build(deps): bump astro from 6.1.6 to 6.1.10 in /resources/js in the npm_and_yarn group across 1 directory#493
Merged
github-actions[bot] merged 1 commit intoMay 20, 2026
Conversation
This was referenced May 19, 2026
nash87
added a commit
that referenced
this pull request
May 19, 2026
… stuck PRs) (#511) **Closes task #11** (Dependabot fop/local-ci/pr gate architectural fix). Authored 2026-05-19 ~07:00 as part of the parkhub E2E fan-out. Initially staged behind the devalue 5.6.4 image-scan blocker (RESUME.md); now unblocked since PR #510 landed the devalue 5.8.1 fix on main. ## Architectural rationale `fop/local-ci/pr` is a required PAT-posted commit status set by a developer running `./scripts/fop-local-ci.sh` locally — which runs lefthook pre-push gates + posts the result. Dependabot bots commit from GitHub-side; no local developer means no `fop-local-ci.sh` invocation means no `fop/local-ci/pr: success` status. Result: PR sits MERGEABLE+BLOCKED indefinitely. **8 Dependabot PRs are stuck right now** by this exact gap: parkhub-php #493/#496/#498 + parkhub-rust #638/#639/#640/#641/#642. ## What this bridge does New GHA + Gitea-Actions workflow `dependabot-local-ci-bridge.yml` that: 1. Triggers only on PRs where `github.event.pull_request.user.login == 'dependabot[bot]'` 2. Runs the headless equivalent of `make ci`: composer-audit hard + npm-audit advisory + gitleaks (scoped to PR range) hard + osv-scanner advisory + typos advisory 3. Posts `fop/local-ci/pr: success|failure` commit status via `gh api POST /repos/.../statuses/{sha}` matching the local-ci-attestation convention (no `actions/github-script`, no new third-party action SHAs) 4. Job permission `statuses: write` (scoped to job, not top-level — minimum privilege) 5. All `github.event.*` values flow through `env:` vars (no injection surface) ## SOTA-2026 discipline notes - Advisory adoption initially — not yet promoted to required gate; verify it runs cleanly over a few Dependabot cycles first. - Both `.github/workflows/dependabot-local-ci-bridge.yml` (GHA) + `.gitea/workflows/dependabot-local-ci-bridge.yaml` (Gitea mirror) committed per workflow-drift requirement. - All actions SHA-pinned, reusing the same SHAs as `security.yml` + `ci.yml` (zero new pin surface). - The bridge does NOT replace the human-developer path — both can post the status; whichever fires first wins. This means the existing developer workflow keeps working. ## Verification `FOP_LOCAL_CI_DIRECT=1 make ci` clean exit-0 on the rebased HEAD. All lefthook pre-push gates green (no `--no-verify` bypass — discipline held per CLAUDE.md L237 and 2026-05-19 E4 incident memory). ## Follow-up A parallel PR will mirror this workflow to parkhub-rust (task #11.2). Once landed and validated, the 8 stuck PRs above can proceed through their auto-merge paths. Co-authored-by: Elly <7864054+nash87@users.noreply.github.com>
Owner
|
@dependabot rebase |
Bumps the npm_and_yarn group with 1 update in the /resources/js directory: [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro). Updates `astro` from 6.1.6 to 6.1.10 - [Release notes](https://github.com/withastro/astro/releases) - [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md) - [Commits](https://github.com/withastro/astro/commits/astro@6.1.10/packages/astro) --- updated-dependencies: - dependency-name: astro dependency-version: 6.1.10 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
115a953 to
55329e1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 1 update in the /resources/js directory: astro.
Updates
astrofrom 6.1.6 to 6.1.10Release notes
Sourced from astro's releases.
... (truncated)
Changelog
Sourced from astro's changelog.
... (truncated)
Commits
c1f2e4f[ci] release (#16467)345fb9echore: fix flaky dev toolbar render time test (#16500)5120ecd[ci] format3d82220Add AEAD context binding to server island encryption (#16457)1bcb43bPrebundle dev toolbar entrypoint in client environment (#16480)93101cc[ci] format152700efix: strip sourceMappingURL from dev toolbar entrypoint during dep optimizati...bc83041refactor(astro): migrate test utils to typescript (#16492)5c543c5refactor(astro): add internal entry points for test (#16473)1058428Suppress content config warning for projects without content collections (#16...