Skip to content

Bring the Renovate-applied dependencies and security labels under the shared taxonomy - #27

Merged
bryanbeverly merged 4 commits into
mainfrom
bryanbeverly/cursor/sync-dependencies-label
Sep 14, 2026
Merged

bryanbeverly merged 4 commits into
mainfrom
bryanbeverly/cursor/sync-dependencies-label

Conversation

@bryanbeverly

@bryanbeverly bryanbeverly commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Neither dependencies nor security was listed in labels.yml, so the sync never touched them and each repo kept whatever the tool that first created the label happened to set. Both come from the shared Renovate preset (renovate-config.json), not the pr-labeler.

  • dependencies exists on all 12 repos but in two colors: 0366d6 with a description on 7, GitHub's default ededed with none on 4. The split is whether Dependabot ran there before the Renovate migration.
  • security exists on only 7. The preset applies it from vulnerabilityAlerts, so GitHub creates it on a repo's first vulnerability PR — and the other 4 have no manifest in an ecosystem the advisory database covers, so they never get one.

Both entries take their color and description from dependabot-core's labeler.rb, where these labels originate. The gray in this org was never a choice; it is what GitHub assigns when Renovate applies a label that does not exist yet.

Next sync recolors dependencies on 4 repos, recolors security on 7, and creates security on 4. Still additive — nothing is deleted.


Note

Low Risk
Config-only change to label metadata; no application or security logic is modified.

Overview
Adds dependencies and security to the org’s shared labels.yml so the label-sync workflow can apply consistent colors and descriptions on the next run.

These labels are already applied by Renovate/Dependabot on many repos but were missing from the taxonomy, so some repositories kept GitHub’s default gray or inconsistent styling. The sync remains additive—it updates or creates these two labels and does not remove anything else.

Reviewed by Cursor Bugbot for commit c898bed. Bugbot is set up for automated code reviews on this repo. Configure here.

The dependencies label was never in labels.yml, so the sync left it alone
and each repo kept whatever color first created it. Of the 12 repos calling
label-sync-reusable.yml, 7 carry Dependabot's 0366d6 with its default
description and 4 carry GitHub's default ededed with none -- the split
tracks whether Dependabot ever ran there, not any current tooling, since
all of them are on Renovate now.

Adopt the 0366d6 that the majority already shows. The next scheduled sync
recolors the remaining 4 via gh label create --force.

Co-authored-by: Cursor <cursoragent@cursor.com>
@bryanbeverly
bryanbeverly requested a review from a team September 14, 2026 06:24
Also applied by the Renovate preset, but only on vulnerability-remediation
PRs via the vulnerabilityAlerts block, so GitHub creates it the first time
one lands. Seven repos have it (gray, no description); the four without it
-- infrastructure, helm-charts, oink, thog-deployments -- have no manifest
in an ecosystem the advisory database covers, so they get no alerts and
have never had a security PR to create it.

Keep ededed so the seven repos that have it don't change, and add the
description they're all missing. Listing it here creates it everywhere up
front rather than having it appear mid-incident.

Co-authored-by: Cursor <cursoragent@cursor.com>
@bryanbeverly bryanbeverly changed the title Bring the dependencies label under the shared taxonomy Bring the Renovate-applied dependencies and security labels under the shared taxonomy Sep 14, 2026
bryanbeverly and others added 2 commits September 13, 2026 23:38
Both entries now take their color and description verbatim from
dependabot-core's labeler (create_github_security_label, ee0701), the same
source the dependencies entry already matched. The gray on the seven repos
that have the label is not a choice anyone made; it is what GitHub assigns
when Renovate applies a label that does not exist yet.

Recolors the label on all seven. Deliberately close to risk/high's cf222e
but they never appear together: risk/* is Bugbot scoring a human PR,
security lands only on Renovate vulnerability PRs.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@bryanbeverly
bryanbeverly merged commit 1974f2b into main Sep 14, 2026
3 checks passed
@bryanbeverly
bryanbeverly deleted the bryanbeverly/cursor/sync-dependencies-label branch September 14, 2026 19:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants