Skip to content

revert: undo the Renovate session and pause automation - #800

Merged
lilienblum merged 3 commits into
mainfrom
lilienblum/alien-370-revert-session
Sep 30, 2026
Merged

lilienblum merged 3 commits into
mainfrom
lilienblum/alien-370-revert-session

Conversation

@lilienblum

@lilienblum lilienblum commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Reverts the Renovate session's merged changes from #784, #792, #795, and #796 while preserving unrelated commits.

Merged current main to resolve the conflict with #780. Its sandbox Dockerfile ignorePaths are retained in the restored renovate.json, so the unrelated sandbox toolchain exclusions survive the rollback.

Removes the self-hosted runner and its repair scripts and restores the previous Renovate configuration and repair workflow. Hosted Renovate remains disabled with enabled: false, and the restored repair job is paused with an explicit false condition.

Keeps the SDK lockfile aligned with its unchanged manifest instead of restoring the pre-session TypeScript mismatch. Regenerated it with npm install --package-lock-only --ignore-scripts --offline --no-audit --no-fund; it matches the valid lockfile on main exactly.

Validation:

  • Independently replayed all four reverse patches and compared the full repository tree. Only the automation pause, retained valid SDK lockfile, and preserved sandbox exclusions differ from that inverse. The complete diff against current main contains only the eight rollback files.
  • SDK npm ci --ignore-scripts --offline --no-audit --no-fund and TypeScript build passed. The clean install and TypeScript build passed again after merging main with Node 24.21.0 and a 12 GiB heap.
  • Workflow syntax validated with actionlint, supplying the existing Depot runner labels and ignoring the deliberate constant-false pause warning. git diff --check and the commit hooks passed.

All six original review threads have documented dispositions: the SDK lockfile was regenerated, and the repaired workflow plus hosted bot remain disabled. The privileged repair trust boundary must be reviewed before any future re-enablement. GitHub CI and automated reviews must run against the new head. This PR has not been merged.

Puts the Renovate config and the lockfile repair workflow back to where they were before this session.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T07:56:15.479390Z bdd7df2 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@greptile-apps

greptile-apps Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Disables automated dependency updates and restructures the workflow.

The PR appears safe to merge with dependency automation paused.

Summary

The PR rolls back the self-hosted Renovate session while retaining the sandbox Dockerfile exclusions from main. Hosted Renovate remains disabled, and the restored lockfile-repair job is paused. The SDK lockfile mismatch identified in the previous review has been corrected.

Reviews (2) · Last reviewed commit: "chore: merge main and preserve sandbox R..."

Comment thread .github/workflows/repair-renovate-lockfiles.yml Outdated
Comment thread client-sdks/platform/typescript/package-lock.json
Comment thread .github/workflows/repair-renovate-lockfiles.yml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bdd7df22b5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread renovate.json
Comment thread renovate.json
Comment thread client-sdks/platform/typescript/package-lock.json Outdated
@lilienblum lilienblum changed the title revert: revert the Renovate session revert: undo the Renovate session and pause automation Sep 30, 2026
@lilienblum

Copy link
Copy Markdown
Contributor Author

@greptile review

@lilienblum
lilienblum merged commit 2b35aed into main Sep 30, 2026
21 checks passed
@lilienblum
lilienblum deleted the lilienblum/alien-370-revert-session branch September 30, 2026 09:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant