fix: pin @types/node to CI runtime major and block dependabot major bumps #4

Merged
seahaven-openswe[bot] merged 1 commit from fix/pin-types-node-to-runtime-major into main 2026-07-04 05:49:40 +00:00
seahaven-openswe[bot] commented 2026-07-04 05:40:51 +00:00 (Migrated from github.com)

Summary

Pins @types/node to ^24 (the Node major used in CI's node-version) and adds a scoped Dependabot ignore for @types/node version-update:semver-major. This stops Dependabot from proposing wrong-direction major bumps (e.g. #1, bumping to 26) that pass CI but describe APIs absent at the repo's runtime. Minor/patch within the current major keep flowing.

This is the sanctioned exception to the no-blanket-ignore rule (engineering-handbook github-standards Pinning Principle) — @types/node must track the runtime Node major, and Dependabot cannot detect it.

Closes #3

Validation

  • tsc --noEmit passes cleanly
  • cdk synth produces the expected CloudFormation output with no errors
  • CI workflow confirms node-version: "24" in both ci.yaml and deploy.yaml

Tests

No new tests added — this is a pinning/config change. Existing compilation and synth checks pass.

Notes

After merge, #1 (the @types/node 25→26 bump PR) should be closed manually — it's now pinned to ^24 and Dependabot will stop proposing major bumps.

## Summary Pins `@types/node` to `^24` (the Node major used in CI's `node-version`) and adds a scoped Dependabot `ignore` for `@types/node` `version-update:semver-major`. This stops Dependabot from proposing wrong-direction major bumps (e.g. #1, bumping to 26) that pass CI but describe APIs absent at the repo's runtime. Minor/patch within the current major keep flowing. This is the sanctioned exception to the no-blanket-ignore rule (engineering-handbook `github-standards` Pinning Principle) — `@types/node` must track the runtime Node major, and Dependabot cannot detect it. Closes #3 ## Validation - `tsc --noEmit` passes cleanly - `cdk synth` produces the expected CloudFormation output with no errors - CI workflow confirms `node-version: "24"` in both `ci.yaml` and `deploy.yaml` ## Tests No new tests added — this is a pinning/config change. Existing compilation and synth checks pass. ## Notes After merge, **#1** (the `@types/node` 25→26 bump PR) should be closed manually — it's now pinned to `^24` and Dependabot will stop proposing major bumps.
seahaven-openswe[bot] (Migrated from github.com) reviewed 2026-07-04 05:42:31 +00:00
seahaven-openswe[bot] (Migrated from github.com) left a comment

✅ Open SWE Review: No issues found

Open SWE reviewed this PR and found no potential bugs to report.

Open in Web

## ✅ Open SWE Review: No issues found Open SWE reviewed this PR and found no potential bugs to report. [Open in Web](https://openswe.seahaven.com/agents/reviews/Sea-Haven-Industries/rustdesk-server/4) <!-- open-swe-reviewer pr=4 -->
amoussa1229 (Migrated from github.com) approved these changes 2026-07-04 05:49:33 +00:00
This repo is archived. You cannot comment on pull requests.
No description provided.