fix: stop dependabot auto-merge from landing breaking majors
Root causes (this round):
- dependabot.yml had been overwritten to a minimal version with NO
ignore rules -> major bumps allowed (typescript 7, eslint 10, tsparticles 4)
- main branch had NO branch protection -> 'gh pr merge --auto' merged
even with failing CI
- auto-merge workflow had no check-run verification step
Fixes:
- Branch protection on main: required status check 'lint + typecheck +
test + build' (strict) so auto-merge cannot land failing changes
- dependabot-auto-merge.yml: verify CI check-run conclusion == success
(actions/github-script poll with timeout) before enabling auto-merge
- dependabot.yml: restore ignore rules for eslint/typescript/@tsparticles
majors + eslint-config-next + eslint-plugin-react
- Rollback toolchain to known-good exact pins:
typescript 6.0.3, eslint 9.39.5, @tsparticles/{react,engine,slim} 3.x
(exact versions, no ranges dependabot can widen)
- Close dependabot PR #19 (tsparticles 4.4.0)
This commit is contained in:
@@ -5,6 +5,8 @@ updates:
|
||||
schedule:
|
||||
interval: "daily"
|
||||
open-pull-requests-limit: 10
|
||||
labels:
|
||||
- "dependencies"
|
||||
groups:
|
||||
production:
|
||||
dependency-type: "production"
|
||||
@@ -16,3 +18,40 @@ updates:
|
||||
update-types:
|
||||
- "minor"
|
||||
- "patch"
|
||||
ignore:
|
||||
# ---- Toolchain pins: semver-major bumps break the lint/typecheck stack ----
|
||||
# ESLint 10 dropped rule-context getFilename(); eslint-plugin-react (^7.37.x)
|
||||
# peer range caps at eslint ^9.7 -> react/display-name crash at load.
|
||||
- dependency-name: "eslint"
|
||||
update-types: ["version-update:semver-major"]
|
||||
# typescript-eslint 8.x peer range is ">=4.8.4 <6.1.0" -> TS 7 hard-refuses.
|
||||
- dependency-name: "typescript"
|
||||
update-types: ["version-update:semver-major"]
|
||||
# @tsparticles v4 changed its exported API; the vendored SparklesCore from the
|
||||
# Aceternity registry targets the v3 API (initParticlesEngine, IEffect.fill...).
|
||||
# NOTE: dependabot `ignore` does NOT support wildcards (only `groups` does) —
|
||||
# list each exact scoped package.
|
||||
- dependency-name: "@tsparticles/react"
|
||||
update-types: ["version-update:semver-major"]
|
||||
- dependency-name: "@tsparticles/engine"
|
||||
update-types: ["version-update:semver-major"]
|
||||
- dependency-name: "@tsparticles/slim"
|
||||
update-types: ["version-update:semver-major"]
|
||||
# eslint-config-next majors follow Next.js majors and can pull incompatible
|
||||
# plugin versions; framework majors are deliberate, not auto-bumps.
|
||||
- dependency-name: "eslint-config-next"
|
||||
update-types: ["version-update:semver-major"]
|
||||
# eslint-plugin-react 8.x targets ESLint 10, which conflicts with the
|
||||
# pinned eslint 9 (and the vendored components' validated toolchain).
|
||||
- dependency-name: "eslint-plugin-react"
|
||||
update-types: ["version-update:semver-major"]
|
||||
- package-ecosystem: "github-actions"
|
||||
directory: "/"
|
||||
schedule:
|
||||
interval: "weekly"
|
||||
groups:
|
||||
actions:
|
||||
patterns: ["*"]
|
||||
update-types:
|
||||
- "minor"
|
||||
- "patch"
|
||||
|
||||
Reference in New Issue
Block a user