Pin @types/node to the runtime major in dependabot.yml (stop wrong-direction major PRs) #73

Closed
opened 2026-07-02 20:07:02 +00:00 by amoussa1229 · 0 comments
amoussa1229 commented 2026-07-02 20:07:02 +00:00 (Migrated from github.com)

Summary

Add a scoped Dependabot ignore for @types/node version-update:semver-major (in both npm directories) so Dependabot stops proposing wrong-direction major bumps (e.g. → 26), while minor/patch within the current major keep flowing.

Why

@types/node must track the runtime Node major, not the newest npm release. A too-new types major still compiles, so the bump passes CI while describing APIs absent at runtime — the gate doesn't catch it, and Dependabot can't see the runtime. This repo just generated #71 (root, @types/node 24 → 26) and #69 (/services/socket-mode). This is the sanctioned exception to the handbook no-blanket-ignore rule (engineering-handbook github-standards Pinning Principle).

Target major for this repo

This repo's Lambdas run on nodejs22.x, so pin @types/node to ^22 now (it's currently ^24, ahead of the runtime — align down).

  • Root / (CDK/Lambda code): pin ^22.
  • /services/socket-mode: pin to the Node major that service runs on (Socket Mode host); default ^22 unless that host runs a different Node — confirm.

Companion: the runtime-bump issue #72 (nodejs22.x → nodejs24.x) will later re-pin @types/node to ^24. This issue is the interim guard to stop the recurring major PRs now.

Change

Add an ignore to each npm updates entry (directory: "/" and directory: "/services/socket-mode"):

        ignore:
          # @types/node must track the runtime Node major, not the latest release.
          # These Lambdas run on nodejs22.x, so @types/node is pinned to ^22.
          # Dependabot can't see the Lambda runtime and a too-new types major still
          # compiles (passes CI, wrong at runtime). Sanctioned exception to the
          # no-blanket-ignore rule (engineering-handbook github-standards Pinning
          # Principle). Bump deliberately alongside a runtime upgrade (#72).
          - dependency-name: "@types/node"
            update-types: ["version-update:semver-major"]

Tasks

  • Add the ignore block to both npm entries in .github/dependabot.yml
  • Pin @types/node to ^22 in package.json and /services/socket-mode/package.json (align down from 24) + update lockfiles
  • Close #71 and #69 (wrong-direction majors) once the pins land
  • Confirm tsc && cdk synth are still green
  • Linked to runtime-bump #72 (which re-pins to ^24 later)

Reference

seahaven-door-unlock-api/.github/dependabot.yml implements this exact pattern (pinned ^22).

## Summary Add a scoped Dependabot `ignore` for `@types/node` `version-update:semver-major` (in **both** npm directories) so Dependabot stops proposing wrong-direction major bumps (e.g. → 26), while minor/patch within the current major keep flowing. ## Why `@types/node` must track the **runtime** Node major, not the newest npm release. A too-new types major still compiles, so the bump passes CI while describing APIs absent at runtime — the gate doesn't catch it, and Dependabot can't see the runtime. This repo just generated **#71** (root, `@types/node` 24 → 26) and **#69** (`/services/socket-mode`). This is the sanctioned exception to the handbook no-blanket-ignore rule (engineering-handbook `github-standards` Pinning Principle). ## Target major for this repo This repo's Lambdas run on **`nodejs22.x`**, so pin `@types/node` to **`^22`** now (it's currently `^24`, ahead of the runtime — align **down**). - Root `/` (CDK/Lambda code): pin `^22`. - `/services/socket-mode`: pin to the Node major that service runs on (Socket Mode host); default `^22` unless that host runs a different Node — confirm. > **Companion:** the runtime-bump issue #72 (nodejs22.x → nodejs24.x) will later re-pin `@types/node` to `^24`. This issue is the interim guard to stop the recurring major PRs **now**. ## Change Add an `ignore` to **each** npm `updates` entry (`directory: "/"` and `directory: "/services/socket-mode"`): ```yaml ignore: # @types/node must track the runtime Node major, not the latest release. # These Lambdas run on nodejs22.x, so @types/node is pinned to ^22. # Dependabot can't see the Lambda runtime and a too-new types major still # compiles (passes CI, wrong at runtime). Sanctioned exception to the # no-blanket-ignore rule (engineering-handbook github-standards Pinning # Principle). Bump deliberately alongside a runtime upgrade (#72). - dependency-name: "@types/node" update-types: ["version-update:semver-major"] ``` ## Tasks - [ ] Add the `ignore` block to **both** npm entries in `.github/dependabot.yml` - [ ] Pin `@types/node` to `^22` in `package.json` and `/services/socket-mode/package.json` (align down from `24`) + update lockfiles - [ ] Close **#71** and **#69** (wrong-direction majors) once the pins land - [ ] Confirm `tsc && cdk synth` are still green - [ ] Linked to runtime-bump #72 (which re-pins to `^24` later) ## Reference `seahaven-door-unlock-api/.github/dependabot.yml` implements this exact pattern (pinned `^22`).
This repo is archived. You cannot comment on issues.
No description provided.