seahaven-org-baseline/.github/dependabot.yml
Adam Moussa 517f41eb7f
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run
ci: add org PR policy caller (#74)
Refs: PLAT-62
2026-08-04 11:56:30 -04:00

29 lines
1 KiB
YAML

version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
commit-message:
prefix: "chore(deps)"
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"
ignore:
# @types/node must track the runtime Node major, not the latest release.
# This is a pure CDK app (no Lambdas); it is built/synthed on Node 24, so
# @types/node is pinned to ^24. Dependabot can't see the build Node and a
# too-new types major still compiles, so a major bump passes CI while being
# wrong. This is the sanctioned exception to the no-blanket-ignore rule
# (engineering-handbook github-standards Pinning Principle). Bump deliberately
# alongside a Node upgrade. Minor/patch within the current major still flow.
- dependency-name: "@types/node"
update-types: ["version-update:semver-major"]
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
commit-message:
prefix: "chore(deps)"