Skip to content

fix: upgrade esbuild to 0.25.x to resolve GHSA-67mh-4wv8-2f99 (#378) #318

fix: upgrade esbuild to 0.25.x to resolve GHSA-67mh-4wv8-2f99 (#378)

fix: upgrade esbuild to 0.25.x to resolve GHSA-67mh-4wv8-2f99 (#378) #318

# Copyright (c) 2026, NVIDIA CORPORATION. All rights reserved.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
name: PR Merge Conflict Check
on:
push:
branches:
- main
workflow_dispatch: {}
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}
jobs:
conflicts:
name: Check Open PRs for Conflicts
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
timeout-minutes: 10
steps:
- name: Check Mergeable State
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
with:
script: |
const label = 'needs-rebase';
const { data: prs } = await github.rest.pulls.list({
owner: context.repo.owner,
repo: context.repo.repo,
state: 'open',
per_page: 100,
});
for (const pr of prs) {
// Fetch full PR to get mergeable state
const { data: full } = await github.rest.pulls.get({
owner: context.repo.owner,
repo: context.repo.repo,
pull_number: pr.number,
});
const hasLabel = full.labels.some(l => l.name === label);
if (full.mergeable === false) {
if (!hasLabel) {
await github.rest.issues.addLabels({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: pr.number,
labels: [label],
});
await github.rest.issues.createComment({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: pr.number,
body: `@${pr.user.login} this PR now has merge conflicts with \`main\`. Please rebase to resolve them.`,
});
}
} else if (full.mergeable === true && hasLabel) {
await github.rest.issues.removeLabel({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: pr.number,
name: label,
});
}
}