Ignore @types/node major bumps in Dependabot (#5)
This pure CDK app is built and synthed on Node 24 (no Lambdas), so @types/node is pinned to ^24. A too-new types major still compiles, so a major bump passes CI while describing APIs absent at the build Node. Add a scoped Dependabot ignore for @types/node semver-major bumps so the alignment can only be broken deliberately, alongside a Node upgrade. Minor/patch within the major still flow. Sanctioned exception to the no-blanket-ignore rule (engineering-handbook github-standards Pinning Principle).
This commit is contained in:
parent
cb3d1ccb94
commit
21b030da77
1 changed files with 10 additions and 0 deletions
10
.github/dependabot.yml
vendored
10
.github/dependabot.yml
vendored
|
|
@ -9,6 +9,16 @@ updates:
|
||||||
update-types:
|
update-types:
|
||||||
- "minor"
|
- "minor"
|
||||||
- "patch"
|
- "patch"
|
||||||
|
ignore:
|
||||||
|
# @types/node must track the runtime Node major, not the latest release.
|
||||||
|
# This is a pure CDK app (no Lambdas); it is built/synthed on Node 24, so
|
||||||
|
# @types/node is pinned to ^24. Dependabot can't see the build Node and a
|
||||||
|
# too-new types major still compiles, so a major bump passes CI while being
|
||||||
|
# wrong. This is the sanctioned exception to the no-blanket-ignore rule
|
||||||
|
# (engineering-handbook github-standards Pinning Principle). Bump deliberately
|
||||||
|
# alongside a Node upgrade. Minor/patch within the current major still flow.
|
||||||
|
- dependency-name: "@types/node"
|
||||||
|
update-types: ["version-update:semver-major"]
|
||||||
- package-ecosystem: "github-actions"
|
- package-ecosystem: "github-actions"
|
||||||
directory: "/"
|
directory: "/"
|
||||||
schedule:
|
schedule:
|
||||||
|
|
|
||||||
Reference in a new issue