From f162d6fb86c756ab7e533dbc6e4979027e4d616c Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Thu, 27 Aug 2026 17:12:54 +0200 Subject: [PATCH 1/2] chore(renovate): onboard to shared Renovate preset Adds a minimal renovate.json extending the org-wide shared preset in EduIDE/.github, so dependency update policy is maintained in one place rather than per repo. Also cleans up two leftovers found while doing this: - Deletes .whitesource, config for an abandoned Mend Bolt trial. Nothing else in the repo references it and no Mend check runs on PRs. - Drops the "fs" dependency. That is a squatting placeholder package on npm, not the Node builtin. Every import in this repo uses `import ... from "fs"`, which Node resolves to the builtin regardless of what sits in node_modules, so removing it changes no behaviour. The lockfile was regenerated with `npm install --package-lock-only`; the resulting diff is limited to dropping the "fs" entry. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9 --- .whitesource | 14 -------------- package-lock.json | 7 ------- package.json | 1 - renovate.json | 4 ++++ 4 files changed, 4 insertions(+), 22 deletions(-) delete mode 100644 .whitesource create mode 100644 renovate.json diff --git a/.whitesource b/.whitesource deleted file mode 100644 index 9c7ae90..0000000 --- a/.whitesource +++ /dev/null @@ -1,14 +0,0 @@ -{ - "scanSettings": { - "baseBranches": [] - }, - "checkRunSettings": { - "vulnerableCheckRunConclusionLevel": "failure", - "displayMode": "diff", - "useMendCheckNames": true - }, - "issueSettings": { - "minSeverityLevel": "LOW", - "issueType": "DEPENDENCY" - } -} \ No newline at end of file diff --git a/package-lock.json b/package-lock.json index a338132..36168a7 100644 --- a/package-lock.json +++ b/package-lock.json @@ -13,7 +13,6 @@ "@modelcontextprotocol/sdk": "^1.17.5", "dayjs": "^1.11.13", "dotenv": "^16.5.0", - "fs": "^0.0.1-security", "fs-extra": "^11.3.0", "uuid": "^11.1.0" }, @@ -7743,12 +7742,6 @@ "node": ">= 0.8" } }, - "node_modules/fs": { - "version": "0.0.1-security", - "resolved": "https://registry.npmjs.org/fs/-/fs-0.0.1-security.tgz", - "integrity": "sha512-3XY9e1pP0CVEUCdj5BmfIZxRBTSDycnbqhIOGec9QYtmVH2fbLpj86CFWkrNOkt/Fvty4KZG5lTglL9j/gJ87w==", - "license": "ISC" - }, "node_modules/fs-constants": { "version": "1.0.0", "resolved": "https://registry.npmjs.org/fs-constants/-/fs-constants-1.0.0.tgz", diff --git a/package.json b/package.json index 1dd6ebf..7862b9d 100644 --- a/package.json +++ b/package.json @@ -30,7 +30,6 @@ "@modelcontextprotocol/sdk": "^1.17.5", "dayjs": "^1.11.13", "dotenv": "^16.5.0", - "fs": "^0.0.1-security", "fs-extra": "^11.3.0", "uuid": "^11.1.0" } diff --git a/renovate.json b/renovate.json new file mode 100644 index 0000000..937744e --- /dev/null +++ b/renovate.json @@ -0,0 +1,4 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "extends": ["local>EduIDE/.github:renovate-config"] +} From d50e5b306664b19e2098c79e48c517e6baacbff4 Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Thu, 27 Aug 2026 17:19:20 +0200 Subject: [PATCH 2/2] fix(ci): stop artillery job failing on an unreachable apt mirror The Artillery job has been red since its last green run in May. It is not a test failure: `npx playwright install --with-deps` runs `apt-get update`, and packages.microsoft.com now returns 403 for the azure-cli and prod repos, which aborts apt with exit 100 before any browser is downloaded. Nothing in this repo needs those Microsoft repos, and the hosted runner image already ships the Playwright system libraries. Removing the two source lists lets apt succeed. Also narrows the install to chromium - the load test only drives chromium, so pulling firefox and webkit was wasted time on every run. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QLGHEpzx7D9NYHx4fCmHa9 --- .github/workflows/artillery-tests.yml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/.github/workflows/artillery-tests.yml b/.github/workflows/artillery-tests.yml index 35bd78e..f7f7d63 100644 --- a/.github/workflows/artillery-tests.yml +++ b/.github/workflows/artillery-tests.yml @@ -19,8 +19,13 @@ jobs: uses: actions/checkout@v4 - name: Install dependencies run: npm ci + # --with-deps runs apt-get update, which fails the whole job when + # packages.microsoft.com returns 403 - it has nothing we need, and the + # hosted runner image already carries the Playwright system libraries. + - name: Drop unreachable apt sources + run: sudo rm -f /etc/apt/sources.list.d/microsoft-prod.list /etc/apt/sources.list.d/azure-cli.list - name: Install Playwright Browsers - run: npx playwright install --with-deps + run: npx playwright install --with-deps chromium - name: Execute load tests uses: artilleryio/action-cli@v1 with: