diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 6568cd2..e16a0c7 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,3 +9,13 @@ updates: update-types: - "minor" - "patch" + ignore: + # @types/node must track the runtime Node major, not the latest release. + # This stack's Lambdas run on nodejs22.x, so @types/node is pinned to ^22. + # Dependabot can't see the Lambda runtime and a too-new types major still + # compiles, so a major bump passes CI while being wrong at runtime. This is + # the sanctioned exception to the no-blanket-ignore rule (engineering-handbook + # github-standards Pinning Principle). Bump deliberately alongside a runtime + # upgrade. Minor/patch within the current major still flow. + - dependency-name: "@types/node" + update-types: ["version-update:semver-major"] diff --git a/package-lock.json b/package-lock.json index 64067fe..324831a 100644 --- a/package-lock.json +++ b/package-lock.json @@ -16,7 +16,7 @@ }, "devDependencies": { "@aws-sdk/client-ssm": "^3.1070.0", - "@types/node": "^25.9.3", + "@types/node": "^22.0.0", "@types/source-map-support": "^0.5.10", "aws-cdk": "^2.1127.0", "esbuild": "^0.28.1", @@ -1031,13 +1031,13 @@ } }, "node_modules/@types/node": { - "version": "25.9.3", - "resolved": "https://registry.npmjs.org/@types/node/-/node-25.9.3.tgz", - "integrity": "sha512-603BddQMv3pUcr4U2dhujk83N2tTDVr/34wII2B6bJy6g+8WD6yUb11jszNs0gdi4PesVWl7ABt8nYMVpnLUcg==", + "version": "22.20.0", + "resolved": "https://registry.npmjs.org/@types/node/-/node-22.20.0.tgz", + "integrity": "sha512-QWlFW2wf3nTjC13/DqRnBpR4ZO36VJH/JVBkA/vcnmbTBNQIlnObqyqZE1tUR7+Ni23Lda8R1BxMfbXRpCUx5g==", "dev": true, "license": "MIT", "dependencies": { - "undici-types": ">=7.24.0 <7.24.7" + "undici-types": "~6.21.0" } }, "node_modules/@types/source-map-support": { @@ -1622,9 +1622,9 @@ } }, "node_modules/undici-types": { - "version": "7.24.6", - "resolved": "https://registry.npmjs.org/undici-types/-/undici-types-7.24.6.tgz", - "integrity": "sha512-WRNW+sJgj5OBN4/0JpHFqtqzhpbnV0GuB+OozA9gCL7a993SmU+1JBZCzLNxYsbMfIeDL+lTsphD5jN5N+n0zg==", + "version": "6.21.0", + "resolved": "https://registry.npmjs.org/undici-types/-/undici-types-6.21.0.tgz", + "integrity": "sha512-iwDZqg0QAGrg9Rav5H4n0M64c3mkR59cJ6wQp+7C4nI0gsmExaedaYLNO44eT4AtBBwjbTiGPMlt2Md0T9H9JQ==", "dev": true, "license": "MIT" }, diff --git a/package.json b/package.json index 84f5866..c93af53 100644 --- a/package.json +++ b/package.json @@ -13,7 +13,7 @@ }, "devDependencies": { "@aws-sdk/client-ssm": "^3.1070.0", - "@types/node": "^25.9.3", + "@types/node": "^22.0.0", "@types/source-map-support": "^0.5.10", "aws-cdk": "^2.1127.0", "esbuild": "^0.28.1",