Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

`updateAutomatedSecurityFixes` never called when no other repo settings changed

オープン 初心者向け
#983 コメント 1 件 リアクション 2 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
74/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
静か
技術スタック
javascript
領域
devops

調査の方向性

lib/plugins/repository.js の changes.hasChanges 分岐の周辺から始め、両方の分岐にある updateSecurity の呼び出しを比較します。他の値がすでに一致していて、enableAutomatedSecurityFixes が false になっているリポジトリ設定で npm run full-sync を実行します。changes.hasChanges が false のときに updateAutomatedSecurityFixes が呼び出され、自動セキュリティ修正が期待どおり更新されれば完了です。

索引モデルが issue の本文から書いたものです。

説明

Describe the bug

updateAutomatedSecurityFixes is only called inside the if (changes.hasChanges) branch in lib/plugins/repository.js. When all other repository settings already match the desired state (i.e. changes.hasChanges === false), the else branch is taken — but that branch only calls updateSecurity (vulnerability alerts). updateAutomatedSecurityFixes is never invoked, so enableAutomatedSecurityFixes: false in settings.yml has no effect.

Relevant code (lib/plugins/repository.js ~line 96, version 2.1.18):

if (changes.hasChanges) {
  // ...
  promises.push(updateRepoPromise.then(() => {
    return this.updateSecurity(resp.data, resArray)
  }))
  promises.push(updateRepoPromise.then(() => {
    return this.updateAutomatedSecurityFixes(resp.data, resArray)  // ✓ called
  }))
} else {
  promises.push(this.updateSecurity(resp.data, resArray))
  // ← updateAutomatedSecurityFixes is missing here
}

To reproduce

settings.yml:

repository:
  # ... other settings that already match repo state ...
  security:
    enableAutomatedSecurityFixes: false  # desired: disabled
  1. Ensure all other repository: settings already match the current repo state so changes.hasChanges is false
  2. Run npm run full-sync
  3. Observe: disableAutomatedSecurityFixes is never called; repos retain their current value

Expected behaviour

updateAutomatedSecurityFixes should be called regardless of whether other repo settings changed — the same way updateSecurity is called in both branches.

Suggested fix

} else {
  promises.push(this.updateSecurity(resp.data, resArray))
  promises.push(this.updateAutomatedSecurityFixes(resp.data, resArray))  // add this
}

Environment

  • safe-settings version: 2.1.18
  • Running via npm run full-sync in GitHub Actions
主要言語
JavaScript
スター
922
フォーク
227
平均マージ
6時間 19分
マージ済み PR(30日)
10

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

github-community-projects/safe-settings のほかの issue

github-community-projects/safe-settings の issue をすべて見る

似ている issue

JavaScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。