Skip to content

fix: (dependency review) new preset allow-listing certain deps#1413

Merged
erikburt merged 3 commits intomainfrom
fix/dependency-review-allowed-deps
Feb 10, 2026
Merged

fix: (dependency review) new preset allow-listing certain deps#1413
erikburt merged 3 commits intomainfrom
fix/dependency-review-allowed-deps

Conversation

@erikburt
Copy link
Contributor

@erikburt erikburt commented Feb 10, 2026

Changes

Add new preset, allowing two deps that we are incorrectly flagging for license violations.

Testing

https://github.com/smartcontractkit/releng-test/actions/runs/21881895055

Caveats

The option doesn't support specific dependencies and licenses, so we basically have to ignore these packages regardless of their license. This would be a problem if they changed to something else that we cannot use for example.


DX-2809

@erikburt erikburt self-assigned this Feb 10, 2026
@erikburt erikburt force-pushed the fix/dependency-review-allowed-deps branch from 32e92d0 to a8d53e1 Compare February 10, 2026 20:59
@erikburt erikburt force-pushed the fix/dependency-review-allowed-deps branch from a8d53e1 to 8ff6201 Compare February 10, 2026 21:04
@erikburt erikburt changed the title fix: (dependency review) allow BUSL-1.1 license for certain deps fix: (dependency review) allowlist license for certain deps Feb 10, 2026
@erikburt erikburt changed the title fix: (dependency review) allowlist license for certain deps fix: (dependency review) new preset allow-listing certain deps Feb 10, 2026
@erikburt erikburt requested a review from chainchad February 10, 2026 21:44
@erikburt erikburt marked this pull request as ready for review February 10, 2026 21:44
@erikburt erikburt requested a review from a team as a code owner February 10, 2026 21:44
@erikburt erikburt merged commit 06c37ae into main Feb 10, 2026
17 checks passed
@erikburt erikburt deleted the fix/dependency-review-allowed-deps branch February 10, 2026 23:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants