build(deps): bump actions/stale from 10 to 11 - #134
Conversation
Bumps [actions/stale](https://github.com/actions/stale) from 10 to 11. - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](actions/stale@v10...v11) --- updated-dependencies: - dependency-name: actions/stale dependency-version: '11' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
Codex review: needs maintainer review before merge. Reviewed August 1, 2026, 6:56 PM ET / 22:56 UTC. ClawSweeper reviewWhat this changesUpdates all three scheduled stale-policy steps in Merge readiness⛔ Blocked until real behavior proof is added - 5 items remain This PR remains necessary: current Priority: P3 Review scores
Verification
How this fits togetherGitcrawl’s scheduled stale workflow passes repository inactivity policy into the third-party flowchart LR
A[Daily schedule or manual dispatch] --> B[Gitcrawl stale workflow]
B --> C[Stale-policy inputs]
C --> D[actions/stale v11]
D --> E[Issue and pull-request labels]
D --> F[Issue and pull-request closure]
Decision needed
Why: The branch changes third-party code that receives issue and pull-request write permissions; the correct validation environment and acceptable mutation scope are repository-owner choices. Before merge
Findings
Agent review detailsSecurityNeeds attention: This narrow dependency reference update changes code executed with repository write permissions, and no controlled execution evidence establishes its mutation behavior under the existing policy. Review metrics
Merge-risk optionsMaintainer options:
Copy recommended automerge instructionTechnical reviewBest possible solution: Validate v11 in an isolated repository or other controlled target using the current policy inputs and known stale/non-stale issue and pull-request fixtures, then merge this narrow reference-only update if the observed mutations match the existing policy. Do we have a high-confidence way to reproduce the issue? Not applicable as a bug reproduction: this PR upgrades workflow automation rather than repairing a reported runtime failure. A high-confidence merge proof instead requires a controlled execution of the scheduled stale policy with v11. Is this the best way to solve the issue? Unclear: changing only the three references is the narrowest implementation, but it is not yet proven safe for this repository’s write-capable stale workflow. Controlled after-fix behavior evidence is the safer path before acceptance. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning high; reviewed against dcdf94703540. LabelsLabel justifications:
EvidenceSecurity concerns:
What I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (13 earlier review cycles; latest 8 shown)
|
Bumps actions/stale from 10 to 11.
Release notes
Sourced from actions/stale's releases.
... (truncated)
Changelog
Sourced from actions/stale's changelog.
... (truncated)
Commits
4391f3dFix 24 high severity vulnerabilities by overriding brace-expansion to 5.0.8 (...eaf9131refactor: update imports to use ES module syntax and improve test structure (...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)