Skip to content

Fix dashboard dependency policy and CI review findings - #19

Merged
oliveirara merged 1 commit into
mainfrom
fix/dashboard-dependency-policy
Oct 4, 2026
Merged

oliveirara merged 1 commit into
mainfrom
fix/dashboard-dependency-policy

Conversation

@oliveirara

@oliveirara oliveirara commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Dependabot PR #18 upgrades TypeScript to 7.0.2, but typescript-eslint 8.71.0 requires >=4.8.4 <6.1.0, so its CI fails during npm ci with ERESOLVE. It also advances Node types to version 26 while the runtime remains Node 24. This keeps automatic updates within the supported compiler/runtime ranges and applies the verified CodeRabbit findings from #17.

  • Restrict TypeScript to 6.0 patches in the manifest and ignore Dependabot proposals outside the supported TypeScript/Node type ranges. Other dependency updates remain enabled.
  • Disable persisted checkout credentials in CI and deployment; neither build job needs authenticated Git after checkout.
  • Require the exact 28 footprint IDs in the build artifact. Add regression coverage for reordered valid manifests, missing/duplicate/unexpected IDs, and missing overlay files.
  • Document the dependency policy and remove an extraneous lockfile entry.

Validation: lint without warnings, type checking, five Node regression tests, Python exporter test, production build with 31,569 objects, isolated clean-install/fixture build, artifact checks and Actionlint.

PR #18 should not be merged as currently proposed. These policy changes prevent equivalent future proposals after this PR is merged; they do not retroactively change the existing Dependabot PR. The previous deployment on main completed successfully.

Summary by CodeRabbit

  • Maintenance
    • Updated dependency update limits to keep TypeScript and Node.js type definitions within supported versions.
    • Improved checkout security in dashboard and deployment workflows by preventing credential persistence.
  • Quality Improvements
    • Strengthened build checks to validate required footprint layers and files, with coverage for missing, duplicate, and unexpected entries.
  • Documentation
    • Clarified TypeScript version requirements and when compatibility settings should be reviewed.

@oliveirara oliveirara self-assigned this Oct 4, 2026
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 17836ec9-1e69-40c0-b2bc-11740bc45989
📥 Commits

Reviewing files that changed from the base of the PR and between 088754b and 583366e.

⛔ Files ignored due to path filters (1)
  • dashboard/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (7)
  • .github/dependabot.yml
  • .github/workflows/dashboard-ci.yml
  • .github/workflows/deploy.yml
  • dashboard/README.md
  • dashboard/package.json
  • dashboard/scripts/check-build.mjs
  • dashboard/tests/check-build.test.mjs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The dashboard dependency policy now limits TypeScript and Node type updates. Two workflows disable persisted checkout credentials. The build checker accepts a supplied build directory and verifies the expected footprint layer IDs, with tests for manifest contents and required assets.

Changes

Dashboard dependency constraints

Layer / File(s) Summary
TypeScript update policy
.github/dependabot.yml, dashboard/package.json, dashboard/README.md
The TypeScript development dependency is limited to the 6.0 patch series. Dependabot ignores TypeScript versions >=6.1.0 and @types/node versions >=25.0.0. The README describes the version constraints and related migration notes.

Dashboard build validation

Layer / File(s) Summary
Build checker and validation tests
dashboard/scripts/check-build.mjs, dashboard/tests/check-build.test.mjs
The checker accepts a build directory argument and verifies the expected 28 footprint layer IDs. Tests cover order-independent acceptance, missing, duplicate, and unexpected IDs, and a missing border file.

Workflow checkout credentials

Layer / File(s) Summary
Checkout credential settings
.github/workflows/dashboard-ci.yml, .github/workflows/deploy.yml
Both workflows set checkout credential persistence to false.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 58336

The dependency range matches the lockfile, and no actionable merge-blocking issue is established in the reviewed changes. The PR is mergeable subject to normal checks.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (5 skipped: 5 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the dashboard dependency policy updates and CI fixes in the pull request.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (5 skipped: 5 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@oliveirara
oliveirara merged commit 41b465e into main Oct 4, 2026
2 checks passed
@oliveirara
oliveirara deleted the fix/dashboard-dependency-policy branch October 4, 2026 17:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant