Skip to content

fix(ci): unblock postinstall scripts hitting GitHub API rate limit - #878

Merged
LucasSantana-Dev merged 1 commit into
release/v2.12.0from
fix/ci-yt-dlp-release-and-quality-bump
May 16, 2026
Merged

LucasSantana-Dev merged 1 commit into
release/v2.12.0from
fix/ci-yt-dlp-release-and-quality-bump

Conversation

@LucasSantana-Dev

Copy link
Copy Markdown
Owner

Summary

Fixes #874 by:

  1. Bumping the pinned ref of the org reusable `quality.yml` to the merge commit of LucasSantana-Dev/.github#2. That PR adds `GITHUB_TOKEN` + `YOUTUBE_DL_SKIP_DOWNLOAD=true` to the install step in the `lint` and `deadcode` jobs, eliminating the 60 req/hr unauthenticated cap that's been failing PRs since the observability rollout started.

  2. Applying the same env vars to local `release.yml` for parity. Release builds don't strictly need the yt-dlp binary, so skipping the fetch is harmless.

Why this scope

Workflow npm ci flags Status
`ci.yml` `--legacy-peer-deps --ignore-scripts` already safe
`sonarcloud.yml` `--legacy-peer-deps --ignore-scripts` already safe
`bundle-size.yml` runs postinstall already sets both env vars
`release.yml` bare `npm ci` fixed here
reusable `quality.yml` runs postinstall fixed via SHA bump

Closes

Unblocks

Test plan

Two changes that address #874:

1. Bump pinned ref of the org reusable quality.yml to pick up
   LucasSantana-Dev/.github#2 — the install steps in lint + deadcode
   now set GITHUB_TOKEN (5000 req/hr) and YOUTUBE_DL_SKIP_DOWNLOAD=true
   so the youtube-dl-exec postinstall doesn't fall through to the
   unauthenticated 60 req/hr cap on shared-runner IPs.

2. Apply the same env vars to release.yml's npm ci step. release.yml
   doesn't strictly need yt-dlp at release time, so skipping the
   binary fetch is harmless.

ci.yml + sonarcloud.yml already pass --ignore-scripts; bundle-size.yml
already sets both env vars. No further workflow changes needed.

Closes #874.
@vercel

vercel Bot commented May 16, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment May 16, 2026 0:08am

Request Review

@coderabbitai

coderabbitai Bot commented May 16, 2026

Copy link
Copy Markdown

Warning

Rate limit exceeded

@LucasSantana-Dev has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 54 minutes and 32 seconds before requesting another review.

You’ve run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: a063034b-c1aa-4d1b-bd7a-b54b4ec9ca61

📥 Commits

Reviewing files that changed from the base of the PR and between 22c4fab and d3d2b8a.

📒 Files selected for processing (2)
  • .github/workflows/quality.yml
  • .github/workflows/release.yml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/ci-yt-dlp-release-and-quality-bump

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LucasSantana-Dev has reached the 50-review limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@github-actions

Copy link
Copy Markdown

Failed to generate code suggestions for PR

@LucasSantana-Dev
LucasSantana-Dev merged commit ea886cc into release/v2.12.0 May 16, 2026
26 checks passed
@LucasSantana-Dev
LucasSantana-Dev deleted the fix/ci-yt-dlp-release-and-quality-bump branch May 16, 2026 00:09
@sonarqubecloud

Copy link
Copy Markdown

LucasSantana-Dev added a commit that referenced this pull request May 21, 2026
## Summary

Cut v2.13.0 of Lucky. Bumps root + 4 workspaces from `2.11.0` → `2.13.0`
(skipping the archived `2.12.0`) and promotes the CHANGELOG
`[Unreleased]` block to `[2.13.0] - 2026-05-21`.

## Headline changes since v2.11.0

**Added**
- Guild Automation Module Executor seam + AutoMessages pilot (#901)
- Sentry React SDK + Router v7 tracing/replay on frontend (#876)
- Prometheus `/metrics` on backend (#875) + bot (#873)
- Guild join/leave history tracking (#872)
- Trivy image-scan on docker-publish, Phase A audit-only (#883)
- Self-hosted developer-tooling register on landing page (#868)

**Changed**
- Backend migrated to Zod 4 API (#919) — unblocked the CVE patch + ended
the lockfile fragility loop
- 3 bot circular-deps clusters broken (#885, #886, #888)

**Fixed**
- brace-expansion DoS + ws uninit-memory CVEs patched (#921)
- nginx-alpine CVEs (#881)
- CI postinstall rate limit + madge actionlint (#878, #905)

Full list in CHANGELOG.md.

## Next steps (after this PR merges)

1. Open `release/v2.13.0 → main` PR with merge-commit method
2. Tag `v2.13.0` on the merge commit
3. Cut next `release` (homelab-style bare branch) — Lucky's bare-release
migration is still pending the user removing protection on
`release/v2.11.0`
@LucasSantana-Dev LucasSantana-Dev mentioned this pull request May 21, 2026
3 tasks
LucasSantana-Dev added a commit that referenced this pull request May 21, 2026
## Release v2.13.0

Promotes \`release/v2.13.0\` to \`main\` for the v2.13.0 cut.

**$AHEAD commits across all merged PRs since v2.11.0 ship.**

(Skipping v2.12.0 — the branch existed but its work was rolled forward
into v2.13.0 alongside this session's Zod migration + CVE patches +
standards adoption.)

## Headline changes

**Added** — Guild Automation Module Executor pilot (#901), Sentry
frontend (#876), Prometheus metrics on bot+backend (#873, #875), guild
membership history (#872), Trivy image-scan Phase A (#883), landing
redesign (#868).

**Changed** — Backend migrated to Zod 4 API (#919), 3 bot circular-deps
clusters broken (#885/#886/#888).

**Fixed** — brace-expansion + ws moderate CVEs (#921), nginx-alpine CVEs
(#881), CI postinstall rate limit (#878), madge actionlint (#905).

**Internal** — shared coverageThreshold gate (#909/#914),
Feature-removal sweep checklist + dangerfile guard (#908/#913),
monitoring network, AI-doc policy, 4 new ADRs.

Full list in [CHANGELOG.md](./CHANGELOG.md).

## Merge method

This PR should land via **merge commit** (NOT squash) to preserve the
individual PR SHAs in main's history. After merge:

1. Tag \`v2.13.0\` on the merge commit
2. Create GitHub release with notes from CHANGELOG.md
3. Fast-forward \`release/v2.13.0\` to match the new main HEAD

## Test plan

- [ ] All 30 checks green except infra (snyk plan cap)
- [ ] Verify \`gh pr view 922 --json mergeCommit\` shows the chore-bump
commit on release tip
- [ ] After merge: confirm \`origin/main\` contains the full $AHEAD
commits

This branch was successfully deployed

1 active deployment
Preview — d3d2b8a0 Deployed May 16, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant