Pin @types/node to the runtime major in dependabot.yml (stop wrong-direction major PRs) #3

Closed
opened 2026-07-02 20:06:59 +00:00 by amoussa1229 · 2 comments
amoussa1229 commented 2026-07-02 20:06:59 +00:00 (Migrated from github.com)

Summary

Add a scoped Dependabot ignore for @types/node version-update:semver-major so Dependabot stops proposing wrong-direction major bumps (e.g. → 26), while minor/patch within the current major keep flowing.

Why

@types/node must track the runtime Node major, not the newest npm release. A too-new types major still compiles, so the bump passes CI while describing APIs absent at runtime — the gate doesn't catch it, and Dependabot can't see the runtime. This repo just generated #1 (@types/node 25 → 26). This is the sanctioned exception to the handbook no-blanket-ignore rule (engineering-handbook github-standards Pinning Principle).

Target major for this repo

This is a pure-CDK infra repo (RustDesk Server Pro on EC2; the only Node "runtime" is the cdk synth/tsc process in CI). So pin @types/node to the CI/synth Node major. It's currently on ^25, which is an odd/non-LTS Node major — align it down to the even-LTS Node CI runs.

  • Check the CI workflow's node-version and pin @types/node to that major (recommended ^24).

Change

Add an ignore to the npm updates entry (directory: /):

    ignore:
      # @types/node must track the runtime Node major, not the latest release.
      # Pure-CDK repo: the runtime is the Node that runs `cdk synth`/`tsc` in CI.
      # Dependabot can't see that and a too-new types major still compiles (passes
      # CI, wrong at runtime). Sanctioned exception to the no-blanket-ignore rule
      # (engineering-handbook github-standards Pinning Principle). Minor/patch flow.
      - dependency-name: "@types/node"
        update-types: ["version-update:semver-major"]

Tasks

  • Add the ignore block to the npm entry in .github/dependabot.yml
  • Pin @types/node in package.json to the CI Node major (align down from 25 → ^24) + update package-lock.json
  • Close #1 (wrong-direction major) once the pin lands
  • Confirm tsc && cdk synth are still green

Reference

seahaven-door-unlock-api/.github/dependabot.yml implements this pattern (pinned ^22).

## Summary Add a scoped Dependabot `ignore` for `@types/node` `version-update:semver-major` so Dependabot stops proposing wrong-direction major bumps (e.g. → 26), while minor/patch within the current major keep flowing. ## Why `@types/node` must track the **runtime** Node major, not the newest npm release. A too-new types major still compiles, so the bump passes CI while describing APIs absent at runtime — the gate doesn't catch it, and Dependabot can't see the runtime. This repo just generated **#1** (`@types/node` 25 → 26). This is the sanctioned exception to the handbook no-blanket-ignore rule (engineering-handbook `github-standards` Pinning Principle). ## Target major for this repo This is a **pure-CDK infra repo** (RustDesk Server Pro on EC2; the only Node "runtime" is the `cdk synth`/`tsc` process in CI). So pin `@types/node` to the **CI/synth Node major**. It's currently on `^25`, which is an odd/non-LTS Node major — align it **down** to the even-LTS Node CI runs. - [ ] Check the CI workflow's `node-version` and pin `@types/node` to that major (recommended `^24`). ## Change Add an `ignore` to the `npm` `updates` entry (`directory: /`): ```yaml ignore: # @types/node must track the runtime Node major, not the latest release. # Pure-CDK repo: the runtime is the Node that runs `cdk synth`/`tsc` in CI. # Dependabot can't see that and a too-new types major still compiles (passes # CI, wrong at runtime). Sanctioned exception to the no-blanket-ignore rule # (engineering-handbook github-standards Pinning Principle). Minor/patch flow. - dependency-name: "@types/node" update-types: ["version-update:semver-major"] ``` ## Tasks - [ ] Add the `ignore` block to the npm entry in `.github/dependabot.yml` - [ ] Pin `@types/node` in `package.json` to the CI Node major (align down from `25` → `^24`) + update `package-lock.json` - [ ] Close **#1** (wrong-direction major) once the pin lands - [ ] Confirm `tsc && cdk synth` are still green ## Reference `seahaven-door-unlock-api/.github/dependabot.yml` implements this pattern (pinned `^22`).
amoussa1229 commented 2026-07-04 05:26:35 +00:00 (Migrated from github.com)

@openswe review and implement the fixes for this issue. When finished, mark a PR ready for review, request review from me. Ensure PR body has "closes issue" notes

@openswe review and implement the fixes for this issue. When finished, mark a PR ready for review, request review from me. Ensure PR body has "closes issue" notes
seahaven-openswe[bot] commented 2026-07-04 05:41:11 +00:00 (Migrated from github.com)

Implemented in #4. Summary:

  • Added Dependabot for in
  • Pinned from → in (matching the CI )
  • Updated
  • Verified and pass
  • Closed #1 (the wrong-direction major PR)

Ready for review: https://github.com/Sea-Haven-Industries/rustdesk-server/pull/4

Implemented in #4. Summary: - Added Dependabot for in - Pinned from → in (matching the CI ) - Updated - Verified and pass - Closed #1 (the wrong-direction major PR) Ready for review: https://github.com/Sea-Haven-Industries/rustdesk-server/pull/4
This repo is archived. You cannot comment on issues.
No description provided.