docs: Web依存PRの終了結果を記録 - #203
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 91d984bd02
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| - Open PR count after web-lockfile superseded closures: 33. | ||
| - Open Dependabot alerts observed: 0. | ||
| - Open dependency PRs observed: 16. |
There was a problem hiding this comment.
Reconcile closure count with “open dependency PRs” snapshot
This snapshot now records post-closure state (open PR count after ... closures: 33) but still reports Open dependency PRs observed: 16, even though this same update closes 3 dependency PRs (#117/#119/#127), leaving 13 open in the table below. That mismatch makes the ledger internally inconsistent and can mislead later triage decisions that rely on these headline counts.
Useful? React with 👍 / 👎.
| - Open dependency PRs observed: 16. | ||
| - Dependency PRs closed in this pass: 0. | ||
| - Dependency PRs closed in this pass: 3 (#117, #119, #127). | ||
| - Open PR count after this dependency pass: 33. |
There was a problem hiding this comment.
Keep dependency snapshot counts in one time basis
In this pass summary, Open dependency PRs observed: 16 is presented next to the post-action totals (Dependency PRs closed ...: 3 and Open PR count after ...: 33), which mixes pre-close and post-close numbers in one snapshot block. Because this section is used as the pass baseline/result, the mixed time basis can misstate the actual remaining dependency backlog after the described closures.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Code Review
This pull request updates the maintenance and security triage documentation to reflect the closure of three web-related dependency PRs (#117, #119, and #127) that were superseded by the current state of the main branch. The changes include updated PR counts, status tables, and revised plans for future dependency lanes. Review feedback identifies an inconsistency in how PRs are grouped between the 'Top 10' list and the 'Next lane split' section, as well as minor punctuation differences between the two ledger files.
| 9. #156 / #7 / #6 / #34: refresh GitHub Actions dependency lane with workflow validation. | ||
| 10. #152 / #151 / #150 / #146: refresh high-risk Python dependency lane with focused tests. | ||
| 8. #156 / #7 / #6 / #34: refresh GitHub Actions dependency lane with workflow validation. | ||
| 9. #152 / #151 / #150 / #146: refresh high-risk Python dependency lane with focused tests. |
There was a problem hiding this comment.
The grouping in point 9 of the Top 10 list (#152, #151, #150, #146) is inconsistent with the lane split defined in lines 66-68. While point 9 rollup is described as the "high-risk Python dependency lane", the lane split section separates these into three distinct lanes (Python runtime, Discord/crypto, and Provider/media). It would be clearer to maintain consistent grouping or explicitly state that point 9 is a rollup of high-risk items from multiple lanes.
| | #127 | `lodash` in `clients/web` | CLOSED | CLOSE_SUPERSEDED | Yes | Current `clients/web/package-lock.json` no longer contains a `node_modules/lodash` package entry; Dependabot alerts are 0. | Closed with evidence comment. Recreate only if `lodash` reappears. | | ||
| | #119 | `picomatch` in `clients/web` | CLOSED | CLOSE_SUPERSEDED | Yes | Current `clients/web/package-lock.json` contains `picomatch` 2.3.2 and nested `picomatch` 4.0.4; Dependabot alerts are 0. | Closed with evidence comment. | | ||
| | #117 | `flatted` in `clients/web` | CLOSED | CLOSE_SUPERSEDED | Yes | Current `clients/web/package-lock.json` contains `flatted` 3.4.2; Dependabot alerts are 0. | Closed with evidence comment. | |
There was a problem hiding this comment.
The evidence descriptions for #127, #119, and #117 in this file include trailing periods, whereas the corresponding entries in docs/maintenance/OPEN_PR_TRIAGE_2026_05_20.md (lines 108-111) do not. For consistency across triage ledgers, it is recommended to use a uniform punctuation style for evidence strings.
Scope
Evidence
gh api /repos/YoneRai12/YonerAI/dependabot/alerts?state=open&per_page=100 --jq lengthreturned0.clients/web/package-lock.jsoncontainsflatted3.4.2.clients/web/package-lock.jsoncontainspicomatch2.3.2and nestedpicomatch4.0.4.clients/web/package-lock.jsonno longer contains anode_modules/lodashpackage entry.clients/web/package-lock.jsonand no longer carried unique required implementation.Validation
git diff --checkpassed.git diff --cached --checkpassed before commit.tokenhits are existing explanatory wording only.src/cogs/ora.py: unchanged.reference_clawdbot: untouched.Non-claims
This does not claim dependency remediation is complete, production readiness, official cloud completion, hybrid completion, persistent memory, Google login, Discord gateway completion, provider ecosystem completion, Tools/MCP completion, or
src/cogs/ora.pyresolution.