Skip to content

Commit 805ac59

Browse files
committed
fix: resolve CI failures for security audit, PR title validation, and dependabot noise
- Update npm overrides: minimatch 10.2.1→10.2.4, add fast-xml-parser 5.3.9 - Add --omit=dev to security:audit (aws-cdk-lib bundles vulnerable minimatch as a bundledDependency that overrides cannot fix; it's a devDep, not shipped) - Add statuses:write permission to pr-title.yml (fixes "Resource not accessible by integration" error on all human PRs) - Group dependabot PRs: @aws-sdk/*, @smithy/*, @aws-cdk/*, github-actions into single PRs; reduce open-pull-requests-limit 20→10
1 parent ca5644f commit 805ac59

4 files changed

Lines changed: 154 additions & 2927 deletions

File tree

.github/dependabot.yml

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,14 @@ updates:
55
schedule:
66
interval: 'weekly'
77
groups:
8+
aws-sdk:
9+
patterns:
10+
- '@aws-sdk/*'
11+
- '@smithy/*'
12+
aws-cdk:
13+
patterns:
14+
- '@aws-cdk/*'
15+
- 'aws-cdk-lib'
816
dev-dependencies:
917
dependency-type: 'development'
1018
patterns:
@@ -13,14 +21,20 @@ updates:
1321
- 'prettier*'
1422
- 'vitest*'
1523
- '@trivago/*'
24+
- '@typescript-eslint/*'
25+
- 'typescript-eslint'
1626
commit-message:
1727
prefix: 'chore'
1828
include: 'scope'
19-
open-pull-requests-limit: 20
29+
open-pull-requests-limit: 10
2030

2131
- package-ecosystem: 'github-actions'
2232
directory: '/'
2333
schedule:
2434
interval: 'weekly'
35+
groups:
36+
github-actions:
37+
patterns:
38+
- '*'
2539
commit-message:
2640
prefix: 'ci'

.github/workflows/pr-title.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,9 @@ on:
55
branches: [main, feat/gateway-integration]
66
types: [opened, edited, synchronize, reopened]
77

8+
permissions:
9+
statuses: write
10+
811
jobs:
912
validate-pr-title:
1013
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)