Skip to content

Conversation

DavidBiddle
Copy link
Contributor

@DavidBiddle DavidBiddle commented Sep 26, 2025

What problem does this pull request solve?

We previously (#1644) removed npm from our Dependabot configuration in response to the Shai-Hulud npm worm.

This PR readds it since we think the immediate risk has been adequately mitigated.

Reverts #1644

Things to consider when reviewing

  • Ensure that you consider the wider context.
  • Does it work when run on your machine?
  • Is it clear what the code is doing?
  • Do the commit messages explain why the changes were made?
  • Are there all the unit tests needed?
  • Do the end to end tests need updating before these changes will pass?
  • Has all relevant documentation been updated?

Copy link

@DavidBiddle DavidBiddle marked this pull request as ready for review September 26, 2025 13:37
Copy link
Contributor

🎉 A review copy of this PR has been deployed! It is made of up two components

  1. A review copy of forms-runner
  2. A production copy of forms-admin

Important

Not all of the functionality of forms-runner is present in review apps.
Functionality such as sending emails, file upload, and S3 submission types are
deliberately disabled for the sake of simplifying review apps.

You should use the full dev environment to test the functionality which is disabled here.

It may take 5 minutes or so for the application to be fully deployed and working. If it still isn't ready
after 5 minutes, there may be something wrong with the ECS task. You will need to go to the integration AWS account
to debug, or otherwise ask an infrastructure person.

For the sign in details and more information, see the review apps wiki page.

@DavidBiddle DavidBiddle merged commit a0516f5 into main Sep 26, 2025
12 checks passed
@DavidBiddle DavidBiddle deleted the revert-1644-ldeb-stop-dependabot-npm branch September 26, 2025 14:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants