Skip to content

docs(ci): update dependabot-repair comments for the redirect sync pass (#986) - #989

Merged
drmoisan merged 2 commits into
mainfrom
bug/dependabot-repair-workflow-comments-986
Oct 9, 2026
Merged

drmoisan merged 2 commits into
mainfrom
bug/dependabot-repair-workflow-comments-986

Conversation

@drmoisan

@drmoisan drmoisan commented Oct 9, 2026

Copy link
Copy Markdown
Owner

Summary

  • Comment-only update to .github/workflows/dependabot-repair.yml (the "Repair package manifest consistency" step). There are no changes to YAML keys, expressions or script lines.
  • The comments now describe both binding-redirect passes:
  • They also explain why neither pass reaches the beyond-known-weak filter, and that WrittenPath covers every pass.

Why

The previous comments said the binding-redirect class is not reachable from the workflow_run trigger. #985 made that false. The behavior is correct; only the comments misled a reader.

Verification

  • Verified against scripts/dependencies/Repair-PackageManifestConsistency.ps1 lines 447-495:
    • The sync result is carried in RedirectSync, separate from Verification[].Report.Repair.
    • Its changed paths are added to WrittenPath.
  • No executable workflow line changed; git diff touches comment lines only.
  • The workflow's current behavior was exercised end-to-end on Dependabot PR Bump AngleSharp and 15 others #988:
    • Repair run 37984377202 pushed the fix.
    • CI run 37984842203 then passed all 7 required checks.
    • The next repair run, 37985385207, wrote nothing.

Review policy exception

The feature-review rule modified-workflow-needs-green-run cannot be satisfied for this file. The workflow runs only on workflow_run for dependabot/ branches and has no workflow_dispatch, so it cannot run against this branch head. The maintainer approved an exception for this comment-only change, and the next Dependabot PR exercises the file.

Risks and Mitigations

  • Risk: none to behavior; comments only. Rollback: revert the commit.

GitHub Auto-close

🤖 Generated with Claude Code

https://claude.ai/code/session_01Gw2R64FrQkj5f88mFAe3KA

#986)

The comments at the repair step still said the binding-redirect class never runs from the workflow_run trigger. The unconditional redirect sync pass added in #985 now rewrites stale redirects on every run and reports through RedirectSync, so describe both passes, why neither reaches the beyond-known-weak filter, and that WrittenPath covers every pass. Comment-only; no behavior change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Claude-Session: https://claude.ai/code/session_01Gw2R64FrQkj5f88mFAe3KA
R7 asserted the old phrase 'not reachable from the workflow_run trigger', which the comment rewrite removed. Assert the new wording instead: that redirect rewrites never count toward beyond-known-weak, and that supplying -CandidateUpgrade with the record kept means the clause must be restored.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Claude-Session: https://claude.ai/code/session_01Gw2R64FrQkj5f88mFAe3KA
@drmoisan
drmoisan merged commit 3f240a1 into main Oct 9, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: dependabot-repair-workflow-comments-predate-redirect-sync

1 participant