Skip to content

Stop dependabot-validate's dev-smoke failing every Dependabot PR on theme repos #69

Description

@mcarter-astronautdev

Every Dependabot PR on foundrae-blackridge gets a red validate / validate check from dependabot-validate.yml@v1.17.0, so the check carries no signal there. Install, build and test all pass in its own build.log; the job then fails at dev-smoke ("crashed or no ready marker").

  • The repo's npm run dev is run-p dev:shopify dev:vite, and shopify theme dev needs the Shopify CLI credentials the validator deliberately withholds. dev-smoke can never come up on a theme repo. Proof it is not the bump: #206 changes two ruby/setup-ruby pin lines and no code, and fails identically to the 11-package npm bump in #207.
  • dev-smoke's output is not in the uploaded artifact, so the dependabot-report agent writes "cause not shown in the artifacts" and tells the reader to hold.
  • The validator ran Node 22.23 against a repo whose engines/.nvmrc say 24 (EBADENGINE warning). Read .nvmrc or engines.node before setup-node.

Options: let a caller input skip dev-smoke (or point it at dev:vite only), and ship the dev-smoke log in the artifact either way.

from: foundrae-blackridge, PRs #206 and #207

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    todoOne-off to-do captured from a session. Not a ticket.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions