Skip to content

Commit efa46a8

Browse files
authored
build: focus Dependabot on security updates (#1759)
* build: focus Dependabot on security updates * build: limit PR validation to CFS restores * build: keep Dependabot updates for GitHub Actions * test: avoid flaky hover screenshot verification * build: validate locked dependencies with npm ci * test: align hover verification wording * build: disable scripts during CFS validation * test: edit single-file fixture inside main
1 parent 2082dc4 commit efa46a8

4 files changed

Lines changed: 31 additions & 20 deletions

File tree

‎.azure-pipelines/ci.yml‎

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,17 @@ trigger:
1616
branches:
1717
include:
1818
- main
19+
pr:
20+
branches:
21+
include:
22+
- main
23+
paths:
24+
include:
25+
- package.json
26+
- package-lock.json
27+
- .azure-pipelines/ci.yml
28+
- .azure-pipelines/npm-cfs.yml
29+
- .azure-pipelines/npm-cfs-variables.yml
1930
extends:
2031
template: v1/1ES.Unofficial.PipelineTemplate.yml@1esPipelines
2132
parameters:
@@ -33,8 +44,22 @@ extends:
3344
stages:
3445
- stage: Build
3546
jobs:
47+
- job: CFSValidation
48+
displayName: Validate dependencies from CFS
49+
condition: eq(variables['Build.Reason'], 'PullRequest')
50+
steps:
51+
- checkout: self
52+
fetchTags: false
53+
- task: NodeTool@0
54+
displayName: Use Node 20.x
55+
inputs:
56+
versionSpec: 20.x
57+
- template: /.azure-pipelines/npm-cfs.yml@self
58+
- script: npm ci --ignore-scripts --no-audit --no-fund
59+
displayName: Validate npm dependencies from CFS
3660
- job: Job_1
3761
displayName: Agent job 1
62+
condition: ne(variables['Build.Reason'], 'PullRequest')
3863
templateContext:
3964
outputs:
4065
- output: pipelineArtifact

‎.github/dependabot.yml‎

Lines changed: 0 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -1,22 +1,5 @@
1-
# To get started with Dependabot version updates, you'll need to specify which
2-
# package ecosystems to update and where the package manifests are located.
3-
# Please see the documentation for all configuration options:
4-
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
5-
61
version: 2
72
updates:
8-
- package-ecosystem: "npm" # See documentation for possible values
9-
directory: "/" # Location of package manifests
10-
schedule:
11-
interval: "daily"
12-
# CI restores packages from the Central Feed Service, which withholds
13-
# upstream versions until they are roughly a week old (measured at ~6.8
14-
# days; both the packument entry and the tarball return 404 before then).
15-
# Dependabot's built-in cooldown is only 3 days, so bumps otherwise land in
16-
# a window where the feed 404s and the build fails. 10 days leaves margin
17-
# in case the feed's ingestion lag drifts.
18-
cooldown:
19-
default-days: 10
203
- package-ecosystem: "github-actions"
214
directory: "/"
225
groups:

‎test-plans/java-go-to-super-implementation.yaml‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,9 +65,12 @@ steps:
6565
# being absent / not rendered as a clickable link).
6666
- id: "hover-greet"
6767
action: "hoverOnText greet"
68-
verify: "A hover popup is open over the overriding greet() method and it contains a clickable 'Go to super implementation' link"
68+
verify: "A hover popup is open over the overriding greet() method, ready for the following link action"
6969
waitBefore: 5
7070
timeout: 30
71+
# The popup can still show "Loading..." when the screenshot is captured on
72+
# macOS. The next step deterministically proves that the link is available.
73+
skipLlmVerify: true
7174

7275
# ── Click the hover link ──────────────────────────────────────
7376
# This is the regression assertion for #4438: the link must be a

‎test-plans/java-single-file.yaml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -57,8 +57,8 @@ steps:
5757

5858
# ── Step 4: Verify basic editing ────────────────────────────────
5959
- id: "goto-main"
60-
action: "goToLine 6"
61-
verify: "Cursor moved to main method"
60+
action: "goToLine 5"
61+
verify: "Cursor moved to the existing statement inside the main method"
6262

6363
- id: "goto-end"
6464
action: "goToEndOfLine"

0 commit comments

Comments
 (0)