through it on your own data. It's written for people on their own data modeling journey: you have a model you built, one you inherited, or one that's implicit in how your data happens to look, and it isn't working as well as you'd like. You want something that holds together better and fits with other datasets and tools. -{/* truncate */} ## Background: JSON Schema and Pydantic From c60dbe81c23c417feac5d97558fdb0fc6e69d6b7 Mon Sep 17 00:00:00 2001 From: John McCall Date: Wed, 7 Oct 2026 09:40:28 -0400 Subject: [PATCH 4/4] [CHORE] Group minor/patch npm prod and GitHub Actions dependabot updates Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: John McCall --- .github/dependabot.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 2c993be6..6363220f 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -31,6 +31,13 @@ updates: - "react*" - "@testing-library/react" - "@mdx-js/react" + prod-minor-patch: + dependency-type: "production" + update-types: + - "minor" + - "patch" + patterns: + - "*" cooldown: default-days: 7 @@ -49,6 +56,12 @@ updates: docker: patterns: - "docker/*" + gha-minor-patch: + update-types: + - "minor" + - "patch" + patterns: + - "*" labels: - "bot" commit-message: