From 80fbbf8a10692313242ca11bab95425de450fd2d Mon Sep 17 00:00:00 2001 From: Maria Carter Date: Thu, 1 Oct 2026 21:42:23 +0200 Subject: [PATCH] dependabot-validate: the registry-names pipeline is best-effort, as its comment promised Under bash -e with pipefail, the names pipeline returned 1 whenever build.log had no npm error line naming a package, which is every clean run. The step died there, silently, before result.json was written, so every clean Dependabot PR has had a red validate check since v1.15.0 while PRs with a real peer-dependency failure got through to a proper report. Fixes #69 (the dev-smoke diagnosis there was wrong: dev-smoke never ran, there is no agent-validate.json on that repo). --- .github/workflows/dependabot-validate.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/dependabot-validate.yml b/.github/workflows/dependabot-validate.yml index d381784..c396105 100644 --- a/.github/workflows/dependabot-validate.yml +++ b/.github/workflows/dependabot-validate.yml @@ -152,7 +152,10 @@ jobs: names="$( { printf '%s\n' "$PR_BODY" | grep -oE '^Bumps \[[^]]+\]' | sed 's/^Bumps \[//; s/\]$//' printf '%s\n' "$PR_BODY" | tr '\140' '"' | grep -oE 'Updates "[^"]+"' | sed 's/^Updates "//; s/"$//' grep '^npm error' "$LOG" | grep -oE '(@[a-z0-9._-]+/)?[a-z0-9._-]+@' | sed 's/@$//' - } 2>/dev/null | grep -E '^(@[a-z0-9][a-z0-9._-]*/)?[a-z0-9][a-z0-9._-]*$' | awk '!seen[$0]++' | head -20 )" + } 2>/dev/null | grep -E '^(@[a-z0-9][a-z0-9._-]*/)?[a-z0-9][a-z0-9._-]*$' | awk '!seen[$0]++' | head -20 || true )" + # `|| true` is load-bearing: the step runs under bash -e, and with pipefail the pipeline above + # returns 1 whenever the log has no `npm error pkg@` line — i.e. on every CLEAN run — which + # killed the step silently before result.json was written (every clean Dependabot PR red, v1.15.0–v1.17.0). : > registry.ndjson for n in $names; do if timeout 20 npm view --json -- "$n" name version dist-tags peerDependencies > n.json 2>/dev/null \