chore(ai-review): no AI review on the org-wide seeders' own pull requests #64

Open
A-Guevara wants to merge 1 commit from chore/ai-review-20261004 into main
Owner

This re-seeds the canonical ai/ai-review.yml from nis/forgejo-stack. The AI review no longer runs on pull requests from the org-wide seeders, whose head branches start with chore/h2-baseline-security or chore/ai-review-: a re-seed opens the same vendored bytes in about 29 repos at once, and each one queued a review of an identical diff on the one shared Linux runner. Every other pull request is reviewed as before. Pull requests run the workflow on their own head, so this PR already uses the new file; it reaches every other pull request once it merges. Advisory only, never a merge gate.

This re-seeds the canonical ai/ai-review.yml from nis/forgejo-stack. The AI review no longer runs on pull requests from the org-wide seeders, whose head branches start with chore/h2-baseline-security or chore/ai-review-: a re-seed opens the same vendored bytes in about 29 repos at once, and each one queued a review of an identical diff on the one shared Linux runner. Every other pull request is reviewed as before. Pull requests run the workflow on their own head, so this PR already uses the new file; it reaches every other pull request once it merges. Advisory only, never a merge gate.
chore(ai-review): no AI review on the org-wide seeders' own pull requests
Some checks failed
ai-review / review (pull_request) Has been skipped
scan / trivy-fs (pull_request) Failing after 1m40s
baseline-security / baseline (pull_request) Failing after 2m36s
scan / trivy-fs (push) Failing after 1m25s
baseline-security / baseline (push) Failing after 1m49s
17ac66ba4c

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
CVE-2026-63671 (HIGH) @nuxtjs/mdc 0.21.1 → 0.22.1 merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f
GHSA-j95f-988m-3j2f (HIGH) @tiptap/core 3.28.0 → 3.30.5 no fix PR yet — npm update core --package-lock-only
CVE-2026-102276 (HIGH) brace-expansion 5.0.9 → 5.0.10, 3.0.7, 2.1.5, 1.1.19 merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s
CVE-2026-102278 (HIGH) brace-expansion 5.0.9 → 5.0.11, 3.0.8, 2.1.6, 1.1.20 merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s
CVE-2026-93687 (HIGH) braces 3.0.3 → ? no fix PR yet — npm update braces --package-lock-only
CVE-2026-92708 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-mcm9-63f2-9j32 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-r9w8-h9r3-54w4 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-x5rw-q4pp-hg5g (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
CVE-2026-85393 (HIGH) node-forge 1.4.0 → ? no fix PR yet — npm update node-forge --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only
CVE-2026-19534 (HIGH) undici 8.10.0 → 6.28.1, 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-84961 (HIGH) undici 8.10.0 → 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-85152 (HIGH) undici 8.10.0 → 8.10.2 no fix PR yet — npm update undici --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:17ac66ba4c55535c05c51bf011d9282211850314 --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | CVE-2026-63671 (HIGH) | `@nuxtjs/mdc` | 0.21.1 → 0.22.1 | merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f | | GHSA-j95f-988m-3j2f (HIGH) | `@tiptap/core` | 3.28.0 → 3.30.5 | no fix PR yet — `npm update core --package-lock-only` | | CVE-2026-102276 (HIGH) | `brace-expansion` | 5.0.9 → 5.0.10, 3.0.7, 2.1.5, 1.1.19 | merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s | | CVE-2026-102278 (HIGH) | `brace-expansion` | 5.0.9 → 5.0.11, 3.0.8, 2.1.6, 1.1.20 | merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s | | CVE-2026-93687 (HIGH) | `braces` | 3.0.3 → ? | no fix PR yet — `npm update braces --package-lock-only` | | CVE-2026-92708 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-mcm9-63f2-9j32 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-r9w8-h9r3-54w4 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-x5rw-q4pp-hg5g (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | CVE-2026-85393 (HIGH) | `node-forge` | 1.4.0 → ? | no fix PR yet — `npm update node-forge --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | | CVE-2026-19534 (HIGH) | `undici` | 8.10.0 → 6.28.1, 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-84961 (HIGH) | `undici` | 8.10.0 → 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-85152 (HIGH) | `undici` | 8.10.0 → 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
Some checks failed
ai-review / review (pull_request) Has been skipped
scan / trivy-fs (pull_request) Failing after 1m40s
baseline-security / baseline (pull_request) Failing after 2m36s
Required
Details
scan / trivy-fs (push) Failing after 1m25s
baseline-security / baseline (push) Failing after 1m49s
This pull request doesn't have enough approvals yet. 0 of 1 approvals granted.
This branch is out-of-date with the base branch
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin chore/ai-review-20261004:chore/ai-review-20261004
git switch chore/ai-review-20261004
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!64
No description provided.