Skip to content

AutoFix: correct the lockfile behavior for yarn, pnpm and Go - #458

Merged
maximelb merged 1 commit into
masterfrom
autofix-lockfile-text
Sep 29, 2026
Merged

maximelb merged 1 commit into
masterfrom
autofix-lockfile-text

Conversation

@maximelb

Copy link
Copy Markdown
Contributor

The AutoFix page said yarn.lock and pnpm-lock.yaml are not updated and that go.sum is never edited. Both are stale: the lockfile is updated, or the fix is refused before any job runs (autofix_not_applicable) when it cannot be updated safely. Only package-lock.json can still end up flagged stale (for example with autofix_registry_access: false).

🤖 Generated with Claude Code

… not left stale

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@limacharlie-refractionpoint

Copy link
Copy Markdown

LimaCharlie Cloud Security — code scan

No new code findings were introduced by this pull request.

This check reports and never fails: no gating.fail_on is set on the code_scanning policy.

Scanned refractionPOINT/documentation c22c6a4…86ef583 — only findings new in the head commit are listed; anything already on the base branch is the repository's own finding set, on the Cloud Security Code page.

This comment is updated in place on every push to this pull request.

@maximelb
maximelb merged commit 0553d39 into master Sep 29, 2026
8 checks passed
@maximelb
maximelb deleted the autofix-lockfile-text branch September 29, 2026 13:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants