Skip to content

fix: keep Dependabot registry configuration credential-free - #2053

Merged
jbeckwith-oai merged 4 commits into
mainfrom
codex/agents-dependabot-public-registry
Oct 9, 2026
Merged

jbeckwith-oai merged 4 commits into
mainfrom
codex/agents-dependabot-public-registry

Conversation

@jbeckwith-oai

@jbeckwith-oai jbeckwith-oai commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

GitHub rejected the anonymous npm-registry entry introduced in #2052. Remove that entry and keep all 13 integration fixtures pointed at public npm in the committed configuration. Existing integration-test setup temporarily routes @openai packages to local Verdaccio and restores the original files on teardown or partial setup failure. No credentials, package versions, compatibility exclusions, cooldowns, or Actions permissions change.

Regression tests cover all 13 hosted configs, effective npm registry selection, byte-exact restoration, unavailable registry, read-before-write, partial writes, and restoration failures. Both independent review rounds found no actionable defects. Current Deno 2.9.7 and Bun 1.4.2 binaries (official release asset digests verified) also requested synthetic package metadata from the local registry with the temporary config; an expected 404 prevented package installation.

Validation: six focused tests, schema/no-custom-registry assertions, install, package build, type checks, declaration checks, lint, and formatting passed. The full local test run had 7,817 passing tests and 12 failures in unchanged tests caused by injected proxy warnings, Docker access/mount limitations, and macOS ACL permissions. Required GitHub CI must provide full-suite evidence; no tests or security checks are disabled. Hosted Dependabot configuration acceptance must be checked after merge separately from PR CI.

Maintainer/security review requested for registry configuration and integration setup restoration. Actions-token PR creation/approval remains enabled pending the separate live app-authored version-PR validation.

@jbeckwith-oai
jbeckwith-oai requested a review from a team as a code owner October 9, 2026 19:31
@changeset-bot

changeset-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: ad6c3be

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T19:34:20.449938Z ad6c3be PR opened
🔒 Security Review ✅ Completed 2026-10-09T19:34:26.662061Z ad6c3be PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved at ad6c3be64bd3dc1b642b555fe6fa811dd833133e.

Removing the anonymous registry entry leaves all 13 hosted fixtures on public npm. The existing integration setup owns the temporary Verdaccio override. It reads every original file before writing, restores partial writes, and reports cleanup failures while retaining the setup error. The change adds no credentials and preserves the existing dependency-update policies.

All current hosted checks pass, including the Node 22 and 24.3.x test jobs. This was a source and hosted-CI review; I did not rerun the repository tests. Hosted Dependabot acceptance still needs verification after merge, and the separate app-authored PR gate remains unchanged.

@jbeckwith-oai
jbeckwith-oai merged commit ffcba52 into main Oct 9, 2026
15 checks passed
@jbeckwith-oai
jbeckwith-oai deleted the codex/agents-dependabot-public-registry branch October 9, 2026 20:31
@jbeckwith-oai

Copy link
Copy Markdown
Contributor Author

Follow-up #2060 addresses the hosted misconfigured_tooling failure: Dependabot inferred pnpm from the ancestor lockfile even though the fixtures are intentionally independent. The pushed fix declares npm@11.12.1 in all 13 fixture manifests, using the deployed updater’s existing package-manager selection guard. It preserves public npm/local Verdaccio routing, runtime commands, dependency versions, and update policies. Seven focused tests and npm/Bun/Deno registry probes pass; required CI is pending. Actual hosted updater completion remains the post-merge acceptance check.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants