Skip to content

fix(dag): stop concurrent map crash in bulk terraform commands - #2831

Merged
Andriy Knysh (aknysh) merged 11 commits into
mainfrom
osterman/dag-concurrent-map-fix
Jul 31, 2026
Merged

Andriy Knysh (aknysh) merged 11 commits into
mainfrom
osterman/dag-concurrent-map-fix

Conversation

@osterman

@osterman Erik Osterman (Cloud Posse) (osterman) commented Jul 30, 2026 •

Copy link
Copy Markdown
Member

what

  • Fix a fatal error: concurrent map iteration and map write crash in DAG-scheduled bulk terraform commands (terraform <cmd> --all/--affected/--query) at higher --max-concurrency.
  • ProcessComponentConfig now shallow-clones the component section before any downstream code mutates it, so concurrent workers never write into the map tree owned by the shared FindStacksMap cache.
  • Apply the same shallow-clone-before-mutate fix to two adjacent cache-corruption sites in the describe-stacks processor (deleting imports, and terraform_workspace_pattern/terraform_workspace_template, from cache-owned maps in place).
  • Add regression tests (internal/exec/process_stacks_shared_cache_test.go) that fail pre-fix both deterministically and under -race.
  • Bump the brace-expansion pnpm.overrides (website) to 1.1.18/2.1.4, patching CVE-2026-14257 / GHSA-mh99-v99m-4gvg (high-severity DoS via unbounded expansion length), reported by Dependabot alert Documented ADRs for Atmos #261.

why

  • FindStacksMap caches processed stack config and returns it by reference on cache hits, shared across all goroutines within a process. ProcessStacks and mergeGlobalAuthConfig write top-level keys into that shared component section, while findComponentInStacks has every DAG worker iterate every stack's component section (not just its own) looking for a match — so one worker's write races with another worker's read/iteration of the same cached map, crashing exactly as reported.
  • The describe-stacks processor had the identical hazard in two more places (both mutate cache-owned maps in place), corrupting the cache for every subsequent ProcessStacks call in the same process even outside the crash path.
  • The brace-expansion bump addresses an open, high-severity Dependabot alert; deferring it risks a DoS crash if attacker-influenced input reaches an affected glob/brace-pattern code path in the docs site tooling.

references

Summary by CodeRabbit

  • Bug Fixes

    • Prevented concurrency-related crashes when processing multiple stacks or components in parallel.
    • Preserved cached configuration data during stack and component processing.
    • Improved template handling for computed Terraform and Atmos sections.
    • Ensured generated Spacelift and Atlantis names are available during template evaluation.
    • Corrected describe output to include referenced imports consistently.
    • Improved propagation of configuration and template-processing errors.
  • Documentation

    • Clarified dependency advisory exceptions and their removal criteria.
    • Documented the concurrency crash fix and validation coverage.

… commands

FindStacksMap returns its cached stack config maps by reference, and
ProcessComponentConfig handed the shared component section straight to
callers. DAG-scheduled bulk commands (terraform --all/--affected/--query)
run ProcessStacks concurrently across workers, so one worker's writes
(atmos_component, workspace, sources, deps, merged auth, ...) raced with
another worker's reads of the same cached section, crashing with
`fatal error: concurrent map iteration and map write` at higher
--max-concurrency.

Shallow-clone the component section before mutating it, and apply the
same fix to two adjacent cache-corruption sites in the describe-stacks
processor that deleted keys from cache-owned maps in place. Add
regression tests that fail pre-fix both deterministically and under
-race.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…9-v99m-4gvg)

brace-expansion <=5.0.7 lets expand() accumulate unbounded output length
from chained brace groups, causing an uncatchable OOM crash (high
severity, Dependabot alert #261). Bump the existing pnpm overrides for
both major lines in use here (transitive via minimatch, pulled in by
serve-handler/docusaurus and docusaurus-plugin-llms) to the patched
releases: 1.1.18 and 2.1.4, both published today with the
EXPANSION_MAX_LENGTH bound backported from the 5.0.8 fix. Verified by
diffing the published tarballs against the vulnerable versions.

Website builds clean with the bump; no Go code is affected.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@atmos-pro

atmos-pro Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@osterman Erik Osterman (Cloud Posse) (osterman) added the patch A minor, backward compatible change label Jul 30, 2026
@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

ProcessStacks and describe-stacks now avoid mutating shared cached maps, preserve non-templated sections, and populate derived fields before template processing. Regression tests cover cache safety, concurrency, and builder errors. Dependency-review documentation is expanded while executable version checking is removed.

Changes

Shared cache safety

Layer / File(s) Summary
Cache contract and ProcessStacks isolation
internal/exec/utils.go
Cached maps are documented as read-only, component sections are cloned before mutation, derived names are populated earlier, and non-templated sections are restored after rendering.
Describe-stacks mutation isolation
internal/exec/describe_stacks_component_processor.go, tests/snapshots/*
Stack and metadata maps are cloned before deletion, template processing preserves excluded sections, and snapshots reflect updated imports and formatting.
Regression coverage
internal/exec/process_stacks_shared_cache_test.go, internal/exec/process_stacks_builder_errors_test.go
Tests verify cache immutability, concurrent access, and propagation of invalid Spacelift and Atlantis configuration errors.
Concurrency fix documentation
docs/fixes/2026-07-30-dag-concurrent-map-crash.md
Documents the failure mechanism, cloning changes, tests, and validation commands.

Dependency review documentation

Layer / File(s) Summary
Brace-expansion advisory documentation
.github/workflows/dependency-review.yml
Removes executable brace-expansion version verification and documents advisory suppression, override scope, upstream constraints, and removal conditions.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant ProcessStacks
  participant FindStacksMap
  participant ProcessComponentConfig
  participant TemplateProcessor
  ProcessStacks->>FindStacksMap: read cached stack configuration
  FindStacksMap-->>ProcessStacks: return shared map
  ProcessStacks->>ProcessComponentConfig: clone component section
  ProcessComponentConfig-->>ProcessStacks: return isolated component data
  ProcessStacks->>TemplateProcessor: render templated sections
  TemplateProcessor-->>ProcessStacks: restore non-templated sections
Loading

Possibly related PRs

Suggested reviewers: aknysh

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the primary fix for concurrent map crashes in DAG bulk Terraform commands.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch osterman/dag-concurrent-map-fix

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues found.

Scanned Files

None

The Dependency Review job still flags brace-expansion@1.1.18/2.1.4 (added
in the prior brace-expansion bump) because GHSA-mh99-v99m-4gvg's recorded
vulnerable range ("<=5.0.7") doesn't distinguish between brace-expansion's
parallel 1.x/2.x/5.x release lines. Both versions we use already contain
the same EXPANSION_MAX_LENGTH bound backported from the 5.0.8 fix,
verified by diffing the published tarballs against the CVE fix commit.

Upgrading further to the only version the advisory recognizes as patched
(5.0.8+) isn't safe here: brace-expansion 5.x's CommonJS build switched
from a callable default export to a named `exports.expand`, which breaks
minimatch@3.1.5's `require('brace-expansion')(...)` call convention
(transitive via serve-handler/@docusaurus/core) — a genuine breaking API
change, not just a semver-major label. Allowlisted following the existing
GHSA-fxhp-mv3v-67qp precedent in this same file, with the reasoning
recorded inline for removal once GitHub's advisory data or minimatch's
dependency catches up.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@mergify

mergify Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Important

Cloud Posse Engineering Team Review Required

This pull request modifies files that require Cloud Posse's review. Please be patient, and a core maintainer will review your changes.

To expedite this process, reach out to us on Slack in the #pr-reviews channel.

Acceptance tests started failing after the ProcessComponentConfig clone
(previous commit): describe component's tags.spacelift_stack/
tags.atlantis_project rendered as `<no value>` instead of the resolved
name, and path-resolved describe component (`.`/`./component`) showed an
empty imports list instead of the real one.

Both were pre-existing bugs masked by the exact cache-mutation issue just
fixed. `describe component` runs ProcessStacks twice per invocation (once
via resolveAuthManager's preliminary ExecuteDescribeComponent call, once
for the real result); pre-fix, the first call's completed computation
leaked into the second call's shared, unprotected cache entry, making
`{{ .spacelift_stack }}`/`{{ .atlantis_project }}` template references
resolve "by accident" and making a describe-stacks preliminary pass's
`delete(stackMap, "imports")` corruption invisible. Once ProcessStacks
stopped mutating the shared cache, each call started from a clean slate
and both latent bugs became visible and deterministic.

BuildSpaceliftStackNameFromComponentConfig/BuildAtlantisProjectNameFromComponentConfig
only depend on data already populated before template processing
(ComponentSettingsSection, ComponentVarsSection, ComponentFromArg, Stack),
so move both calls before the template-processing block instead of after
it. This makes `.spacelift_stack`/`.atlantis_project` genuinely available
to templates in a single pass, matching what the working
"describe component <name>" (backward-compatibility) golden snapshot
already showed, and consistent regardless of how many times ProcessStacks
runs per invocation.

Regenerated the 3 affected golden snapshots via `-regenerate-snapshots`
per repo convention (never hand-edited) — verified each diff against the
now-consistent, already-correct behavior on the other snapshot.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
internal/exec/process_stacks_shared_cache_test.go (1)

20-21: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Build the fixture path with filepath.Join.

Proposed fix
 import (
+	"path/filepath"
 	"sync"
 	"testing"
@@
-	testDir := "../../tests/fixtures/scenarios/stack-manifest-name-template"
+	testDir := filepath.Join("..", "..", "tests", "fixtures", "scenarios", "stack-manifest-name-template")

As per coding guidelines, tests must use filepath.Join() for filesystem paths.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@internal/exec/process_stacks_shared_cache_test.go` around lines 20 - 21,
Update the test fixture path assignment before t.Chdir in the relevant test to
construct the path with filepath.Join instead of a hardcoded slash-separated
string, and ensure the filepath package is imported.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/dependency-review.yml:
- Line 81: Update the dependency-review configuration around the allow-ghsas
entry to scope the GHSA-mh99-v99m-4gvg exception to the verified brace-expansion
versions covered by the pinned ^1 and ^2 overrides. Add a lock/version assertion
or equivalent validation so future brace-expansion 3.x/4.x resolutions cannot
bypass the vulnerability check.

---

Nitpick comments:
In `@internal/exec/process_stacks_shared_cache_test.go`:
- Around line 20-21: Update the test fixture path assignment before t.Chdir in
the relevant test to construct the path with filepath.Join instead of a
hardcoded slash-separated string, and ensure the filepath package is imported.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: bbfc93ca-d5b4-461d-8e02-3c025968fc33

📥 Commits

Reviewing files that changed from the base of the PR and between 6f92049 and b65d794.

⛔ Files ignored due to path filters (1)
  • website/pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (9)
  • .github/workflows/dependency-review.yml
  • docs/fixes/2026-07-30-dag-concurrent-map-crash.md
  • internal/exec/describe_stacks_component_processor.go
  • internal/exec/process_stacks_shared_cache_test.go
  • internal/exec/utils.go
  • tests/snapshots/TestCLICommands_describe_component_with_component_name_(backward_compatibility).stdout.golden
  • tests/snapshots/TestCLICommands_describe_component_with_current_directory_(.).stdout.golden
  • tests/snapshots/TestCLICommands_describe_component_with_relative_path.stdout.golden
  • website/package.json
💤 Files with no reviewable changes (1)
  • tests/snapshots/TestCLICommands_describe_component_with_component_name_(backward_compatibility).stdout.golden

Comment thread .github/workflows/dependency-review.yml
@codecov

codecov Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.94%. Comparing base (b69113d) to head (8b4265f).

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #2831      +/-   ##
==========================================
+ Coverage   81.90%   81.94%   +0.03%     
==========================================
  Files        1798     1798              
  Lines      173914   173917       +3     
==========================================
+ Hits       142450   142513      +63     
+ Misses      23688    23634      -54     
+ Partials     7776     7770       -6     
Flag Coverage Δ
unittests 81.94% <100.00%> (+0.03%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
...ternal/exec/describe_stacks_component_processor.go 95.84% <100.00%> (+0.01%) ⬆️
internal/exec/utils.go 88.71% <100.00%> (+3.44%) ⬆️

... and 12 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Address CodeRabbit review feedback on PR #2831: allow-ghsas allowlists
GHSA-mh99-v99m-4gvg by ID only, so any future brace-expansion resolution
(an unpatched 3.x/4.x, or a 1.x/2.x release without the backported fix)
would silently bypass the vulnerability check. Add a CI step that parses
website/pnpm-lock.yaml and fails the job if any resolved brace-expansion
version isn't in the explicit verified-patched set (1.1.18, 2.1.4).

Also add regression tests closing the patch-coverage gap Codecov flagged
on the two Spacelift/Atlantis error-propagation lines moved earlier in
ProcessStacks: real, reachable error paths (a malformed name_template for
BuildSpaceliftStackNameFromComponentConfig; a type-mismatched
settings.atlantis.project_template for
BuildAtlantisProjectNameFromComponentConfig) that ProcessStacks must
surface rather than silently swallow.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/dependency-review.yml:
- Around line 41-45: Update the found-assignment pipeline in the
dependency-review workflow so grep’s expected status 1 for no matches is
converted to empty input, allowing the existing “No brace-expansion entries
found” diagnostic to run. Preserve nonzero failures caused by unreadable or
otherwise invalid input, while keeping the current allowlist guidance unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 4e1a3d7f-0df6-47a4-a221-d30fa7d835f5

📥 Commits

Reviewing files that changed from the base of the PR and between b65d794 and 4de3c68.

📒 Files selected for processing (2)
  • .github/workflows/dependency-review.yml
  • internal/exec/process_stacks_builder_errors_test.go

Comment thread .github/workflows/dependency-review.yml Outdated
Address CodeRabbit review feedback on PR #2831: under `set -euo pipefail`,
grep's exit status 1 for "no matches" was propagating through the pipeline
into the `found=` assignment, aborting the step with a bare exit code
before the intended "No brace-expansion entries found" error message
ever printed. Convert grep's expected no-match status into empty input
while still preserving failures from a genuinely unreadable/missing file
(verified locally: exit 2 still aborts, exit 1 now reaches the diagnostic).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 30, 2026
…nt-map-fix

# Conflicts:
#	.github/workflows/dependency-review.yml
#	website/package.json
#	website/pnpm-lock.yaml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/dependency-review.yml (1)

41-45: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Check every brace-expansion lockfile version, not only X.Y.Z versions.

The current regex skips valid keys like brace-expansion@1.1.18-beta.0; since allow-ghsas suppresses the advisory for every resolved version, such a key would not fail this check and can bypass the scoped pin. Extract every brace-expansion@... key and compare the full version against the allowlist.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/dependency-review.yml around lines 41 - 45, The version
extraction in the found assignment must match every brace-expansion lockfile
key, including prerelease and other valid semver forms, rather than only numeric
X.Y.Z versions. Update the grep pattern and normalization around found to
capture the complete version after brace-expansion@, then compare those full
versions against the existing allowlist while preserving deduplication.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/dependency-review.yml:
- Around line 112-121: Update the comment near the brace-expansion exception to
replace “exact (non-^) pnpm override pins” with “exact override values,”
accurately distinguishing the selectors from their pinned target values while
preserving the rest of the scoping explanation.

---

Outside diff comments:
In @.github/workflows/dependency-review.yml:
- Around line 41-45: The version extraction in the found assignment must match
every brace-expansion lockfile key, including prerelease and other valid semver
forms, rather than only numeric X.Y.Z versions. Update the grep pattern and
normalization around found to capture the complete version after
brace-expansion@, then compare those full versions against the existing
allowlist while preserving deduplication.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 5be0723b-af84-4cb0-8ea9-005716db9398

📥 Commits

Reviewing files that changed from the base of the PR and between 0a487b3 and ecaba38.

📒 Files selected for processing (3)
  • .github/workflows/dependency-review.yml
  • internal/exec/describe_stacks_component_processor.go
  • internal/exec/utils.go

Comment thread .github/workflows/dependency-review.yml Outdated
Address CodeRabbit review feedback on PR #2831: the pnpm override
selectors (brace-expansion@^1/@^2) always carry a caret; only their
pinned target values (1.1.18/2.1.4) are exact. The prior comment
conflated the two, documenting an inaccurate contract.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 30, 2026
The bash step re-parsing website/pnpm-lock.yaml on every PR was pure
defense-in-depth on top of the allow-ghsas suppression and has cost
four follow-up commits with no functional benefit over the one-line
allowlist entry. Investigated a real fix (traced the dependency chain
to serve-handler/minimatch, checked dependency-review-action's
suppression options, confirmed upstream status via
isaacs/minimatch#314 and #310): there isn't one currently reachable
from this repo, so the suppression is structurally required, not a
maintenance debt we're choosing to carry. Rewrote the allow-ghsas
comment with the upstream citations and a concrete removal condition
instead of dropping the extra verification step silently.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♻️ Duplicate comments (1)
.github/workflows/dependency-review.yml (1)

68-111: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Automated brace-expansion version check removed — unscoped suppression now has no guardrail.

The prior fix added an executable step verifying website/pnpm-lock.yaml resolves only the audited 1.1.18/2.1.4 versions before trusting allow-ghsas. This PR removes that check and keeps only documentation. Since allow-ghsas: GHSA-mh99-v99m-4gvg suppresses the advisory for any resolved brace-expansion version (as the comment itself notes on lines 92-97), a future dependency bump resolving an unpatched version would now silently pass CI — the only thing catching that regression was the removed script.

Consider restoring the version-assertion step (with the earlier no-match fix from commit 0a487b3 applied) alongside the documentation, so the suppression stays backed by an automated guarantee rather than just a comment.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/dependency-review.yml around lines 68 - 111, Restore the
executable dependency-review guard that inspects website/pnpm-lock.yaml and
fails unless brace-expansion resolves only the audited 1.1.18 and 2.1.4
versions, applying the no-match handling from commit 0a487b3. Keep the existing
allow-ghsas documentation, and place the assertion alongside the allow-ghsas
configuration so future unpatched resolutions cannot be silently suppressed.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Duplicate comments:
In @.github/workflows/dependency-review.yml:
- Around line 68-111: Restore the executable dependency-review guard that
inspects website/pnpm-lock.yaml and fails unless brace-expansion resolves only
the audited 1.1.18 and 2.1.4 versions, applying the no-match handling from
commit 0a487b3. Keep the existing allow-ghsas documentation, and place the
assertion alongside the allow-ghsas configuration so future unpatched
resolutions cannot be silently suppressed.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 17f72619-a9b3-407d-a040-b762174f765b

📥 Commits

Reviewing files that changed from the base of the PR and between f4a4b2a and 18c5f9c.

📒 Files selected for processing (1)
  • .github/workflows/dependency-review.yml

@aknysh
Andriy Knysh (aknysh) merged commit b7559e1 into main Jul 31, 2026
85 checks passed
@aknysh
Andriy Knysh (aknysh) deleted the osterman/dag-concurrent-map-fix branch July 31, 2026 04:33
@atmos-pro

atmos-pro Bot commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@mergify mergify Bot removed the needs-cloudposse Needs Cloud Posse assistance label Jul 31, 2026
@github-actions

github-actions Bot commented Aug 1, 2026

Copy link
Copy Markdown

These changes were released in v1.225.0-rc.4.

This branch was successfully deployed

1 active (outdated) and 1 inactive deployments
screengrabs — 8b4265f2 Deployed Jul 31, 2026 by aknysh via build #885
preview — 0a487b3d Deployed Jul 30, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

patch A minor, backward compatible change size/m Medium size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants