Skip to content

revert: revert the untested Renovate batch - #796

Merged
lilienblum merged 3 commits into
mainfrom
lilienblum/alien-370-revert-batch
Sep 30, 2026
Merged

lilienblum merged 3 commits into
mainfrom
lilienblum/alien-370-revert-batch

Conversation

@lilienblum

Copy link
Copy Markdown
Contributor

Pull request #795 moved packageManager to pnpm@10.34.6 while the workflows still install 10.34.5. GitHub merged it about twenty seconds after it opened, and the test jobs then failed in pnpm/action-setup.

This reverts that commit. Renovate no longer asks GitHub to auto-merge when the pull request opens. It merges on a later run, after the checks are green. pnpm updates are disabled because this token cannot update the version pinned in the workflow.

The batch moved packageManager to pnpm@10.34.6 while CI still installs 10.34.5. GitHub merged it before those jobs finished.
GitHub merged the batch as soon as the pull request opened. Renovate will merge on a later run, after the checks are green. pnpm stays at the version pinned in the workflow.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T06:32:15.755389Z 098c8b0 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@greptile-apps

greptile-apps Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Reverts dependency and build configuration changes.

The PR appears safe to merge, with a non-blocking concern about the deprecated HTTP handler restored in the pnpm lockfile.

Fix All in CodexFindings

  1. P2 Deprecated HTTP handler restored ▶
Fix with agent prompt
### Issue 1
pnpm-lock.yaml:2060
The rollback selects `@smithy/node-http-handler` 4.12.0, which its lockfile entry marks as deprecated for a memory leak. AWS-backed secret tests create an `SSMClient` for each write, so repeated writes in a long-lived test process risk accumulating resources. This is a non-blocking concern, but it could make those tests less reliable.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

The PR reverts the Renovate dependency batch, restores the pnpm version used by CI, and changes Renovate to merge after checks rather than requesting immediate platform auto-merge.

  • The Platform TypeScript lockfile now matches its committed TypeScript manifest.
  • One lower-impact concern remains: the rollback restores a deprecated HTTP handler used by AWS secret tests.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Renovate opens dependency PR] --> B[CI checks]
  B -->|green| C[Later Renovate run merges PR]
  D[pnpm updates] --> E[Disabled until workflow pin can move]
Loading

Reviews (2) · Last reviewed commit: "fix: align the platform SDK lockfile wit..."

Comment thread client-sdks/platform/typescript/package-lock.json Outdated
The revert restored a lockfile that resolved TypeScript 5.9.3 while package.json requires ~5.8.3.
@lilienblum

Copy link
Copy Markdown
Contributor Author

@greptileai Please re-review the current head 26fc375. The lockfile mismatch from the 4/5 review is fixed, its thread is resolved, and npm ci now passes.

Comment thread pnpm-lock.yaml
@lilienblum
lilienblum merged commit 4208809 into main Sep 30, 2026
29 checks passed
@lilienblum
lilienblum deleted the lilienblum/alien-370-revert-batch branch September 30, 2026 07:26
lilienblum added a commit that referenced this pull request Sep 30, 2026
Reverts the Renovate session's merged changes from #784, #792, #795, and
#796 while preserving unrelated commits.

Merged current main to resolve the conflict with #780. Its sandbox
Dockerfile ignorePaths are retained in the restored renovate.json, so
the unrelated sandbox toolchain exclusions survive the rollback.

Removes the self-hosted runner and its repair scripts and restores the
previous Renovate configuration and repair workflow. Hosted Renovate
remains disabled with `enabled: false`, and the restored repair job is
paused with an explicit false condition.

Keeps the SDK lockfile aligned with its unchanged manifest instead of
restoring the pre-session TypeScript mismatch. Regenerated it with `npm
install --package-lock-only --ignore-scripts --offline --no-audit
--no-fund`; it matches the valid lockfile on main exactly.

Validation:
- Independently replayed all four reverse patches and compared the full
repository tree. Only the automation pause, retained valid SDK lockfile,
and preserved sandbox exclusions differ from that inverse. The complete
diff against current main contains only the eight rollback files.
- SDK `npm ci --ignore-scripts --offline --no-audit --no-fund` and
TypeScript build passed. The clean install and TypeScript build passed
again after merging main with Node 24.21.0 and a 12 GiB heap.
- Workflow syntax validated with actionlint, supplying the existing
Depot runner labels and ignoring the deliberate constant-false pause
warning. `git diff --check` and the commit hooks passed.

All six original review threads have documented dispositions: the SDK
lockfile was regenerated, and the repaired workflow plus hosted bot
remain disabled. The privileged repair trust boundary must be reviewed
before any future re-enablement. GitHub CI and automated reviews must
run against the new head. This PR has not been merged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant