Skip to content

chore(repo): prune stale minimumReleaseAge exemptions - #1102

Open
apollo-ui-release-bot[bot] wants to merge 1 commit into
mainfrom
chore/prune-release-age-exemptions-20260831
Open

chore(repo): prune stale minimumReleaseAge exemptions#1102
apollo-ui-release-bot[bot] wants to merge 1 commit into
mainfrom
chore/prune-release-age-exemptions-20260831

Conversation

@apollo-ui-release-bot

Copy link
Copy Markdown

Summary

The following packages were in `minimumReleaseAgeExclude` in `pnpm-workspace.yaml` because their latest release was too new at the time. Their latest versions are now older than the 14-day quarantine and no longer need an exemption.

  • nanoid@3.3.18
  • dompurify@3.4.13
  • mermaid@11.16.1
  • fast-uri@3.1.5
  • hono@4.12.34
  • framer-motion@13.1.0
  • motion@13.1.0
  • motion-dom@13.0.0
  • motion-utils@13.0.0

Automated by the Prune Release Age Exemptions workflow.

Copilot AI lite review requested due to automatic review settings August 31, 2026 09:08
@apollo-ui-release-bot apollo-ui-release-bot Bot added the dependencies Pull requests that update a dependency file label Aug 31, 2026
@github-actions

github-actions Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Apollo Coded App preview deployments finished with failures.

Project Status Preview Updated (PT)
apollo-design Failed Logs Aug 31, 2026, 02:17:21 AM
apollo-docs Ready Preview · Logs Aug 31, 2026, 02:17:21 AM
apollo-landing Ready Preview · Logs Aug 31, 2026, 02:17:21 AM
apollo-vertex Ready Preview · Logs Aug 31, 2026, 02:17:21 AM

@github-actions github-actions Bot added the size:XS 0-9 changed lines. label Aug 31, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

Pull request overview

Removes now-stale minimumReleaseAgeExclude entries from pnpm-workspace.yaml after the affected package versions have aged past the repository’s 14‑day pnpm quarantine window. This keeps the supply-chain hardening configuration minimal while preserving the quarantine for newer releases.

Changes:

  • Pruned version-scoped minimumReleaseAgeExclude exemptions for nanoid, dompurify, mermaid, fast-uri, hono, and the framer-motion/motion* packages.
  • Retained existing scope-based exemptions (e.g., @turbo/*, @esbuild/*, @next/*) and other pnpm hardening settings.
File summaries
File Description
pnpm-workspace.yaml Removes stale minimumReleaseAgeExclude entries whose versions are now older than the quarantine threshold.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

Copy link
Copy Markdown
Contributor

Dependency License Review

  • 1951 package(s) scanned
  • ✅ No license issues found
  • ⚠️ 2 package(s) excluded (see details below)
License distribution
License Packages
MIT 1722
ISC 88
Apache-2.0 55
BSD-3-Clause 27
BSD-2-Clause 23
BlueOak-1.0.0 8
MPL-2.0 4
MIT-0 3
CC0-1.0 3
MIT OR Apache-2.0 2
(MIT OR Apache-2.0) 2
Unlicense 2
LGPL-3.0-or-later 1
Python-2.0 1
CC-BY-4.0 1
(MPL-2.0 OR Apache-2.0) 1
Unknown 1
Artistic-2.0 1
(WTFPL OR MIT) 1
(BSD-2-Clause OR MIT OR Apache-2.0) 1
CC-BY-3.0 1
0BSD 1
(MIT OR CC0-1.0) 1
MIT AND ISC 1
Excluded packages
Package Version License Reason
@img/sharp-libvips-linux-x64 1.3.2 LGPL-3.0-or-later LGPL pre-built binary, not linked
khroma 2.1.0 Unknown MIT per GitHub repo, missing license field in package.json

@github-actions

Copy link
Copy Markdown
Contributor

📊 Coverage + size by package

Per-package bundle size on this PR (no JS/TS source changes detected under packages/* or web-packages/*).

Package Coverage New-line coverage Packed (gzip) Unpacked vs main
@uipath/apollo-core
@uipath/apollo-react
@uipath/apollo-ui-icons
@uipath/apollo-wind
@uipath/ap-chat

"Coverage" is each package's own coverage.include scope (e.g. apollo-core instruments only scripts/). "Packed"/"Unpacked" come from npm pack --dry-run and only cover built packages — "—" means not measured this run (package not affected / not built). "vs main" is the packed (gzipped) delta against the last successful main build (the package-sizes artifact from the Release workflow); "—" there means no main baseline was available this run. The baseline is main's latest build, not this PR's exact merge-base, so it includes any drift since the branch diverged. Packages with no vitest config are omitted.

@github-actions

Copy link
Copy Markdown
Contributor

Storybook visual diff

⏭️ Skipped: the apollo-design preview deployment did not succeed, so no comparison ran. Logs

Updated (PT): Aug 31, 2026, 02:17:33 AM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file size:XS 0-9 changed lines.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant