Engineering operations

War-game a dependency pinning policy before upgrades drift

War-game a dependency pinning policy by testing whether pin rules, upgrade cadence, and ownership still keep builds reproducible when a critical CVE lands and a team wants to "just bump" under deadline pressure.

Pinning policies fail when lockfiles are treated as optional, when transitive upgrades land without review, and when no owner can explain why a version is frozen. The session should freeze one rule for direct pins, one rule for transitive updates, and the decisions that fire when a security patch conflicts with a freeze.

Lock the policy inputs

Write which ecosystems are covered, how lockfiles are enforced in CI, who may change a pin, the review path for major upgrades, and the exception path for emergency patches. Attach the current lockfiles for the critical services, the last three unplanned bumps with outcomes, and the measured rebuild time after a pin change. If private registries or mirrored packages constrain the story, put those constraints in the same packet.

Name the decision the policy is meant to support: keep builds reproducible, control blast radius on upgrades, or hold a train until a CVE response is named. Without that decision, the policy becomes decorative.

Seat pressure on the pins

Release manager
Defends train stability and whether an unpinned bump can enter a freeze window.
Security engineer
Challenges CVE response timing and whether pins block a required patch.
DevOps lead
Tests whether CI actually fails on lockfile drift and who can waive it.
Service owner
Shows which upgrades are already half-committed in local branches.
Skeptic
Finds the strongest "we pin everything" claim with the weakest enforcement proof.

Force upgrade decisions under pressure

In Pingpong, run cases where a CVE requires a major bump mid-freeze, a transitive package drifts without a lockfile change, a mirror is unavailable, and a "non-breaking" bump later breaks a shared library. For each case, start from the policy language. Ask who can approve an emergency unpin and which evidence is required. Any exception without an owner becomes a planning gap.

Replay last quarter's unplanned bumps under today's rules. If a historical bump would have looked allowed while later causing a known outage, revise the policy before the next train.

Pair with a dependency upgrade stress test, the release manager seat, and a hotfix criteria review. Browse the war-game decisions hub for related engineering controls.

Clear the policy only after two independent readers can recompute allow or deny from the same lockfile and ticket fields and reach the same label.