From 34c5da73287399fe07a8b8486f6bc28161aba500 Mon Sep 17 00:00:00 2001 From: "seahaven-openswe[bot]" <296972425+seahaven-openswe[bot]@users.noreply.github.com> Date: Thu, 2 Jul 2026 18:15:22 -0400 Subject: [PATCH] Add Dependabot ignore for @types/node semver-major bumps (#112) Prevent Dependabot from proposing wrong-direction @types/node major bumps (e.g. 24 -> 26). /ui runs on Node 24 on Vercel; a too-new types major still compiles but describes APIs absent at runtime. Refs: #110 Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com> --- .github/dependabot.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index f21a4257..e3ba2844 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -22,6 +22,15 @@ updates: groups: minor-and-patch: update-types: ["minor", "patch"] + ignore: + # @types/node must track the runtime Node major, not the latest release. + # /ui is the web dashboard deployed on Vercel; pin @types/node to the Node + # major Vercel builds/runs it on. Dependabot can't see that and a too-new + # types major still compiles (passes CI, wrong at runtime). Sanctioned + # exception to the no-blanket-ignore rule (engineering-handbook + # github-standards Pinning Principle). Minor/patch within the major flow. + - dependency-name: "@types/node" + update-types: ["version-update:semver-major"] # Docker — root Dockerfile - package-ecosystem: "docker"