version: 2 updates: - package-ecosystem: "npm" directory: "/" schedule: interval: "weekly" groups: minor-and-patch: update-types: - "minor" - "patch" ignore: # @types/node must track the runtime Node major, not the latest release. # This stack's Lambdas run on nodejs22.x, so @types/node is pinned to ^22. # Dependabot can't see the Lambda runtime and a too-new types major still # compiles, so a major bump passes CI while being wrong at runtime. This is # the sanctioned exception to the no-blanket-ignore rule (engineering-handbook # github-standards Pinning Principle). Bump deliberately alongside a runtime # upgrade. Minor/patch within the current major still flow. - dependency-name: "@types/node" update-types: ["version-update:semver-major"]