You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Unlike the other new hub-repository guards, this one checks only the repository name. A PR opened in a same-named repository in any other organization will incorrectly create a Safe Settings validation check that the later check_run.created owner guard refuses to process. Include the configured hub organization in this predicate.
This reopened-PR path also identifies the hub by repository name alone. Reopening a PR in a same-named repository outside SAFE_SETTINGS_HUB_ORG therefore creates a validation check that cannot be completed by the owner-scoped handler. Apply the same organization check used for check_suite.requested.
Asset URLs ignore configured base path
ui/src/app/layout.jsx:14
These public-asset URLs are rooted at the host, so under the configured /safe-settings (or any custom) basePath they request /favicon.* outside the mounted router and return 404. Prefix metadata and the duplicate <head> icon links with the configured base path, or use a base-path-aware file metadata approach.
Deleting this suite leaves the existing npm run test:archived script pointing to a nonexistent file, so that documented command now fails instead of running. It also silently removes these archived-repository regression cases from the integration-test glob; restore the suite or update the script and provide equivalent coverage.
Make the success test assert a valid response
test/unit/lib/routes.test.js:90
This success test accepts every plausible outcome, including HTTP 500, and only asserts that Express returned a body. Because cacheGetInstallations is not configured here, the route currently takes its error path and the test still passes. Mock a hub installation/authenticated content response and require 200 plus the expected tree; inject a distinct failure for the following error test.
File selection is implemented as an onClick handler on a non-focusable <div>, making files impossible to select from the keyboard. Render this row as a button/treeitem with keyboard support and selected state.
This issue also appears on line 143 of the same file.
The content-table rows are clickable but not keyboard-focusable or operable, so this second navigation path is also inaccessible without a pointer. Put the item action in a link/button or add equivalent keyboard semantics.
Fix insufficient dark-theme navigation contrast
ui/src/app/globals.css:91
This !important rule forces dark-theme navigation text to #6c757d on the #22272e navigation background, which is below the WCAG 4.5:1 contrast requirement for normal text. It also overrides the higher-contrast component rule in TitleBar.css; use the dark theme's primary text color instead.
Update the link to the dry-run orchestration code
docs/dry-runs.md:48
This anchor currently points to the repository-renamed handler (index.js:639-700), not dry-run check orchestration, which is now around index.js:747-918. Update the link so readers reach the implementation being described.
Remove stale destination files during reimport
docs/hubSyncHandler/ADR-reimport_control.md:219
The implementation does not replace the entire destination tree during reimport. retrieveSettingsFromOrgs() creates a Git tree with base_tree and only overlays files currently found in the source, so destination files deleted from the organization remain in the hub. Either implement deletion of stale paths or document the additive/update behavior rather than promising full replacement.
Replace absolute filesystem paths with repository links
These machine-specific absolute paths are not usable repository references and expose a contributor's local filesystem layout. Replace them with repository-relative paths/links; the same issue recurs for the entries below.
Correct the documented default configuration path
docs/hubSyncHandler/README.md:279
The documented default incorrectly includes CONFIG_PATH. Runtime code constructs paths as CONFIG_PATH/SAFE_SETTINGS_HUB_PATH, and lib/env.js defaults this variable to safe-settings; configuring .github/safe-settings as shown would produce .github/.github/safe-settings.
Fix the nonexistent module in the usage example
examples/merge-configs-example.js:238
The printed usage imports a module that does not exist; this example itself imports mergeConfigs from lib/hubSyncHandler.js. Copying the summary snippet therefore fails with MODULE_NOT_FOUND.
This new test cannot pass against the added deepMerge implementation: when the overlay value is null, deepMerge returns the existing target value, so the result is { a: 1, b: 2 }, not { a: 1, b: null }. Update the merge logic so an explicit YAML null overrides the prior value, or change the documented/tested contract consistently.
Prefix public asset URLs with the configured base path
ui/src/app/layout.jsx:14
These root-relative public-asset URLs bypass the configured Next.js basePath. Under the default /safe-settings deployment they request /favicon.* from the server root, while static assets are mounted below the prefix, so the icons return 404. Prefix all metadata and manual icon URLs with the same normalized base path.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.