seahaven-door-unlock-api/.github/dependabot.yml
Adam Moussa 7dc6a69ddd
Some checks are pending
Deploy / deploy (push) Waiting to run
Pin @types/node to runtime major (Node 22) (#41)
The Lambdas in this stack run on the nodejs22.x runtime, but @types/node
had drifted to ^25 via Dependabot. A too-new types major still compiles,
so the mismatch passed CI while describing APIs absent at runtime.

Repin to ^22 to match the Lambda runtime and add a scoped Dependabot
ignore for @types/node semver-major bumps so the alignment can only be
broken deliberately, alongside a runtime upgrade. Minor/patch within the
major still flow. Sanctioned exception to the no-blanket-ignore rule
(engineering-handbook github-standards Pinning Principle).
2026-06-24 15:01:13 -04:00

21 lines
865 B
YAML

version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"
ignore:
# @types/node must track the runtime Node major, not the latest release.
# This stack's Lambdas run on nodejs22.x, so @types/node is pinned to ^22.
# Dependabot can't see the Lambda runtime and a too-new types major still
# compiles, so a major bump passes CI while being wrong at runtime. This is
# the sanctioned exception to the no-blanket-ignore rule (engineering-handbook
# github-standards Pinning Principle). Bump deliberately alongside a runtime
# upgrade. Minor/patch within the current major still flow.
- dependency-name: "@types/node"
update-types: ["version-update:semver-major"]