file-share/.github/dependabot.yml
amoussa1229 c5cae564f7 fix: stop dependabot from proposing wrong-direction @types/node major bumps
Add an ignore rule for version-update:semver-major on @types/node to
prevent Dependabot from proposing bumps that exceed the CI/synth Node
major (24). This is a sanctioned exception — minor and patch updates
within the current major still flow normally.

Refs #16
2026-07-04 05:31:54 +00:00

28 lines
915 B
YAML

version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"
ignore:
# @types/node must track the runtime Node major, not the latest release.
# Pure-CDK repo: the runtime is the Node that runs `cdk synth`/`tsc` in CI.
# Dependabot can't see that and a too-new types major still compiles (passes
# CI, wrong at runtime). Sanctioned exception to the no-blanket-ignore rule
# (engineering-handbook github-standards Pinning Principle). Minor/patch flow.
- dependency-name: "@types/node"
update-types: ["version-update:semver-major"]
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"