Skip to content

chore: remove stale Dependabot references from workflow comments - #47

Merged
ryota-murakami merged 1 commit into
mainfrom
cursor/remove-dependabot-refs-f2d7
Sep 10, 2026
Merged

ryota-murakami merged 1 commit into
mainfrom
cursor/remove-dependabot-refs-f2d7

Conversation

@ryota-murakami

@ryota-murakami ryota-murakami commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Dependabot was already disabled in #? (commit dbdbb25) by deleting .github/dependabot.yml and the auto-merge workflow. This PR cleans up the remaining references in CI/release workflow comments.

Changes

  • Remove Dependabot mention from ci.yml SHA-pin comment
  • Remove Dependabot mention from release.yml SHA-pin comment

Notes

No functional changes — comments only.

Open in Web Open in Cursor 

Summary by CodeRabbit

  • Chores
    • Updated continuous integration and release workflow documentation to clarify that action references are SHA-pinned for tag-hijack protection.

Dependabot config was already removed; update CI and release workflow
comments so they no longer mention .github/dependabot.yml.

Co-authored-by: dojce1048 <dojce1048@gmail.com>
@vercel

vercel Bot commented Sep 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
react-flow-scrollbar-docs Error Error Sep 10, 2026 12:34pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 01451fc0-474f-4856-a6ef-5c4158e39fb5

📥 Commits

Reviewing files that changed from the base of the PR and between aa43914 and 959f8ea.

📒 Files selected for processing (2)
  • .github/workflows/ci.yml
  • .github/workflows/release.yml

📝 Walkthrough

Walkthrough

The CI and release workflow comments now describe SHA-pinned action references without stating that Dependabot maintains the pins.

Changes

Workflow comment cleanup

Layer / File(s) Summary
Update action pinning comments
.github/workflows/ci.yml, .github/workflows/release.yml
The comments retain the SHA-pinning explanation and remove the Dependabot maintenance statement.

Estimated code review effort: 1 (Trivial) | ~2 minutes

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/remove-dependabot-refs-f2d7

A rabbit checks the workflow lines
The SHA pins guard the designs
Dependabot claims hop away
Clear comments mark the way
CI and release both stay spry

Comment @coderabbitai help to get the list of available commands.

@ryota-murakami
ryota-murakami marked this pull request as ready for review September 10, 2026 12:35
@ryota-murakami
ryota-murakami merged commit b25f27d into main Sep 10, 2026
5 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants