fix: stop dependabot from proposing wrong-direction @types/node major bumps

Add an ignore rule for version-update:semver-major on @types/node to
prevent Dependabot from proposing bumps that exceed the CI/synth Node
major (24). This is a sanctioned exception — minor and patch updates
within the current major still flow normally.

Refs #16
This commit is contained in:
amoussa1229 2026-07-04 05:31:54 +00:00
parent dee783717a
commit c5cae564f7

View file

@ -9,6 +9,14 @@ updates:
update-types:
- "minor"
- "patch"
ignore:
# @types/node must track the runtime Node major, not the latest release.
# Pure-CDK repo: the runtime is the Node that runs `cdk synth`/`tsc` in CI.
# Dependabot can't see that and a too-new types major still compiles (passes
# CI, wrong at runtime). Sanctioned exception to the no-blanket-ignore rule
# (engineering-handbook github-standards Pinning Principle). Minor/patch flow.
- dependency-name: "@types/node"
update-types: ["version-update:semver-major"]
- package-ecosystem: "github-actions"
directory: "/"
schedule: