Skip to content

test: remove example-install-only - #1838

Open
MikeMcC399 wants to merge 4 commits into
cypress-io:masterfrom
MikeMcC399:remove/example-install-only
Open

test: remove example-install-only#1838
MikeMcC399 wants to merge 4 commits into
cypress-io:masterfrom
MikeMcC399:remove/example-install-only

Conversation

@MikeMcC399

@MikeMcC399 MikeMcC399 commented Jul 26, 2026

Copy link
Copy Markdown
Collaborator

Situation

The workflow example-install-only.yml pins a version of Cypress separately from the version defined in examples/install-only.

  • Renovate is unable to maintain the separate version in the workflow, resulting in manual instructions being written for

  • Code scanning typically flags pinning npm versions in workflows like this, since current updating utilities such as Renovate and Dependabot can't maintain them.

  • The workflow currently runs on ubuntu-24.04 using the default Node.js 22.23.1 version.

  • If it is upgraded to Node.js 24.x, it warns. And if it is upgraded to npm 12, it fails.

  • Attempting to make it compatible with npm 12, exposes other errors in the workflow, such as the npm install running in the wrong directory.

Assessment

  • Given heightened awareness of supply-chain vulnerabilities, it can no longer be considered as a good example and it is not fixable. npm does not allow picking only one dependency defined in package.json, although it can choose between dev and prod. Renovate can't keep it synced either.

  • The higher frequency of reported vulnerabilities in the npm ecosystem, compared to earlier, means that it is no longer viable to be manually updating dependencies. The main part of the work needs to be automated, and in this repo that means relying on Renovate.

Change

Remove the following, and all references to this example set:

Verification

Under Ubuntu 24.04.4 LTS, Node.js 24.18.0 LTS execute:

npm run update:cypress

Confirm that the script runs without error and no longer prompts to manually update example-install-only.yml.


Note

Low Risk
Documentation and example-only deletions with no changes to the GitHub Action runtime or production code.

Overview
Removes the install-only example and all documentation for installing only Cypress (without full npm ci) alongside cypress-io/github-action with install: false.

The .github/workflows/example-install-only.yml workflow and the entire examples/install-only tree (config, spec, lockfile, package.json) are deleted. README.md drops the TOC link and the "Install Cypress only" section under Custom install. docs/MAINTENANCE.md no longer documents manual Cypress version edits for that workflow. scripts/update-cypress-latest-npm.sh stops updating install-only, and scripts/update-cypress-latest.sh no longer prompts to edit the removed workflow after npm run update:cypress.

Reviewed by Cursor Bugbot for commit 4cf41c4. Bugbot is set up for automated code reviews on this repo. Configure here.

@cypress-app-bot

Copy link
Copy Markdown
Collaborator

@MikeMcC399 MikeMcC399 self-assigned this Jul 26, 2026
@MikeMcC399 MikeMcC399 added bug Something isn't working tests labels Jul 26, 2026
@MikeMcC399
MikeMcC399 marked this pull request as ready for review July 26, 2026 11:07
@MikeMcC399
MikeMcC399 requested a review from mschile July 27, 2026 06:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants