Skip to content

Check package-lock.json for wrong addresses - #4192

Merged
mbg merged 3 commits into
mainfrom
mbg/project-changes
Oct 2, 2026
Merged

mbg merged 3 commits into
mainfrom
mbg/project-changes

Conversation

@mbg

@mbg mbg commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

This PR adds a check to make sure that certain URLs that would create issues for some contributors don't end up in package-lock.json.

Risk assessment

For internal use only. Please select the risk level of this change:

  • Low risk: Changes are fully under feature flags, or have been fully tested and validated in pre-production environments and are highly observable, or are documentation or test only.

Which use cases does this change impact?

  • Testing/None - This change does not impact any CodeQL workflows in production.

How did/will you validate this change?

  • Unit tests - I am depending on unit test coverage (i.e. tests in .test.ts files).
  • End-to-end tests - I am depending on PR checks (i.e. tests in pr-checks).

If something goes wrong after this change is released, what are the mitigation and rollback strategies?

  • Development/testing only - This change cannot cause any failures in production.

How will you know if something goes wrong after this change is released?

  • Telemetry - I rely on existing telemetry or have made changes to the telemetry.
    • Dashboards - I will watch relevant dashboards for issues after the release. Consider whether this requires this change to be released at a particular time rather than as part of a regular release.
    • Alerts - New or existing monitors will trip if something goes wrong with this change.

Are there any special considerations for merging or releasing this change?

  • No special considerations - This change can be merged at any time.

Merge / deployment checklist

  • Confirm this change is backwards compatible with existing workflows.
  • Consider adding a changelog entry for this change.
  • Confirm the readme and docs have been updated if necessary.

@mbg
mbg requested a review from henrymercer October 2, 2026 15:51
@mbg mbg self-assigned this Oct 2, 2026
Copilot AI balanced review requested due to automatic review settings October 2, 2026 15:51
@mbg
mbg requested a review from a team as a code owner October 2, 2026 15:51
@github-actions github-actions Bot added the size/XS Should be very easy to review label Oct 2, 2026
henrymercer
henrymercer previously approved these changes Oct 2, 2026

@henrymercer henrymercer left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should probably also set min-release-age=7 in .npmrc and remove the @actions/* and actions/* Dependabot cooldown exclusions. This can happen in a separate PR though.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The configuration and validation check correctly implement the stated portability safeguard without affecting production workflows.

Review effort: Balanced
Findings: None

What changed in this PR

Makes npm lockfiles registry-agnostic and prevents internal feed URLs from being committed.

Changes:

  • Omits registry-resolved URLs from generated lockfiles.
  • Adds a PR check rejecting known internal package-feed URLs.
File Description
.npmrc Enables registry-agnostic lockfile generation.
.github/​workflows/​pr-checks.yml Detects internal feed URLs in package-lock.json.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@mbg

This comment was marked as outdated.

@mbg
mbg force-pushed the mbg/project-changes branch from 3136764 to 9008fdb Compare October 2, 2026 16:19
@mbg
mbg changed the base branch from main to mbg/dependency/downgrade-cache October 2, 2026 16:19
@mbg
mbg added this pull request to stack #4195 October 2, 2026 16:19
@mbg
mbg force-pushed the mbg/project-changes branch from 9008fdb to d4c9bc1 Compare October 2, 2026 16:22
Base automatically changed from mbg/dependency/downgrade-cache to main October 2, 2026 16:43
@mbg
mbg force-pushed the mbg/project-changes branch 2 times, most recently from 579cce1 to d735805 Compare October 2, 2026 16:49
@mbg mbg changed the title Adjust feed-related configuration Check package-lock.json for wrong addresses Oct 2, 2026
@mbg
mbg requested a review from henrymercer October 2, 2026 16:50
@mbg
mbg force-pushed the mbg/project-changes branch from 3c10114 to ae091ae Compare October 2, 2026 16:56
@github-actions github-actions Bot added size/S Should be easy to review and removed size/XS Should be very easy to review labels Oct 2, 2026
@mbg
mbg force-pushed the mbg/project-changes branch from ee7b65a to 8948426 Compare October 2, 2026 17:32
@github-actions github-actions Bot added size/XS Should be very easy to review and removed size/S Should be easy to review labels Oct 2, 2026
@mbg
mbg force-pushed the mbg/project-changes branch from 0f62d21 to b948c4d Compare October 2, 2026 17:38
@mbg
mbg added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit b6d38e5 Oct 2, 2026
233 checks passed
@mbg
mbg deleted the mbg/project-changes branch October 2, 2026 18:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XS Should be very easy to review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants