Add Dependabot ignore for @types/node semver-major bumps (#112)

Prevent Dependabot from proposing wrong-direction @types/node major
bumps (e.g. 24 -> 26). /ui runs on Node 24 on Vercel; a too-new types
major still compiles but describes APIs absent at runtime.

Refs: #110

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
This commit is contained in:
seahaven-openswe[bot] 2026-07-02 18:15:22 -04:00 • committed by GitHub
parent f43606309e
commit 34c5da7328
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -22,6 +22,15 @@ updates:
groups:
minor-and-patch:
update-types: ["minor", "patch"]
ignore:
# @types/node must track the runtime Node major, not the latest release.
# /ui is the web dashboard deployed on Vercel; pin @types/node to the Node
# major Vercel builds/runs it on. Dependabot can't see that and a too-new
# types major still compiles (passes CI, wrong at runtime). Sanctioned
# exception to the no-blanket-ignore rule (engineering-handbook
# github-standards Pinning Principle). Minor/patch within the major flow.
- dependency-name: "@types/node"
update-types: ["version-update:semver-major"]
# Docker — root Dockerfile
- package-ecosystem: "docker"