From ada92d22cbc31d3fee6d347d924119541fd086e6 Mon Sep 17 00:00:00 2001 From: Thomas Jung Date: Sun, 13 Sep 2026 13:24:10 -0400 Subject: [PATCH 1/2] fix(2245): declare gray-matter as runtime dependency srv/lib/skill-bundle.js (added in 43ead4c0, feat #2245) imports gray-matter at module top-level, but it was only a devDependency. CF installs prod-only, so tutorials-srv crash-loops at boot with ERR_MODULE_NOT_FOUND: Cannot find package 'gray-matter'. Move it to dependencies and mark its transitive subtree non-dev in the lockfile. --- package-lock.json | 12 +----------- package.json | 2 +- 2 files changed, 2 insertions(+), 12 deletions(-) diff --git a/package-lock.json b/package-lock.json index 3fb3f084f..0a7367329 100644 --- a/package-lock.json +++ b/package-lock.json @@ -42,6 +42,7 @@ "csv-stringify": "6.8.3", "ejs": "3.1.10", "exceljs": "4.4.0", + "gray-matter": "^4.0.3", "hdb": "^2.29.5", "jose": "6.2.12", "js-yaml": "5.4.1", @@ -73,7 +74,6 @@ "dompurify": "3.4.15", "esbuild": "0.28.2", "fundamental-styles": "^0.41.7", - "gray-matter": "^4.0.3", "happy-dom": "20.14.3", "playwright-core": "^1.61.1", "postcss": "^8.5.16", @@ -14762,7 +14762,6 @@ }, "node_modules/esprima": { "version": "4.0.1", - "dev": true, "license": "BSD-2-Clause", "bin": { "esparse": "bin/esparse.js", @@ -15081,7 +15080,6 @@ }, "node_modules/extend-shallow": { "version": "2.0.1", - "dev": true, "license": "MIT", "dependencies": { "is-extendable": "^0.1.0" @@ -15768,7 +15766,6 @@ }, "node_modules/gray-matter": { "version": "4.0.3", - "dev": true, "license": "MIT", "dependencies": { "js-yaml": "^3.13.1", @@ -15782,7 +15779,6 @@ }, "node_modules/gray-matter/node_modules/argparse": { "version": "1.0.10", - "dev": true, "license": "MIT", "dependencies": { "sprintf-js": "~1.0.2" @@ -15790,7 +15786,6 @@ }, "node_modules/gray-matter/node_modules/js-yaml": { "version": "3.14.2", - "dev": true, "license": "MIT", "dependencies": { "argparse": "^1.0.7", @@ -16439,7 +16434,6 @@ }, "node_modules/is-extendable": { "version": "0.1.1", - "dev": true, "license": "MIT", "engines": { "node": ">=0.10.0" @@ -16935,7 +16929,6 @@ }, "node_modules/kind-of": { "version": "6.0.3", - "dev": true, "license": "MIT", "engines": { "node": ">=0.10.0" @@ -20075,7 +20068,6 @@ }, "node_modules/section-matter": { "version": "1.0.0", - "dev": true, "license": "MIT", "dependencies": { "extend-shallow": "^2.0.1", @@ -20539,7 +20531,6 @@ }, "node_modules/sprintf-js": { "version": "1.0.3", - "dev": true, "license": "BSD-3-Clause" }, "node_modules/stack-trace": { @@ -20760,7 +20751,6 @@ }, "node_modules/strip-bom-string": { "version": "1.0.0", - "dev": true, "license": "MIT", "engines": { "node": ">=0.10.0" diff --git a/package.json b/package.json index 02d6c41d4..67c352164 100644 --- a/package.json +++ b/package.json @@ -155,7 +155,6 @@ "dompurify": "3.4.15", "esbuild": "0.28.2", "fundamental-styles": "^0.41.7", - "gray-matter": "^4.0.3", "happy-dom": "20.14.3", "playwright-core": "^1.61.1", "postcss": "^8.5.16", @@ -216,6 +215,7 @@ "csv-stringify": "6.8.3", "ejs": "3.1.10", "exceljs": "4.4.0", + "gray-matter": "^4.0.3", "hdb": "^2.29.5", "jose": "6.2.12", "js-yaml": "5.4.1", From 5367486caaeba8f692e91ceef731b986442c1083 Mon Sep 17 00:00:00 2001 From: Thomas Jung Date: Sun, 13 Sep 2026 13:29:59 -0400 Subject: [PATCH 2/2] ci(guards): add packages: read so npm ci can read @sap-tutorials pkg The static-guards job had only `contents: read`, unlike every other npm-ci workflow (deploy, cds-build-staging, schema-drift, etc. all declare `packages: read`). The npm cache masked it: on a cache hit the private @sap-tutorials/cds-alert-notification tarball is already local, so no registry read is needed. Any PR that changes package-lock.json busts the cache key, forcing npm ci to re-download it, and the fallback GITHUB_TOKEN 403s without packages: read. Align guards with siblings. --- .github/workflows/static-guards.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/static-guards.yml b/.github/workflows/static-guards.yml index 864e6d957..7a1c2b55a 100644 --- a/.github/workflows/static-guards.yml +++ b/.github/workflows/static-guards.yml @@ -18,6 +18,7 @@ jobs: runs-on: ubuntu-latest permissions: contents: read + packages: read steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4