Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Backpatch override cleanup — GitHub Action

Reports which overrides, resolutions, and pnpm.overrides entries in your package.json can now be removed, because the parent dependency has since caught up and pulls in a safe version on its own.

Security fixes leave overrides behind. Nothing in a normal toolchain tells you when one has stopped doing work — npm audit stays quiet precisely because the override is there. This Action asks that question on a schedule, or on the dependency-bump PRs that are most likely to have made an override redundant.

Usage

name: Override cleanupon:
schedule:
- cron: '0 9 * * 1'# Mondays, 09:00 UTCworkflow_dispatch:
jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}

The result lands in the job summary. Nothing fails by default — see fail-on to change that.

On dependency-bump PRs

The highest-value trigger. A Renovate or Dependabot PR moves a parent dependency, which is exactly the event that can make an override redundant:

on:
pull_request:
paths: ['**/package.json', '**/package-lock.json']jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}lockfile: package-lock.json

Passing the lockfile makes the analysis more precise: it reflects what is actually installed rather than what the ranges allow.

Acting on the result

removable-count and results are outputs, so a later step can open an issue, comment on the PR, or gate a merge:

 - uses: cridertechnologies/backpatch-action@v1id: backpatchwith:
api-key: ${{ secrets.BACKPATCH_API_KEY }}
- if: steps.backpatch.outputs.removable-count != '0'run: | echo "${{ steps.backpatch.outputs.removable-count }} override(s) can go." echo '${{ steps.backpatch.outputs.results }}' | jq '.[] | select(.status=="SafeToRemove")'

Inputs

InputDefaultDescription
api-key(required)Your Backpatch API key. Every request needs one — start a 14-day trial. Pass it from a secret, never inline.
working-directory.Directory the other paths resolve against. Use it for a monorepo package.
package-jsonpackage.jsonManifest to analyze, relative to working-directory.
lockfile(none)Optional package-lock.json or yarn.lock. Improves precision.
allow-major-bumpfalseTreat overrides that only clear behind a breaking major parent upgrade as removable. Off by default.
fail-onnevernever reports only. removable fails the job when any override can be removed.
summarytrueWrite the results table to the job summary.
api-urlhttps://api.backpatch.devOverride only when self-hosting the API.

Outputs

OutputDescription
removable-countOverrides reported SafeToRemove.
needs-major-countOverrides removable only behind a major parent upgrade.
still-needed-countOverrides still doing real work.
total-countOverride entries analyzed.
resultsThe full analysis as a JSON array.

Statuses

StatusMeaning
SafeToRemoveA parent version within reach already pulls in a safe transitive version.
NeedsMajorUpgradeRemovable, but only behind a breaking major upgrade of a parent. Deliberately notSafeToRemove — treating it as one produces a PR that deletes an override and breaks the build.
StillNeededNo parent has caught up. Keep the override.
UnknownThe registry or advisory lookup could not settle it.

Before you delete anything

The analysis reads declared ranges and registry metadata. It tells you a parent should resolve safely — your lockfile and test suite are what confirm it did. Delete the entries, re-resolve the lockfile from scratch (rm -rf node_modules package-lock.json && npm install), and run your tests before merging. Updating in place can leave the old resolution pinned, which makes a still-needed override look removable.

Notes

  • What is sent: your package.json, and the lockfile only if you pass one. No repository access, no credentials, no source. The API does not retain the file beyond the request.
  • Rate limits are per key. CI is bursty and plan limits are per minute, so a busy org on one shared key can rate-limit itself. The Action surfaces a 429 with that explanation rather than a bare failure.
  • Requires a key. There is no anonymous tier. A missing or revoked key fails the step with an actionable message.
  • Self-hosting. If sending a manifest off-network is not an option, point api-url at your own deployment of the Backpatch API.

Versioning

Use the floating major tag — @v1 — to pick up fixes. Pin a full tag or SHA if you need byte-for-byte reproducibility.

License

MIT. See LICENSE

About

The official action for Backpatch

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Backpatch override cleanup — GitHub Action

Reports which overrides, resolutions, and pnpm.overrides entries in your package.json can now be removed, because the parent dependency has since caught up and pulls in a safe version on its own.

Security fixes leave overrides behind. Nothing in a normal toolchain tells you when one has stopped doing work — npm audit stays quiet precisely because the override is there. This Action asks that question on a schedule, or on the dependency-bump PRs that are most likely to have made an override redundant.

Usage

name: Override cleanupon:
schedule:
- cron: '0 9 * * 1'# Mondays, 09:00 UTCworkflow_dispatch:
jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}

The result lands in the job summary. Nothing fails by default — see fail-on to change that.

On dependency-bump PRs

The highest-value trigger. A Renovate or Dependabot PR moves a parent dependency, which is exactly the event that can make an override redundant:

on:
pull_request:
paths: ['**/package.json', '**/package-lock.json']jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}lockfile: package-lock.json

Passing the lockfile makes the analysis more precise: it reflects what is actually installed rather than what the ranges allow.

Acting on the result

removable-count and results are outputs, so a later step can open an issue, comment on the PR, or gate a merge:

 - uses: cridertechnologies/backpatch-action@v1id: backpatchwith:
api-key: ${{ secrets.BACKPATCH_API_KEY }}
- if: steps.backpatch.outputs.removable-count != '0'run: | echo "${{ steps.backpatch.outputs.removable-count }} override(s) can go." echo '${{ steps.backpatch.outputs.results }}' | jq '.[] | select(.status=="SafeToRemove")'

Inputs

InputDefaultDescription
api-key(required)Your Backpatch API key. Every request needs one — start a 14-day trial. Pass it from a secret, never inline.
working-directory.Directory the other paths resolve against. Use it for a monorepo package.
package-jsonpackage.jsonManifest to analyze, relative to working-directory.
lockfile(none)Optional package-lock.json or yarn.lock. Improves precision.
allow-major-bumpfalseTreat overrides that only clear behind a breaking major parent upgrade as removable. Off by default.
fail-onnevernever reports only. removable fails the job when any override can be removed.
summarytrueWrite the results table to the job summary.
api-urlhttps://api.backpatch.devOverride only when self-hosting the API.

Outputs

OutputDescription
removable-countOverrides reported SafeToRemove.
needs-major-countOverrides removable only behind a major parent upgrade.
still-needed-countOverrides still doing real work.
total-countOverride entries analyzed.
resultsThe full analysis as a JSON array.

Statuses

StatusMeaning
SafeToRemoveA parent version within reach already pulls in a safe transitive version.
NeedsMajorUpgradeRemovable, but only behind a breaking major upgrade of a parent. Deliberately notSafeToRemove — treating it as one produces a PR that deletes an override and breaks the build.
StillNeededNo parent has caught up. Keep the override.
UnknownThe registry or advisory lookup could not settle it.

Before you delete anything

The analysis reads declared ranges and registry metadata. It tells you a parent should resolve safely — your lockfile and test suite are what confirm it did. Delete the entries, re-resolve the lockfile from scratch (rm -rf node_modules package-lock.json && npm install), and run your tests before merging. Updating in place can leave the old resolution pinned, which makes a still-needed override look removable.

Notes

  • What is sent: your package.json, and the lockfile only if you pass one. No repository access, no credentials, no source. The API does not retain the file beyond the request.
  • Rate limits are per key. CI is bursty and plan limits are per minute, so a busy org on one shared key can rate-limit itself. The Action surfaces a 429 with that explanation rather than a bare failure.
  • Requires a key. There is no anonymous tier. A missing or revoked key fails the step with an actionable message.
  • Self-hosting. If sending a manifest off-network is not an option, point api-url at your own deployment of the Backpatch API.

Versioning

Use the floating major tag — @v1 — to pick up fixes. Pin a full tag or SHA if you need byte-for-byte reproducibility.

License

MIT. See LICENSE

About

The official action for Backpatch

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Backpatch override cleanup — GitHub Action

Reports which overrides, resolutions, and pnpm.overrides entries in your package.json can now be removed, because the parent dependency has since caught up and pulls in a safe version on its own.

Security fixes leave overrides behind. Nothing in a normal toolchain tells you when one has stopped doing work — npm audit stays quiet precisely because the override is there. This Action asks that question on a schedule, or on the dependency-bump PRs that are most likely to have made an override redundant.

Usage

name: Override cleanupon:
schedule:
- cron: '0 9 * * 1'# Mondays, 09:00 UTCworkflow_dispatch:
jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}

The result lands in the job summary. Nothing fails by default — see fail-on to change that.

On dependency-bump PRs

The highest-value trigger. A Renovate or Dependabot PR moves a parent dependency, which is exactly the event that can make an override redundant:

on:
pull_request:
paths: ['**/package.json', '**/package-lock.json']jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}lockfile: package-lock.json

Passing the lockfile makes the analysis more precise: it reflects what is actually installed rather than what the ranges allow.

Acting on the result

removable-count and results are outputs, so a later step can open an issue, comment on the PR, or gate a merge:

 - uses: cridertechnologies/backpatch-action@v1id: backpatchwith:
api-key: ${{ secrets.BACKPATCH_API_KEY }}
- if: steps.backpatch.outputs.removable-count != '0'run: | echo "${{ steps.backpatch.outputs.removable-count }} override(s) can go." echo '${{ steps.backpatch.outputs.results }}' | jq '.[] | select(.status=="SafeToRemove")'

Inputs

InputDefaultDescription
api-key(required)Your Backpatch API key. Every request needs one — start a 14-day trial. Pass it from a secret, never inline.
working-directory.Directory the other paths resolve against. Use it for a monorepo package.
package-jsonpackage.jsonManifest to analyze, relative to working-directory.
lockfile(none)Optional package-lock.json or yarn.lock. Improves precision.
allow-major-bumpfalseTreat overrides that only clear behind a breaking major parent upgrade as removable. Off by default.
fail-onnevernever reports only. removable fails the job when any override can be removed.
summarytrueWrite the results table to the job summary.
api-urlhttps://api.backpatch.devOverride only when self-hosting the API.

Outputs

OutputDescription
removable-countOverrides reported SafeToRemove.
needs-major-countOverrides removable only behind a major parent upgrade.
still-needed-countOverrides still doing real work.
total-countOverride entries analyzed.
resultsThe full analysis as a JSON array.

Statuses

StatusMeaning
SafeToRemoveA parent version within reach already pulls in a safe transitive version.
NeedsMajorUpgradeRemovable, but only behind a breaking major upgrade of a parent. Deliberately notSafeToRemove — treating it as one produces a PR that deletes an override and breaks the build.
StillNeededNo parent has caught up. Keep the override.
UnknownThe registry or advisory lookup could not settle it.

Before you delete anything

The analysis reads declared ranges and registry metadata. It tells you a parent should resolve safely — your lockfile and test suite are what confirm it did. Delete the entries, re-resolve the lockfile from scratch (rm -rf node_modules package-lock.json && npm install), and run your tests before merging. Updating in place can leave the old resolution pinned, which makes a still-needed override look removable.

Notes

  • What is sent: your package.json, and the lockfile only if you pass one. No repository access, no credentials, no source. The API does not retain the file beyond the request.
  • Rate limits are per key. CI is bursty and plan limits are per minute, so a busy org on one shared key can rate-limit itself. The Action surfaces a 429 with that explanation rather than a bare failure.
  • Requires a key. There is no anonymous tier. A missing or revoked key fails the step with an actionable message.
  • Self-hosting. If sending a manifest off-network is not an option, point api-url at your own deployment of the Backpatch API.

Versioning

Use the floating major tag — @v1 — to pick up fixes. Pin a full tag or SHA if you need byte-for-byte reproducibility.

License

MIT. See LICENSE

About

The official action for Backpatch

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Backpatch override cleanup — GitHub Action

Reports which overrides, resolutions, and pnpm.overrides entries in your package.json can now be removed, because the parent dependency has since caught up and pulls in a safe version on its own.

Security fixes leave overrides behind. Nothing in a normal toolchain tells you when one has stopped doing work — npm audit stays quiet precisely because the override is there. This Action asks that question on a schedule, or on the dependency-bump PRs that are most likely to have made an override redundant.

Usage

name: Override cleanupon:
schedule:
- cron: '0 9 * * 1'# Mondays, 09:00 UTCworkflow_dispatch:
jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}

The result lands in the job summary. Nothing fails by default — see fail-on to change that.

On dependency-bump PRs

The highest-value trigger. A Renovate or Dependabot PR moves a parent dependency, which is exactly the event that can make an override redundant:

on:
pull_request:
paths: ['**/package.json', '**/package-lock.json']jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}lockfile: package-lock.json

Passing the lockfile makes the analysis more precise: it reflects what is actually installed rather than what the ranges allow.

Acting on the result

removable-count and results are outputs, so a later step can open an issue, comment on the PR, or gate a merge:

 - uses: cridertechnologies/backpatch-action@v1id: backpatchwith:
api-key: ${{ secrets.BACKPATCH_API_KEY }}
- if: steps.backpatch.outputs.removable-count != '0'run: | echo "${{ steps.backpatch.outputs.removable-count }} override(s) can go." echo '${{ steps.backpatch.outputs.results }}' | jq '.[] | select(.status=="SafeToRemove")'

Inputs

InputDefaultDescription
api-key(required)Your Backpatch API key. Every request needs one — start a 14-day trial. Pass it from a secret, never inline.
working-directory.Directory the other paths resolve against. Use it for a monorepo package.
package-jsonpackage.jsonManifest to analyze, relative to working-directory.
lockfile(none)Optional package-lock.json or yarn.lock. Improves precision.
allow-major-bumpfalseTreat overrides that only clear behind a breaking major parent upgrade as removable. Off by default.
fail-onnevernever reports only. removable fails the job when any override can be removed.
summarytrueWrite the results table to the job summary.
api-urlhttps://api.backpatch.devOverride only when self-hosting the API.

Outputs

OutputDescription
removable-countOverrides reported SafeToRemove.
needs-major-countOverrides removable only behind a major parent upgrade.
still-needed-countOverrides still doing real work.
total-countOverride entries analyzed.
resultsThe full analysis as a JSON array.

Statuses

StatusMeaning
SafeToRemoveA parent version within reach already pulls in a safe transitive version.
NeedsMajorUpgradeRemovable, but only behind a breaking major upgrade of a parent. Deliberately notSafeToRemove — treating it as one produces a PR that deletes an override and breaks the build.
StillNeededNo parent has caught up. Keep the override.
UnknownThe registry or advisory lookup could not settle it.

Before you delete anything

The analysis reads declared ranges and registry metadata. It tells you a parent should resolve safely — your lockfile and test suite are what confirm it did. Delete the entries, re-resolve the lockfile from scratch (rm -rf node_modules package-lock.json && npm install), and run your tests before merging. Updating in place can leave the old resolution pinned, which makes a still-needed override look removable.

Notes

  • What is sent: your package.json, and the lockfile only if you pass one. No repository access, no credentials, no source. The API does not retain the file beyond the request.
  • Rate limits are per key. CI is bursty and plan limits are per minute, so a busy org on one shared key can rate-limit itself. The Action surfaces a 429 with that explanation rather than a bare failure.
  • Requires a key. There is no anonymous tier. A missing or revoked key fails the step with an actionable message.
  • Self-hosting. If sending a manifest off-network is not an option, point api-url at your own deployment of the Backpatch API.

Versioning

Use the floating major tag — @v1 — to pick up fixes. Pin a full tag or SHA if you need byte-for-byte reproducibility.

License

MIT. See LICENSE

About

The official action for Backpatch

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Backpatch override cleanup — GitHub Action

Reports which overrides, resolutions, and pnpm.overrides entries in your package.json can now be removed, because the parent dependency has since caught up and pulls in a safe version on its own.

