Skip to content

Bug: dependabot-repair-deferred-credential-criteria-and-residuals (follow-up to #911) #914

Description

@drmoisan
  • Work Mode: minor-audit

Summary

Follow-up to issue #911. Three acceptance criteria of that change depend on a GitHub App installation
token that does not exist yet, two PowerShell files carry formatting #911 deliberately left alone,
and Phase 7 surfaced two further residuals. This entry carries all of them so none is lost when #911
merges.

Environment

  • OS/version: Windows 11 Pro 10.0.26200
  • Python version: n/a (.NET Framework 4.8.1 VSTO solution)
  • Command/flags used: measured in the Bug: dependabot-fanout-and-ci-failing-nuget-upgrades #911 execution worktree on 2026-09-20
  • Data source or fixture: repository secrets query and open-pull-request query, both exiting 0

Steps to Reproduce

  1. Query repository secrets and open Dependabot pull requests; both return empty.
  2. Observe that AC18, AC19 and AC20 of Bug: dependabot-fanout-and-ci-failing-nuget-upgrades #911 cannot be exercised without a credential and a fixture.
  3. Run the repository formatter over scripts/vscode/; observe two files it would rewrite.
  4. Inspect the six app.config files named below against their restored packages.

Expected Behavior

Every acceptance criterion of #911 is exercised against a live fixture, the repository formatter
leaves no file it would rewrite, and every binding redirect names the assembly version the restored
package actually ships.

Actual Behavior

Three criteria are deferred, two files remain unformatted by deliberate scope decision, ten binding
redirects are stale, and one shipped module carries an unreached defect in its own entry point.

Logs / Screenshots

  • Attached minimal logs or snippet

Follow-up to issue #911. Three acceptance criteria of that change depend on a GitHub App
installation token that does not exist yet, and two PowerShell files in scripts/vscode/ carry
formatting the repository's formatter would rewrite but which #911 deliberately left alone. This
issue carries both, so neither is lost when #911 merges.

Impact / Severity

  • Blocker
  • High
  • Medium
  • Low

Nothing here blocks #911. The deferred criteria are unverifiable rather than failing, the formatting
and redirect items are pre-existing, and the module defect is unreachable through the shipped
composition root.

Source

From: docs/features/potential/2026-09-20-dependabot-repair-deferred-credential-criteria-and-residuals.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions