Repository navigation
chore(deps): take Bun 1.4.3 from the shared toolchain - #243
Conversation
|
You have reached your Codex usage limits for security reviews. Please try again later. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 51 minutes. View limit details
📝 Walkthrough
Merge Risk: ⚪ Minimal · up to The toolchain changes and table formatting present no established merge risk; the spelling preference is not required by the project. Pre-merge checks |
|
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
There was a problem hiding this comment.
🔇 Additional comments (4)
package.json (1)
10-10: LGTM!Also applies to: 59-59, 62-62, 80-80
.github/workflows/ci.yml (1)
94-95: LGTM!Also applies to: 97-97, 131-132, 150-151, 188-189, 282-283, 335-336
bunfig.toml (1)
6-6: 🔒 Security & PrivacyThe concern is refuted. The local scheduled workflow delegates to a pinned reusable workflow that detects expired quarantine exceptions and prepares their removal. The
quarantine-expirescomment is therefore processed by repository automation, even though Bun itself does not interpret the comment and the workflow does not reject dependency resolution directly.COVERAGE.md-5-5 (1)
5-5: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
⚠️ Unverified finding
Verification ran but could not confirm this finding. It is shown for review, not as a verified issue.Use the British spelling
Licence.
Licenseis a noun in this heading. Change it toLicenceto match the British English locale.Suggested correction
-| Key | Library | Language | License | Countries | Modules | Oracle | +| Key | Library | Language | Licence | Countries | Modules | Oracle |Source: Linters/SAST tools
ℹ️ Review info
⚙️ Run configuration
- Configuration used: Repository: stella/stdnum/.coderabbit.yaml
- Review profile: CHILL
- Plan: Advanced
- Run ID:
b2368db0-d94d-41a7-99dd-0a38b35f7edf
⛔ Files ignored due to path filters (1)
bun.lockis excluded by!**/*.lock
📒 Files selected for processing (4)
.github/workflows/ci.ymlCOVERAGE.mdbunfig.tomlpackage.json
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.
📜 Review details
⏰ Context from checks skipped due to timeout. (12)
- GitHub Check: Test
- GitHub Check: Bindings and packages
- GitHub Check: Changeset
- GitHub Check: Pack
- GitHub Check: Oracle
- GitHub Check: Version sync
- GitHub Check: Lint
- GitHub Check: Rust
- GitHub Check: cla / cla
- GitHub Check: Enforce package quarantine / Enforce package quarantine
- GitHub Check: dependency-review
- GitHub Check: Check generated AI instructions
🧰 Additional context used
🪛 GitHub Actions: Package quarantine policy / 0_Enforce package quarantine _ Enforce package quarantine.txt
bunfig.toml
[error] 1-1: Quarantine policy check failed: the quarantine exclude entry for "bun-types" has an invalid UTC timestamp. Failed command: bun .quarantine-policy/.github/actions/quarantine-policy/check.ts "636b7841096c8f0cc5a1572077b78768ef8fea42" "stella/stdnum".
🪛 GitHub Actions: Package quarantine policy / Enforce package quarantine _ Enforce package quarantine
bunfig.toml
[error] 1-1: Quarantine policy check failed: the bun-types exclusion has an invalid UTC timestamp.
🪛 LanguageTool
COVERAGE.md
[locale-violation] ~5-~5: License must be spelled with a “c” when used as a noun in British English. Use “licence”.
Context: ...| Library | Language | License | Countries | Modules | Oracle ...
(LICENCE_LICENSE_NOUN_SINGULAR)
Align Bun and bun-types with the shared Bun 1.4.3 toolchain in @stll/oxlint-config 0.8.0. Use package.json for workflow version selection, add the CI toolchain check, and record the temporary bun-types quarantine exception.
Summary by CodeRabbit