Pin @types/node to the runtime major in dependabot.yml (stop wrong-direction major PRs) #73
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#73
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Add a scoped Dependabot
ignorefor@types/nodeversion-update:semver-major(in both npm directories) so Dependabot stops proposing wrong-direction major bumps (e.g. → 26), while minor/patch within the current major keep flowing.Why
@types/nodemust track the runtime Node major, not the newest npm release. A too-new types major still compiles, so the bump passes CI while describing APIs absent at runtime — the gate doesn't catch it, and Dependabot can't see the runtime. This repo just generated #71 (root,@types/node24 → 26) and #69 (/services/socket-mode). This is the sanctioned exception to the handbook no-blanket-ignore rule (engineering-handbookgithub-standardsPinning Principle).Target major for this repo
This repo's Lambdas run on
nodejs22.x, so pin@types/nodeto^22now (it's currently^24, ahead of the runtime — align down)./(CDK/Lambda code): pin^22./services/socket-mode: pin to the Node major that service runs on (Socket Mode host); default^22unless that host runs a different Node — confirm.Change
Add an
ignoreto each npmupdatesentry (directory: "/"anddirectory: "/services/socket-mode"):Tasks
ignoreblock to both npm entries in.github/dependabot.yml@types/nodeto^22inpackage.jsonand/services/socket-mode/package.json(align down from24) + update lockfilestsc && cdk synthare still green^24later)Reference
seahaven-door-unlock-api/.github/dependabot.ymlimplements this exact pattern (pinned^22).