Skip to content

Update Managed Files#341

Merged
cmmarslender merged 1 commit into
mainfrom
managed-files
Apr 2, 2026
Merged

Update Managed Files#341
cmmarslender merged 1 commit into
mainfrom
managed-files

Conversation

@ChiaAutomation
Copy link
Copy Markdown
Contributor

@ChiaAutomation ChiaAutomation commented Apr 2, 2026

Note

Medium Risk
Touches the Dependabot review workflow’s malware scanning script; mistakes could cause false negatives/positives or broken CI for dependency PRs. Changes are mostly mechanical refactors, but they impact security-signal generation.

Overview
Improves the dependabot-cursor-review.yml upstream malware scan step by refactoring bash helpers to avoid local -n nameref usage, passing allowlists as explicit arguments instead.

Tightens scan execution flow by guarding several rg-based heuristics behind a non-empty file list, and makes a small semver parsing tweak to ignore the patch component when evaluating large version jumps.

Reformats malware-scan env inputs to YAML folded scalars (no behavioral change intended) for consistency/readability.

Written by Cursor Bugbot for commit 9fbb33e. This will update automatically on new commits. Configure here.

@ChiaAutomation ChiaAutomation requested a review from a team April 2, 2026 16:21
@cmmarslender cmmarslender merged commit fcdf877 into main Apr 2, 2026
67 checks passed
@cmmarslender cmmarslender deleted the managed-files branch April 2, 2026 16:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants