WARNING: THIS SITE IS A MIRROR OF GITHUB.COM / IT CANNOT LOGIN OR REGISTER ACCOUNTS / THE CONTENTS ARE PROVIDED AS-IS / THIS SITE ASSUMES NO RESPONSIBILITY FOR ANY DISPLAYED CONTENT OR LINKS / IF YOU FOUND SOMETHING MAY NOT GOOD FOR EVERYONE, CONTACT ADMIN AT ilovescratch@foxmail.com
Skip to content

Conversation

@Trott
Copy link
Member

@Trott Trott commented Nov 26, 2025

SHA1-Hulud makes me definitely not want to be responsible for failing to pin versions of semantic-release, etc. Updating package-lock.json might have extra annoying steps to keep npm ci working, but it is still possible. Like I did here.

SHA1-Hulud makes me definitely not want to be responsible
for failing to pin versions of semantic-release, etc. Updating
package-lock.json has extra annoying steps, but is still possible.
Like I did here.
@Trott
Copy link
Member Author

Trott commented Nov 26, 2025

@aduh95 PTAL

@Trott
Copy link
Member Author

Trott commented Nov 26, 2025

@aduh95 PTAL

Actually, I'm going to go ahead and land this. In the hopefully-unlikely event that we want to revert, hey, it's git, we can do that.

@Trott Trott merged commit b2a6793 into main Nov 26, 2025
8 checks passed
@Trott
Copy link
Member Author

Trott commented Nov 26, 2025

Looking at our GitHub Actions logs, we've been erroring out with EGITNOPERMISSION for a long time.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants