You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The explanatory comments in .github/workflows/dependabot-repair.yml (lines 87-105) predate the unconditional binding-redirect sync pass added by issue #985 (scripts/dependencies/BindingRedirectSync.psm1). They state that the binding-redirect class is not reachable from the workflow_run trigger and that the app.config reconciliation pass never runs, which is no longer true: the sync pass now rewrites stale transitive redirects on every run and reports through a separate RedirectSync field and WrittenPath. The behavior is correct; only the comments mislead a reader.
Compare with Repair-PackageManifestConsistency.ps1, which now invokes the redirect sync pass unconditionally.
Expected Behavior
The workflow comments describe the current write classes: analyzer repairs (repair records), manifest normalisation, the -CandidateUpgrade reconciliation pass (still unreachable from this trigger), and the unconditional redirect sync pass (reported in RedirectSync, written files counted by WrittenPath, not counted in beyond-known-weak).
Actual Behavior
The comments say the app.config reconciliation pass never runs from this trigger and do not mention the redirect sync pass.
Logs / Screenshots
Attached minimal logs or screenshot
Snippet: # The binding-redirect class is not reachable from the workflow_run trigger
Sections omitted by the promotion tool, reposted from the potential record:
Suspected Cause / Notes
Issue #985 deliberately excluded .github/workflows/** from its write set: the modified-workflow-needs-green-run rule cannot be satisfied for this workflow before merge, because it runs only on dependabot/ branches and has no manual trigger.
Proposed Fix / Validation Ideas
Update the comment block at lines 87-105 to describe the redirect sync pass; comment-only change.
actionlint passes; the green-run requirement is satisfied by the next Dependabot PR's repair run.
Summary
The explanatory comments in
.github/workflows/dependabot-repair.yml(lines 87-105) predate the unconditional binding-redirect sync pass added by issue #985 (scripts/dependencies/BindingRedirectSync.psm1). They state that the binding-redirect class is not reachable from the workflow_run trigger and that the app.config reconciliation pass never runs, which is no longer true: the sync pass now rewrites stale transitive redirects on every run and reports through a separateRedirectSyncfield andWrittenPath. The behavior is correct; only the comments mislead a reader.Environment
windows-latestdependabot-repair.yml"Repair package manifest consistency" stepcode-review.2026-10-09T14-55.md, non-blocking item)Steps to Reproduce
.github/workflows/dependabot-repair.ymllines 87-105 after issue Bug: dependabot-repair-borrowed-packages-and-transitive-redirects #985 merges.Repair-PackageManifestConsistency.ps1, which now invokes the redirect sync pass unconditionally.Expected Behavior
The workflow comments describe the current write classes: analyzer repairs (repair records), manifest normalisation, the
-CandidateUpgradereconciliation pass (still unreachable from this trigger), and the unconditional redirect sync pass (reported inRedirectSync, written files counted byWrittenPath, not counted inbeyond-known-weak).Actual Behavior
The comments say the app.config reconciliation pass never runs from this trigger and do not mention the redirect sync pass.
Logs / Screenshots
# The binding-redirect class is not reachable from the workflow_run triggerImpact / Severity
Source
From: docs/features/potential/2026-10-09-dependabot-repair-workflow-comments-predate-redirect-sync.md