From ff4f750678e24aaeb1f567adfeb8316d1ae85abe Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 24 Jun 2026 14:49:51 -0400 Subject: [PATCH] Ignore @types/node major bumps in Dependabot This pure CDK app is built and synthed on Node 24 (no Lambdas), so @types/node is pinned to ^24. A too-new types major still compiles, so a major bump passes CI while describing APIs absent at the build Node. Add a scoped Dependabot ignore for @types/node semver-major bumps so the alignment can only be broken deliberately, alongside a Node upgrade. Minor/patch within the major still flow. Sanctioned exception to the no-blanket-ignore rule (engineering-handbook github-standards Pinning Principle). --- .github/dependabot.yml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index a6586ff..cbcbe9f 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,6 +9,16 @@ updates: update-types: - "minor" - "patch" + ignore: + # @types/node must track the runtime Node major, not the latest release. + # This is a pure CDK app (no Lambdas); it is built/synthed on Node 24, so + # @types/node is pinned to ^24. Dependabot can't see the build Node and a + # too-new types major still compiles, so a major bump passes CI while being + # wrong. This is the sanctioned exception to the no-blanket-ignore rule + # (engineering-handbook github-standards Pinning Principle). Bump deliberately + # alongside a Node upgrade. Minor/patch within the current major still flow. + - dependency-name: "@types/node" + update-types: ["version-update:semver-major"] - package-ecosystem: "github-actions" directory: "/" schedule: