seahaven-door-unlock-api/.github/dependabot.yml
2026-08-11 11:15:08 -04:00

35 lines
1.1 KiB
YAML

version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
commit-message:
prefix: "chore(deps)"
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"
ignore:
# @types/node must track the runtime Node major, not the latest release.
# This stack's Lambdas run on nodejs24.x, so @types/node is pinned to ^24.
# Dependabot can't see the Lambda runtime and a too-new types major still
# compiles, so a major bump passes CI while being wrong at runtime. This is
# the sanctioned exception to the no-blanket-ignore rule (engineering-handbook
# github-standards Pinning Principle). Bump deliberately alongside a runtime
# upgrade. Minor/patch within the current major still flow.
- dependency-name: "@types/node"
update-types: ["version-update:semver-major"]
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
commit-message:
prefix: "chore(deps)"
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"