Two green GitHub pull requests broke main — require branches to be up to date before merging
Why a GitHub pull request with every check green can still break main, how Require branches to be up to date before merging stops it, and rules for main.
Why a GitHub pull request with every check green can still break main, how Require branches to be up to date before merging stops it, and rules for main.
Dependabot cannot update transitive dependencies on pnpm. Building the GitHub Action that patches them, and why its credential decided the design.
GNU Make as a task runner for a polyglot repo: prerequisite composition npm scripts cannot express, CI calling the same targets, and GNU Make 3.81 on macOS.
GitHub OIDC gives CI an AWS identity, but a JWT-authorized MCP endpoint needs a second one: a Cognito client_credentials token read from terraform output.
Gitignored Terraform override files retarget a committed config at your own AWS sandbox: a local backend, overridden locals, and what only apply found.
On a private repo the dependency graph is off by default, so Dependabot opened no npm pull request, and the auto-merge workflow merged 45s before CI finished.