fix(ci): remove the duplicate ignore entries that broke the Dependabot config - #374
Merged
Merged
Conversation
…parsing the config
Ank-KhoaHo
added a commit
that referenced
this pull request
Aug 24, 2026
🤖 I have created a release *beep* *boop* --- ## [0.37.0](v0.36.1...v0.37.0) (2026-08-24) ### Added * **extensions:** mirror DocxReview as IDocxReview ([#375](#375)) ([8bcfacf](8bcfacf)) ### Fixed * **ci:** remove the duplicate ignore entries that broke the Dependabot config ([#374](#374)) ([cab06a2](cab06a2)) * **core:** restore the samples to the floating version ([#371](#371)) ([51a66eb](51a66eb)) ### Changed * **deps:** bump OfficeIMO to 3.2.6, AngleSharp to 1.7.2 and PdfPig to 0.1.16 ([#366](#366)) ([df1dc03](df1dc03)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
#373 shipped a
.github/dependabot.ymlthat Dependabot refuses to parse. It appended thefifteen shipped packages to two ignore lists that already named
SixLabors.Fonts, so both gained aduplicate:
Dependabot stops parsing the whole file on that, so every update it would raise is disabled —
security updates included.
mainhas been in that state since #373 merged.Caught by Dependabot's own API check appearing on #366, not by anything in this repo.
Why nothing here saw it
Three separate blind spots, all pointing the same way:
check-dependabot-scoping.pyreduces each block's ignore list to a set, so a duplicate isgone before it is examined
yaml.safe_loadaccepts duplicate list items happily — they are list entries, not map keysci: stop the chore block bumping shipped dependencies #373's own checks did not show before I merged it
Fixed
SixLabors.Fontsis no longer a standalone entry in either block; the derived list carries it. Inthe root block that entry had an
update-types: ["version-update:semver-major"]line under it —removing only the name left the line orphaned and broke the YAML outright, which is worth recording
because it is the second way to get this wrong in one edit.
That is a deliberate widening: the root block ignored only SixLabors majors, the derived entry
ignores it entirely. Ignoring more is always safe, and
src/pins it to an exact version anyway.Guarded
check-dependabot-scoping.pynow counts each ignore list as a list rather than a set, usingthis file's own line patterns.
Deliberately not via PyYAML. The first version of this check imported it inside a
try/except ImportError— and no workflow here installs PyYAML, so in CI it would have skippeditself and reported success. A check that silently does nothing is worse than no check.
Sabotage-verified three ways, each duplicating a name that already exists in its own block:
Ank.DocToolkitOfficeIMO.WordMicrosoft.Extensions.HostingMy first two sabotage attempts were ineffective — I added a name to a block that did not already
have it, so no duplicate existed and the check passed correctly. Worth stating: an ineffective
sabotage looks exactly like a guard that does not work.