forgejo/.github/dependabot.yml
amoussa1229 0d2f75d42e fix: pin @types/node to CI runtime major and block Dependabot major bumps
Add a Dependabot ignore for @types/node semver-major updates so
Dependabot stops proposing wrong-direction major bumps that would
reference APIs absent at runtime. Pin the package from ^25 (odd,
non-LTS) to ^24, matching the Node major that runs cdk synth/tsc
in CI. tsc --noEmit passes cleanly.
2026-07-04 05:31:13 +00:00

30 lines
923 B
YAML

version: 2
updates:
- package-ecosystem: npm
directory: /
schedule:
interval: weekly
assignees:
- amoussa1229
ignore:
# @types/node must track the runtime Node major, not the latest release.
# Pure-CDK repo: the runtime is the Node that runs `cdk synth`/`tsc` in CI.
# Dependabot can't see that and a too-new types major still compiles (passes
# CI, wrong at runtime). Sanctioned exception to the no-blanket-ignore rule
# (engineering-handbook github-standards Pinning Principle). Minor/patch flow.
- dependency-name: "@types/node"
update-types: ["version-update:semver-major"]
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
assignees:
- amoussa1229
- package-ecosystem: pip
directory: /lambda/backup-verification
schedule:
interval: weekly
assignees:
- amoussa1229