diff --git a/.github/dependabot.yml b/.github/dependabot.yml deleted file mode 100644 index e77ecfd..0000000 --- a/.github/dependabot.yml +++ /dev/null @@ -1,35 +0,0 @@ -version: 2 -updates: - - package-ecosystem: "npm" - directory: "/" - schedule: - interval: "weekly" - commit-message: - prefix: "chore(deps)" - groups: - minor-and-patch: - update-types: - - "minor" - - "patch" - ignore: - # @types/node must track the runtime Node major, not the latest release. - # This stack's Lambdas run on nodejs24.x, so @types/node is pinned to ^24. - # Dependabot can't see the Lambda runtime and a too-new types major still - # compiles, so a major bump passes CI while being wrong at runtime. This is - # the sanctioned exception to the no-blanket-ignore rule (engineering-handbook - # github-standards Pinning Principle). Bump deliberately alongside a runtime - # upgrade. Minor/patch within the current major still flow. - - dependency-name: "@types/node" - update-types: ["version-update:semver-major"] - - - package-ecosystem: "github-actions" - directory: "/" - schedule: - interval: "weekly" - commit-message: - prefix: "chore(deps)" - groups: - minor-and-patch: - update-types: - - "minor" - - "patch"