FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

ci: excludes samples from dotnet dependabot because they are causing a timeout by baywet · Pull Request #8476 · microsoft/agent-framework · GitHub

Repository navigation

ci: excludes samples from dotnet dependabot because they are causing a timeout - #8476

Merged
Vincent Biret (baywet) merged 2 commits into
mainfrom
ci/dependabot-dotnet
Sep 17, 2026
Merged

Vincent Biret (baywet) merged 2 commits into
mainfrom
ci/dependabot-dotnet

Conversation

Copy link
Copy Markdown
Member

despite the manual updates dependabot is still timing out on scans, this is another attempt at fixing it

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

🔵 Needs a closer look

The exclusion pattern targets the wrong path, so sample manifests remain in scope.

Pull request overview

Attempts to exclude .NET samples from Dependabot NuGet scans to prevent timeouts.

Changes:

  • Adds an exclusion rule for the .NET samples directory.
File summaries
File Description
.github/dependabot.yml Configures Dependabot path exclusions.
Review details

Suppressed comments (1)

.github/dependabot.yml:16

  • exclude-paths patterns are resolved relative to the configured directory (dotnet/). This therefore targets dotnet/dotnet/samples/** and does not exclude the repository's dotnet/samples/**, so the timeout-causing manifests remain in scope. Use samples/** here (or change the base directory).
      - "dotnet/samples/**"
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite (auto)

Note

Copilot is running an experiment and ran this review at Lite.


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

MAF Automated Review — Iteration 1

Result: Findings reported
Scope: full PR (1 commit(s)): b7c5240f0078
Model: gpt-5.6-sol-fast

Overview

The PR takes a focused approach by excluding the sample subtree while retaining production projects, tests, and central package versions in the NuGet update job. Existing grouping, cooldown, CI coverage, and central package management constrain update volume and validate resulting dependency changes. However, the new glob is rooted incorrectly, so all sample manifests remain in scope and the Dependabot timeout this change is meant to resolve can continue blocking NuGet updates.

Reviewed the supplied pull-request change set across correctness, security/reliability, architecture, and failure behavior.
1 verified finding remained after source verification (1 high) across 1 file. Details are attached to the affected lines below.

Affected areas: .github/dependabot.yml

Comment thread .github/dependabot.yml Outdated
This was referenced Sep 30, 2026

This branch was successfully deployed

1 active deployment
github-app-auth — 462b1db7 Deployed Sep 17, 2026 by baywet via add_label #23159
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants


Back | FazBrowse Home | New Git URL