Repository navigation
fix: keep Dependabot registry configuration credential-free - #2053
Conversation
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
markstuart-oai
left a comment
There was a problem hiding this comment.
Approved at ad6c3be64bd3dc1b642b555fe6fa811dd833133e.
Removing the anonymous registry entry leaves all 13 hosted fixtures on public npm. The existing integration setup owns the temporary Verdaccio override. It reads every original file before writing, restores partial writes, and reports cleanup failures while retaining the setup error. The change adds no credentials and preserves the existing dependency-update policies.
All current hosted checks pass, including the Node 22 and 24.3.x test jobs. This was a source and hosted-CI review; I did not rerun the repository tests. Hosted Dependabot acceptance still needs verification after merge, and the separate app-authored PR gate remains unchanged.
|
Follow-up #2060 addresses the hosted |
GitHub rejected the anonymous
npm-registryentry introduced in #2052. Remove that entry and keep all 13 integration fixtures pointed at public npm in the committed configuration. Existing integration-test setup temporarily routes@openaipackages to local Verdaccio and restores the original files on teardown or partial setup failure. No credentials, package versions, compatibility exclusions, cooldowns, or Actions permissions change.Regression tests cover all 13 hosted configs, effective npm registry selection, byte-exact restoration, unavailable registry, read-before-write, partial writes, and restoration failures. Both independent review rounds found no actionable defects. Current Deno 2.9.7 and Bun 1.4.2 binaries (official release asset digests verified) also requested synthetic package metadata from the local registry with the temporary config; an expected 404 prevented package installation.
Validation: six focused tests, schema/no-custom-registry assertions, install, package build, type checks, declaration checks, lint, and formatting passed. The full local test run had 7,817 passing tests and 12 failures in unchanged tests caused by injected proxy warnings, Docker access/mount limitations, and macOS ACL permissions. Required GitHub CI must provide full-suite evidence; no tests or security checks are disabled. Hosted Dependabot configuration acceptance must be checked after merge separately from PR CI.
Maintainer/security review requested for registry configuration and integration setup restoration. Actions-token PR creation/approval remains enabled pending the separate live app-authored version-PR validation.