Security fixes leave overrides behind. Nothing in a normal toolchain tells you when one has stopped doing work — npm audit stays quiet precisely because the override is there. This Action asks that question on a schedule, or on the dependency-bump PRs that are most likely to have made an override redundant.

Usage

name: Override cleanupon:
schedule:
- cron: '0 9 * * 1'# Mondays, 09:00 UTCworkflow_dispatch:
jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}

The result lands in the job summary. Nothing fails by default — see fail-on to change that.

On dependency-bump PRs

The highest-value trigger. A Renovate or Dependabot PR moves a parent dependency, which is exactly the event that can make an override redundant:

on:
pull_request:
paths: ['**/package.json', '**/package-lock.json']jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}lockfile: package-lock.json

Passing the lockfile makes the analysis more precise: it reflects what is actually installed rather than what the ranges allow.

Acting on the result

removable-count and results are outputs, so a later step can open an issue, comment on the PR, or gate a merge:

 - uses: cridertechnologies/backpatch-action@v1id: backpatchwith:
api-key: ${{ secrets.BACKPATCH_API_KEY }}
- if: steps.backpatch.outputs.removable-count != '0'run: | echo "${{ steps.backpatch.outputs.removable-count }} override(s) can go." echo '${{ steps.backpatch.outputs.results }}' | jq '.[] | select(.status=="SafeToRemove")'

Inputs

InputDefaultDescription
api-key(required)Your Backpatch API key. Every request needs one — start a 14-day trial. Pass it from a secret, never inline.
working-directory.Directory the other paths resolve against. Use it for a monorepo package.
package-jsonpackage.jsonManifest to analyze, relative to working-directory.
lockfile(none)Optional package-lock.json or yarn.lock. Improves precision.
allow-major-bumpfalseTreat overrides that only clear behind a breaking major parent upgrade as removable. Off by default.
fail-onnevernever reports only. removable fails the job when any override can be removed.
summarytrueWrite the results table to the job summary.
api-urlhttps://api.backpatch.devOverride only when self-hosting the API.

Outputs

OutputDescription
removable-countOverrides reported SafeToRemove.
needs-major-countOverrides removable only behind a major parent upgrade.
still-needed-countOverrides still doing real work.
total-countOverride entries analyzed.
resultsThe full analysis as a JSON array.

Statuses

StatusMeaning
SafeToRemoveA parent version within reach already pulls in a safe transitive version.
NeedsMajorUpgradeRemovable, but only behind a breaking major upgrade of a parent. Deliberately notSafeToRemove — treating it as one produces a PR that deletes an override and breaks the build.
StillNeededNo parent has caught up. Keep the override.
UnknownThe registry or advisory lookup could not settle it.

Before you delete anything

The analysis reads declared ranges and registry metadata. It tells you a parent should resolve safely — your lockfile and test suite are what confirm it did. Delete the entries, re-resolve the lockfile from scratch (rm -rf node_modules package-lock.json && npm install), and run your tests before merging. Updating in place can leave the old resolution pinned, which makes a still-needed override look removable.

Notes

  • What is sent: your package.json, and the lockfile only if you pass one. No repository access, no credentials, no source. The API does not retain the file beyond the request.
  • Rate limits are per key. CI is bursty and plan limits are per minute, so a busy org on one shared key can rate-limit itself. The Action surfaces a 429 with that explanation rather than a bare failure.
  • Requires a key. There is no anonymous tier. A missing or revoked key fails the step with an actionable message.
  • Self-hosting. If sending a manifest off-network is not an option, point api-url at your own deployment of the Backpatch API.

Versioning

Use the floating major tag — @v1 — to pick up fixes. Pin a full tag or SHA if you need byte-for-byte reproducibility.

License

MIT. See LICENSE

About

The official action for Backpatch

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Backpatch override cleanup — GitHub Action

Reports which overrides, resolutions, and pnpm.overrides entries in your package.json can now be removed, because the parent dependency has since caught up and pulls in a safe version on its own.

Security fixes leave overrides behind. Nothing in a normal toolchain tells you when one has stopped doing work — npm audit stays quiet precisely because the override is there. This Action asks that question on a schedule, or on the dependency-bump PRs that are most likely to have made an override redundant.

Usage

name: Override cleanupon:
schedule:
- cron: '0 9 * * 1'# Mondays, 09:00 UTCworkflow_dispatch:
jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}

The result lands in the job summary. Nothing fails by default — see fail-on to change that.

On dependency-bump PRs

The highest-value trigger. A Renovate or Dependabot PR moves a parent dependency, which is exactly the event that can make an override redundant:

on:
pull_request:
paths: ['**/package.json', '**/package-lock.json']jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}lockfile: package-lock.json

Passing the lockfile makes the analysis more precise: it reflects what is actually installed rather than what the ranges allow.

Acting on the result

removable-count and results are outputs, so a later step can open an issue, comment on the PR, or gate a merge:

 - uses: cridertechnologies/backpatch-action@v1id: backpatchwith:
api-key: ${{ secrets.BACKPATCH_API_KEY }}
- if: steps.backpatch.outputs.removable-count != '0'run: | echo "${{ steps.backpatch.outputs.removable-count }} override(s) can go." echo '${{ steps.backpatch.outputs.results }}' | jq '.[] | select(.status=="SafeToRemove")'

Inputs

InputDefaultDescription
api-key(required)Your Backpatch API key. Every request needs one — start a 14-day trial. Pass it from a secret, never inline.
working-directory.Directory the other paths resolve against. Use it for a monorepo package.
package-jsonpackage.jsonManifest to analyze, relative to working-directory.
lockfile(none)Optional package-lock.json or yarn.lock. Improves precision.
allow-major-bumpfalseTreat overrides that only clear behind a breaking major parent upgrade as removable. Off by default.
fail-onnevernever reports only. removable fails the job when any override can be removed.
summarytrueWrite the results table to the job summary.
api-urlhttps://api.backpatch.devOverride only when self-hosting the API.

Outputs

OutputDescription
removable-countOverrides reported SafeToRemove.
needs-major-countOverrides removable only behind a major parent upgrade.
still-needed-countOverrides still doing real work.
total-countOverride entries analyzed.
resultsThe full analysis as a JSON array.

Statuses

StatusMeaning
SafeToRemoveA parent version within reach already pulls in a safe transitive version.
NeedsMajorUpgradeRemovable, but only behind a breaking major upgrade of a parent. Deliberately notSafeToRemove — treating it as one produces a PR that deletes an override and breaks the build.
StillNeededNo parent has caught up. Keep the override.
UnknownThe registry or advisory lookup could not settle it.

Before you delete anything

The analysis reads declared ranges and registry metadata. It tells you a parent should resolve safely — your lockfile and test suite are what confirm it did. Delete the entries, re-resolve the lockfile from scratch (rm -rf node_modules package-lock.json && npm install), and run your tests before merging. Updating in place can leave the old resolution pinned, which makes a still-needed override look removable.

Notes

  • What is sent: your package.json, and the lockfile only if you pass one. No repository access, no credentials, no source. The API does not retain the file beyond the request.
  • Rate limits are per key. CI is bursty and plan limits are per minute, so a busy org on one shared key can rate-limit itself. The Action surfaces a 429 with that explanation rather than a bare failure.
  • Requires a key. There is no anonymous tier. A missing or revoked key fails the step with an actionable message.
  • Self-hosting. If sending a manifest off-network is not an option, point api-url at your own deployment of the Backpatch API.

Versioning

Use the floating major tag — @v1 — to pick up fixes. Pin a full tag or SHA if you need byte-for-byte reproducibility.

License

MIT. See LICENSE

About

The official action for Backpatch

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Backpatch override cleanup — GitHub Action

Reports which overrides, resolutions, and pnpm.overrides entries in your package.json can now be removed, because the parent dependency has since caught up and pulls in a safe version on its own.

Security fixes leave overrides behind. Nothing in a normal toolchain tells you when one has stopped doing work — npm audit stays quiet precisely because the override is there. This Action asks that question on a schedule, or on the dependency-bump PRs that are most likely to have made an override redundant.

Usage

name: Override cleanupon:
schedule:
- cron: '0 9 * * 1'# Mondays, 09:00 UTCworkflow_dispatch:
jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}

The result lands in the job summary. Nothing fails by default — see fail-on to change that.

On dependency-bump PRs

The highest-value trigger. A Renovate or Dependabot PR moves a parent dependency, which is exactly the event that can make an override redundant:

on:
pull_request:
paths: ['**/package.json', '**/package-lock.json']jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}lockfile: package-lock.json

Passing the lockfile makes the analysis more precise: it reflects what is actually installed rather than what the ranges allow.

Acting on the result

removable-count and results are outputs, so a later step can open an issue, comment on the PR, or gate a merge:

 - uses: cridertechnologies/backpatch-action@v1id: backpatchwith:
api-key: ${{ secrets.BACKPATCH_API_KEY }}
- if: steps.backpatch.outputs.removable-count != '0'run: | echo "${{ steps.backpatch.outputs.removable-count }} override(s) can go." echo '${{ steps.backpatch.outputs.results }}' | jq '.[] | select(.status=="SafeToRemove")'

Inputs

InputDefaultDescription
api-key(required)Your Backpatch API key. Every request needs one — start a 14-day trial. Pass it from a secret, never inline.
working-directory.Directory the other paths resolve against. Use it for a monorepo package.
package-jsonpackage.jsonManifest to analyze, relative to working-directory.
lockfile(none)Optional package-lock.json or yarn.lock. Improves precision.
allow-major-bumpfalseTreat overrides that only clear behind a breaking major parent upgrade as removable. Off by default.
fail-onnevernever reports only. removable fails the job when any override can be removed.
summarytrueWrite the results table to the job summary.
api-urlhttps://api.backpatch.devOverride only when self-hosting the API.

Outputs

OutputDescription
removable-countOverrides reported SafeToRemove.
needs-major-countOverrides removable only behind a major parent upgrade.
still-needed-countOverrides still doing real work.
total-countOverride entries analyzed.
resultsThe full analysis as a JSON array.

Statuses

StatusMeaning
SafeToRemoveA parent version within reach already pulls in a safe transitive version.
NeedsMajorUpgradeRemovable, but only behind a breaking major upgrade of a parent. Deliberately notSafeToRemove — treating it as one produces a PR that deletes an override and breaks the build.
StillNeededNo parent has caught up. Keep the override.
UnknownThe registry or advisory lookup could not settle it.

Before you delete anything

The analysis reads declared ranges and registry metadata. It tells you a parent should resolve safely — your lockfile and test suite are what confirm it did. Delete the entries, re-resolve the lockfile from scratch (rm -rf node_modules package-lock.json && npm install), and run your tests before merging. Updating in place can leave the old resolution pinned, which makes a still-needed override look removable.

Notes

  • What is sent: your package.json, and the lockfile only if you pass one. No repository access, no credentials, no source. The API does not retain the file beyond the request.
  • Rate limits are per key. CI is bursty and plan limits are per minute, so a busy org on one shared key can rate-limit itself. The Action surfaces a 429 with that explanation rather than a bare failure.
  • Requires a key. There is no anonymous tier. A missing or revoked key fails the step with an actionable message.
  • Self-hosting. If sending a manifest off-network is not an option, point api-url at your own deployment of the Backpatch API.

Versioning

Use the floating major tag — @v1 — to pick up fixes. Pin a full tag or SHA if you need byte-for-byte reproducibility.

License

MIT. See LICENSE

About

The official action for Backpatch

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Backpatch override cleanup — GitHub Action

Reports which overrides, resolutions, and pnpm.overrides entries in your package.json can now be removed, because the parent dependency has since caught up and pulls in a safe version on its own.

Security fixes leave overrides behind. Nothing in a normal toolchain tells you when one has stopped doing work — npm audit stays quiet precisely because the override is there. This Action asks that question on a schedule, or on the dependency-bump PRs that are most likely to have made an override redundant.

Usage

name: Override cleanupon:
schedule:
- cron: '0 9 * * 1'# Mondays, 09:00 UTCworkflow_dispatch:
jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}

The result lands in the job summary. Nothing fails by default — see fail-on to change that.

On dependency-bump PRs

The highest-value trigger. A Renovate or Dependabot PR moves a parent dependency, which is exactly the event that can make an override redundant:

on:
pull_request:
paths: ['**/package.json', '**/package-lock.json']jobs:
backpatch:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: cridertechnologies/backpatch-action@v1with:
api-key: ${{ secrets.BACKPATCH_API_KEY }}lockfile: package-lock.json

Passing the lockfile makes the analysis more precise: it reflects what is actually installed rather than what the ranges allow.

Acting on the result

removable-count and results are outputs, so a later step can open an issue, comment on the PR, or gate a merge:

 - uses: cridertechnologies/backpatch-action@v1id: backpatchwith:
api-key: ${{ secrets.BACKPATCH_API_KEY }}
- if: steps.backpatch.outputs.removable-count != '0'run: | echo "${{ steps.backpatch.outputs.removable-count }} override(s) can go." echo '${{ steps.backpatch.outputs.results }}' | jq '.[] | select(.status=="SafeToRemove")'

Inputs

InputDefaultDescription
api-key(required)Your Backpatch API key. Every request needs one — start a 14-day trial. Pass it from a secret, never inline.
working-directory.Directory the other paths resolve against. Use it for a monorepo package.
package-jsonpackage.jsonManifest to analyze, relative to working-directory.
lockfile(none)Optional package-lock.json or yarn.lock. Improves precision.
allow-major-bumpfalseTreat overrides that only clear behind a breaking major parent upgrade as removable. Off by default.
fail-onnevernever reports only. removable fails the job when any override can be removed.
summarytrueWrite the results table to the job summary.
api-urlhttps://api.backpatch.devOverride only when self-hosting the API.

Outputs

OutputDescription
removable-countOverrides reported SafeToRemove.
needs-major-countOverrides removable only behind a major parent upgrade.
still-needed-countOverrides still doing real work.
total-countOverride entries analyzed.
resultsThe full analysis as a JSON array.

Statuses

StatusMeaning
SafeToRemoveA parent version within reach already pulls in a safe transitive version.
NeedsMajorUpgradeRemovable, but only behind a breaking major upgrade of a parent. Deliberately notSafeToRemove — treating it as one produces a PR that deletes an override and breaks the build.
StillNeededNo parent has caught up. Keep the override.
UnknownThe registry or advisory lookup could not settle it.

Before you delete anything

The analysis reads declared ranges and registry metadata. It tells you a parent should resolve safely — your lockfile and test suite are what confirm it did. Delete the entries, re-resolve the lockfile from scratch (rm -rf node_modules package-lock.json && npm install), and run your tests before merging. Updating in place can leave the old resolution pinned, which makes a still-needed override look removable.

Notes

  • What is sent: your package.json, and the lockfile only if you pass one. No repository access, no credentials, no source. The API does not retain the file beyond the request.
  • Rate limits are per key. CI is bursty and plan limits are per minute, so a busy org on one shared key can rate-limit itself. The Action surfaces a 429 with that explanation rather than a bare failure.
  • Requires a key. There is no anonymous tier. A missing or revoked key fails the step with an actionable message.
  • Self-hosting. If sending a manifest off-network is not an option, point api-url at your own deployment of the Backpatch API.

Versioning

Use the floating major tag — @v1 — to pick up fixes. Pin a full tag or SHA if you need byte-for-byte reproducibility.

License

MIT. See LICENSE

About

The official action for Backpatch

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages