From c5cae564f77925f43e8977984e4b8d7486908ab3 Mon Sep 17 00:00:00 2001 From: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> Date: Sat, 4 Jul 2026 05:31:54 +0000 Subject: [PATCH] fix: stop dependabot from proposing wrong-direction @types/node major bumps MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add an ignore rule for version-update:semver-major on @types/node to prevent Dependabot from proposing bumps that exceed the CI/synth Node major (24). This is a sanctioned exception — minor and patch updates within the current major still flow normally. Refs #16 --- .github/dependabot.yml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 2a101d7..6aa91fc 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,6 +9,14 @@ updates: update-types: - "minor" - "patch" + ignore: + # @types/node must track the runtime Node major, not the latest release. + # Pure-CDK repo: the runtime is the Node that runs `cdk synth`/`tsc` in CI. + # Dependabot can't see that and a too-new types major still compiles (passes + # CI, wrong at runtime). Sanctioned exception to the no-blanket-ignore rule + # (engineering-handbook github-standards Pinning Principle). Minor/patch flow. + - dependency-name: "@types/node" + update-types: ["version-update:semver-major"] - package-ecosystem: "github-actions" directory: "/" schedule: