Ignore @types/node major bumps in Dependabot (#31)
Some checks are pending
Deploy / deploy (push) Waiting to run

This pure CDK app is built and synthed on Node 24 (no Lambdas), so
@types/node is pinned to ^24. A too-new types major still compiles, so a
major bump passes CI while describing APIs absent at the build Node.

Add a scoped Dependabot ignore for @types/node semver-major bumps so the
alignment can only be broken deliberately, alongside a Node upgrade.
Minor/patch within the major still flow. Sanctioned exception to the
no-blanket-ignore rule (engineering-handbook github-standards Pinning
Principle).
This commit is contained in:
Adam Moussa 2026-06-24 15:01:32 -04:00 • committed by GitHub
parent 797d1e83ff
commit 749e5ce4e9
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -9,6 +9,16 @@ updates:
update-types:
- "minor"
- "patch"
ignore:
# @types/node must track the runtime Node major, not the latest release.
# This is a pure CDK app (no Lambdas); it is built/synthed on Node 24, so
# @types/node is pinned to ^24. Dependabot can't see the build Node and a
# too-new types major still compiles, so a major bump passes CI while being
# wrong. This is the sanctioned exception to the no-blanket-ignore rule
# (engineering-handbook github-standards Pinning Principle). Bump deliberately
# alongside a Node upgrade. Minor/patch within the current major still flow.
- dependency-name: "@types/node"
update-types: ["version-update:semver-major"]
- package-ecosystem: "github-actions"
directory: "/"
schedule: