dependabot-validate: clean Dependabot PRs no longer fail the validate check - #73
Merged
Merged
Conversation
…ts comment promised Under bash -e with pipefail, the names pipeline returned 1 whenever build.log had no npm error line naming a package, which is every clean run. The step died there, silently, before result.json was written, so every clean Dependabot PR has had a red validate check since v1.15.0 while PRs with a real peer-dependency failure got through to a proper report. Fixes #69 (the dev-smoke diagnosis there was wrong: dev-smoke never ran, there is no agent-validate.json on that repo).
ApprovabilityVerdict: Approved at Macroscope's review found this PR approvable — This is a focused CI workflow bug fix that lets clean Dependabot validations finish when no npm error package names are present. It does not change the validation verdict logic, production behavior, schemas, or deployment configuration. You can add or adjust custom eligibility rules. Learn more. |
This was referenced Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #69.
dependabot-validate.yml— the registry-names pipeline gets the|| trueits own comment promised. Underbash -ewithpipefailit returned 1 whenever the log had nonpm error <pkg>@line, which is every clean run, so the step died silently beforeresult.jsonwas written: every clean Dependabot PR has carried a redvalidate / validatesince v1.15.0, while PRs with a real peer-dependency failure got a proper report.Needs a release (v1.18.0), repin and wave to reach the fleet.