Skip to content

Keep incidental fixture pins alert-free#50

Merged
richardmhope merged 1 commit into
mainfrom
fixture-clean-pins
Jul 4, 2026
Merged

Keep incidental fixture pins alert-free#50
richardmhope merged 1 commit into
mainfrom
fixture-clean-pins

Conversation

@richardmhope

Copy link
Copy Markdown
Collaborator

The four open Dependabot alerts all point at the eval fixture's incidental requests==2.32.3 pin — the dependency graph indexes fixture manifests even though #49 stopped Dependabot update PRs for them. The fixture's planted defect is the git-fork left-pad line, which is untouched; bumping the incidental pin resolves the alerts without weakening the eval.

🤖 Generated with Claude Code

The dependency-review fixture's planted defect is the git-fork
left-pad dependency; the requests pin is incidental context, but its
old version raised four Dependabot alerts on the default branch (the
dependency graph indexes fixture manifests regardless of dependabot
config). Pin the clean version so the alerts resolve; the eval is
unaffected.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@richardmhope
richardmhope merged commit 809117e into main Jul 4, 2026
11 checks passed
@richardmhope
richardmhope deleted the fixture-clean-pins branch July 4, 2026 00:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant