Skip to content

ops(josh-sync): Opt in to 6 additional lints - #85

Merged
ubiratansoares merged 6 commits into
rust-lang:mainfrom
hashcatHitman:josh-sync
Oct 6, 2026
Merged

ubiratansoares merged 6 commits into
rust-lang:mainfrom
hashcatHitman:josh-sync

Conversation

@hashcatHitman

@hashcatHitman hashcatHitman commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

This PR opts rust-lang/josh-sync into 6 lints it was already passing without any fixes:

Opened in response to #83 (review), which I hope I didn't misunderstand.

A note on dependabot-cooldown:

It also passes dependabot-cooldown. This lint is specific to Dependabot. rust-lang/josh-sync passes because it is using Renovate, not Dependabot. The Renovate config uses the t-infra maintained "actions" config, which intentionally does not have a cooldown. So there may be some semantic reason to prefer to not opt-in, even though it passes. It seems like it's best to lave it disabled for now.

Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>
Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>

@ubiratansoares ubiratansoares left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @hashcatHitman !

Regarding the Dependabot cooldown : if you don't use Dependabot and don't have plans to, I think that keeping related audits disabled is the correct approach, ie, one should opt-in if one wants to get a valid signal out of these audits.

Perhaps we could make this clear in our policy file (e.g. with comments). Meanwhile, let me know if that makes sense to you

@hashcatHitman

Copy link
Copy Markdown
Member Author

Regarding the Dependabot cooldown : if you don't use Dependabot and don't have plans to, I think that keeping related audits disabled is the correct approach, ie, one should opt-in if one wants to get a valid signal out of these audits.

Perhaps we could make this clear in our policy file (e.g. with comments). Meanwhile, let me know if that makes sense to you

I can't say what the plans are in josh-sync, but I think they will probably stick with Renovate. So I can remove that commit, sure.

Personally, I see it one of two ways:

  • The lint doesn't fire, so enabling it doesn't change anything unless you use Dependabot later on
  • The lint doesn't fire, so enabling it may lead to incorrectly assuming it also applies to Renovate

To be clear, I'm not anyone with any particular authority over josh-sync. I'm just trying to fix as many issues as I can across all rust-lang public repositories with crabwatch enabled. (See: #t-infra > questions about helping with crabwatch/zizmor)

Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>
Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>
Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>
Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>
@hashcatHitman hashcatHitman changed the title ops(josh-sync): Opt in to 7 additional lints ops(josh-sync): Opt in to 6 additional lints Oct 6, 2026
@ubiratansoares
ubiratansoares merged commit 5ae1f52 into rust-lang:main Oct 6, 2026
5 checks passed
@hashcatHitman
hashcatHitman deleted the josh-sync branch October 6, 2026 21:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants