Repository navigation
ci: cover independent integration fixtures with Dependabot - #2052
Conversation
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed at 32b63678f476d47db3868647895dc86a870094f3. No blocking findings.
The configuration covers all 13 independent fixture manifests. The scoped public registry leaves local Verdaccio settings intact. Ordinary updates preserve the tested majors and exact client/compiler fixture; the version-only exclusions retain security-update eligibility.
The rebase preserves all reviewed source; current CI is still running. This was a source and upstream-semantics review, without installs or updater runs. Hosted Dependabot execution still needs this configuration on the default branch.
|
Follow-up #2053 corrects the hosted configuration rejection in check 113983259656. The anonymous npm registry entry has been removed; committed fixture configurations now use public npm. Existing integration setup temporarily selects local Verdaccio and restores the original files, with regression coverage for normal teardown and partial failures. No registry credentials or dependency-policy exceptions were added. The fix is pushed and awaiting required CI/review; hosted Dependabot acceptance must be verified after merge separately from PR CI. |
The 13 integration fixtures install independently of the root pnpm workspace, so the root Dependabot updater does not cover their manifests. Add dedicated monthly updaters with a seven-day ordinary-update cooldown and bounded, grouped version PRs.
Preserve dependency majors and the exact OpenAI-client/TypeScript compatibility oracle using version-update-only exclusions; security updates remain eligible without the ordinary cooldown. A scoped public npm registry mapping lets hosted Dependabot resolve
@openaipackages while keeping the fixtures' committed localhost/Verdaccio settings intact. Existing root and Actions coverage is unchanged. No package versions or lockfiles change.Validation: Dependabot JSON schema passed; seven focused configuration/mutation checks passed; two consecutive independent review rounds passed. The registry override was checked against GitHub documentation and upstream Dependabot registry/.npmrc handling. Hosted updater execution still requires the config to reach the default branch.
Stacked on #2051 to keep release authentication and updater coverage separately reviewable. Maintainer/security review requested for dependency-automation configuration.