ci: drop the two dependabot labels this repo does not have - #1761
Merged
Merged
Conversation
`.github/dependabot.yml` requested `automated` (npm block) and `github-actions` (GitHub-Actions block). Neither is declared in `.github/labels.yml` nor exists in the repository, so Dependabot failed the labelling step on every PR it opened since 2026-08-10. The bot reports only that *a* label failed, never which one, so the second missing name was invisible from the notice alone; each referenced name was checked against the repo's actual label set. `dependencies` and `skip-changeset` were confirmed to exist and are kept. Dropped rather than created: `dependencies` already marks these PRs, and `.github/labels.yml` governs the taxonomy by design. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019YKN9TPqDSSXUaYqp2j7MZ
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1743
Description
.github/dependabot.ymlasked for two labels this repository does not have. Dependabot cannot create labels, so it failed the whole labelling step and said so in its first comment on every PR it opened, from #1058 (2026-08-10) onward. Both names are removed.automated, and deleting only that name would have left the notice repeating on the next Dependabot PR with nothing new to read and no way to tell whether the fix had worked. Establishing that a second name was also missing required checking each referenced name against the repository's actual label set; it could not be got by reading the notice more carefully.Type of Change
Related Issues
Fixes #1743
Changes Made
automatedfrom the npm block'slabels:list.github-actionsfrom the GitHub-Actions block'slabels:list — the second missing name, invisible from the bot's notice.Both blocks now request only
dependenciesandskip-changeset, which do exist. ⛔ Thepackage-ecosystem: "github-actions"value on line 25 is a different key and is untouched — only the label entry was removed.The verification, in full
Every name the file references was checked against two independent sources, with a control so the two misses read as measurements rather than a broken endpoint:
.github/labels.ymldependenciesskip-changesetautomatedgithub-actionsci/cd(control)The control leg matters: the same channel, same repository, returns a real label for
ci/cd(color 6e5494, "CI plumbing and the verification pipeline"). So the two 404s are genuine absences, not a denied endpoint returning empty..github/labels.ymlcalls itself "the single source of truth for this repository's labels" and governs the taxonomy by design ("no ad-hoc labels"). Neither removed name appears in it.Why removed rather than created
dependenciesalready marks these PRs and is enough to filter them, so a new label would serve the config rather than a reader. Creating labels would also widen the manifest to match a stale config; this brings the config to the manifest instead, which is the direction.github/labels.ymlprescribes. Reversible at one line each if the maintainer wants the cross-repo axis.Why a real changeset and not
skip-changeset⭐ Both routes are sanctioned and either is defensible; the reasoning is the deliverable, so here it is.
AGENTS.mdcallsskip-changeset"the lone exception … for PRs that ship nothing to users", and this PR genuinely ships nothing — so that label would not have been a reach to turn a red check green. I went the other way for three reasons:docs-app-runs-on-content-changes.mdanddocs-anchor-existence-guard.mdare two pure.github/changes that do exactly this..github/workflows/changeset-check.ymldocuments the empty-frontmatter changeset as "the sanctioned 'this PR releases nothing' declaration, on par with theskip-changesetlabel."Testing
pnpm verify(=validate && typecheck && lint && lint:i18n-gate && hygiene && hygiene:tokens && build && test) run in full on the pushed tree:No test was added — see the note below on why that is a reporting matter rather than something to fix inside this PR.
Additional Notes
Observed, not acted on — reported for the seat to file if it agrees, ⛔ not fixed here:
.github/labeler.ymlcarries a guard for this exact defect class. Its header states the invariant ("Every label key must already exist in the repository —actions/labelerdoes not create them") andtest/labeler-config.test.tsenforces it. Nothing enforces the same invariant for.github/dependabot.yml: no test in the repo reads that file'slabels:list, which is why this survived a month. Extending the guard would close the class, but it adds a new verification surface, so it is out of scope for this card..github/labeler.ymlitself is clean — all six of its keys are declared in the manifest..github/labels.ymllists the workflow group as "needs-user-decision / skip-changeset", but the manifest also declarespm:queueandpm:dispatched. Comment drift only; no behaviour depends on it.U+00B7and stores inert.skip-deleteis load-bearing, not belt-and-braces #1501 remains open and is not addressed here; its scope is the manifest disagreeing with live usage, which is a different problem from this one config line.Environment note: REST label enumeration returned 403 in this container ("GitHub access is not enabled for this session") — the same wall #1501 records. The per-name checks above went through a different channel, which succeeded and carried the control leg.
🤖 Generated with Claude Code
https://claude.ai/code/session_019YKN9TPqDSSXUaYqp2j7MZ
Generated by Claude Code