Skip to content

Bug: dependabot-repair-workflow-comments-predate-redirect-sync #986

Description

@drmoisan
  • Work Mode: minor-audit

Summary

The explanatory comments in .github/workflows/dependabot-repair.yml (lines 87-105) predate the unconditional binding-redirect sync pass added by issue #985 (scripts/dependencies/BindingRedirectSync.psm1). They state that the binding-redirect class is not reachable from the workflow_run trigger and that the app.config reconciliation pass never runs, which is no longer true: the sync pass now rewrites stale transitive redirects on every run and reports through a separate RedirectSync field and WrittenPath. The behavior is correct; only the comments mislead a reader.

Environment

Steps to Reproduce

  1. Read .github/workflows/dependabot-repair.yml lines 87-105 after issue Bug: dependabot-repair-borrowed-packages-and-transitive-redirects #985 merges.
  2. Compare with Repair-PackageManifestConsistency.ps1, which now invokes the redirect sync pass unconditionally.

Expected Behavior

The workflow comments describe the current write classes: analyzer repairs (repair records), manifest normalisation, the -CandidateUpgrade reconciliation pass (still unreachable from this trigger), and the unconditional redirect sync pass (reported in RedirectSync, written files counted by WrittenPath, not counted in beyond-known-weak).

Actual Behavior

The comments say the app.config reconciliation pass never runs from this trigger and do not mention the redirect sync pass.

Logs / Screenshots

  • Attached minimal logs or screenshot
  • Snippet: # The binding-redirect class is not reachable from the workflow_run trigger

Impact / Severity

  • Blocker
  • High
  • Medium
  • Low

Source

From: docs/features/potential/2026-10-09-dependabot-repair-workflow-comments-predate-redirect-sync.md

Activity

  1. drmoisan commented on Oct 9, 2026

    @drmoisan
    OwnerAuthor

    Sections omitted by the promotion tool, reposted from the potential record:

    Suspected Cause / Notes

    Issue #985 deliberately excluded .github/workflows/** from its write set: the modified-workflow-needs-green-run rule cannot be satisfied for this workflow before merge, because it runs only on dependabot/ branches and has no manual trigger.

    Proposed Fix / Validation Ideas

    • Update the comment block at lines 87-105 to describe the redirect sync pass; comment-only change.
    • actionlint passes; the green-run requirement is satisfied by the next Dependabot PR's repair run.
    • Manual verification notes: none.

    Next Step

    • Promote to GitHub issue (bug-report template)
    • Move to active fix folder / branch
  2. added 2 commits that reference this issue on Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions