fix: pin @types/node to CI runtime major and block dependabot major bumps #4
No reviewers
Labels
No labels
bug
ci
dependencies
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/rustdesk-server#4
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "fix/pin-types-node-to-runtime-major"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Pins
@types/nodeto^24(the Node major used in CI'snode-version) and adds a scoped Dependabotignorefor@types/nodeversion-update:semver-major. This stops Dependabot from proposing wrong-direction major bumps (e.g. #1, bumping to 26) that pass CI but describe APIs absent at the repo's runtime. Minor/patch within the current major keep flowing.This is the sanctioned exception to the no-blanket-ignore rule (engineering-handbook
github-standardsPinning Principle) —@types/nodemust track the runtime Node major, and Dependabot cannot detect it.Closes #3
Validation
tsc --noEmitpasses cleanlycdk synthproduces the expected CloudFormation output with no errorsnode-version: "24"in bothci.yamlanddeploy.yamlTests
No new tests added — this is a pinning/config change. Existing compilation and synth checks pass.
Notes
After merge, #1 (the
@types/node25→26 bump PR) should be closed manually — it's now pinned to^24and Dependabot will stop proposing major bumps.✅ Open SWE Review: No issues found
Open SWE reviewed this PR and found no potential bugs to report.
Open in Web