open-swe/.github/dependabot.yml
seahaven-openswe[bot] 34c5da7328
Add Dependabot ignore for @types/node semver-major bumps (#112)
Prevent Dependabot from proposing wrong-direction @types/node major
bumps (e.g. 24 -> 26). /ui runs on Node 24 on Vercel; a too-new types
major still compiles but describes APIs absent at runtime.

Refs: #110

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-07-02 18:15:22 -04:00

53 lines
1.6 KiB
YAML

version: 2
updates:
# Python — uv (open-swe-specific; siblings use pip)
- package-ecosystem: "uv"
directory: "/"
schedule:
interval: "weekly"
assignees: ["amoussa1229"]
groups:
minor-and-patch:
update-types: ["minor", "patch"]
# JavaScript/TypeScript — Playwright (/tests/e2e), dashboard (/ui), root tooling
- package-ecosystem: "npm"
directories:
- "/"
- "/tests/e2e"
- "/ui"
schedule:
interval: "weekly"
assignees: ["amoussa1229"]
groups:
minor-and-patch:
update-types: ["minor", "patch"]
ignore:
# @types/node must track the runtime Node major, not the latest release.
# /ui is the web dashboard deployed on Vercel; pin @types/node to the Node
# major Vercel builds/runs it on. Dependabot can't see that and a too-new
# types major still compiles (passes CI, wrong at runtime). Sanctioned
# exception to the no-blanket-ignore rule (engineering-handbook
# github-standards Pinning Principle). Minor/patch within the major flow.
- dependency-name: "@types/node"
update-types: ["version-update:semver-major"]
# Docker — root Dockerfile
- package-ecosystem: "docker"
directory: "/"
schedule:
interval: "weekly"
assignees: ["amoussa1229"]
groups:
minor-and-patch:
update-types: ["minor", "patch"]
# GitHub Actions
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
assignees: ["amoussa1229"]
groups:
minor-and-patch:
update-types: ["minor", "patch"]