chore(ai-review): no AI review on the org-wide seeders' own pull requests #64
No reviewers
Labels
No labels
idea
points
1
points
13
points
2
points
3
points
5
points
8
priority
p0
priority
p1
priority
p2
priority
p3
state
blocked
state
done
state
in-progress
state
ready
state
review
state
triage
status
declined
status
in-progress
status
planned
status
proposed
status
shipped
status
under-review
type
bug
type
epic
type
feature
type
spike
type
story
type
task
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
tti/tti-ux!64
Loading…
Reference in a new issue
No description provided.
Delete branch "chore/ai-review-20261004"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This re-seeds the canonical ai/ai-review.yml from nis/forgejo-stack. The AI review no longer runs on pull requests from the org-wide seeders, whose head branches start with chore/h2-baseline-security or chore/ai-review-: a re-seed opens the same vendored bytes in about 29 repos at once, and each one queued a review of an identical diff on the one shared Linux runner. Every other pull request is reviewed as before. Pull requests run the workflow on their own head, so this PR already uses the new file; it reaches every other pull request once it merges. Advisory only, never a merge gate.
🔧 Security-gate fix map
The gate failed on these dependency findings — fastest path to green for each:
@nuxtjs/mdc@tiptap/corenpm update core --package-lock-onlybrace-expansionbrace-expansionbracesnpm update braces --package-lock-onlydevaluenpm update devalue --package-lock-onlydevaluenpm update devalue --package-lock-onlydevaluenpm update devalue --package-lock-onlydevaluenpm update devalue --package-lock-onlyjs-yamlnpm update js-yaml --package-lock-onlynode-forgenpm update node-forge --package-lock-onlysharpnpm update sharp --package-lock-onlysvgonpm update svgo --package-lock-onlyundicinpm update undici --package-lock-onlyundicinpm update undici --package-lock-onlyundicinpm update undici --package-lock-onlyPosted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.