fix: stop dependabot auto-merge from landing breaking majors

Root causes (this round):
- dependabot.yml had been overwritten to a minimal version with NO
  ignore rules -> major bumps allowed (typescript 7, eslint 10, tsparticles 4)
- main branch had NO branch protection -> 'gh pr merge --auto' merged
  even with failing CI
- auto-merge workflow had no check-run verification step

Fixes:
- Branch protection on main: required status check 'lint + typecheck +
  test + build' (strict) so auto-merge cannot land failing changes
- dependabot-auto-merge.yml: verify CI check-run conclusion == success
  (actions/github-script poll with timeout) before enabling auto-merge
- dependabot.yml: restore ignore rules for eslint/typescript/@tsparticles
  majors + eslint-config-next + eslint-plugin-react
- Rollback toolchain to known-good exact pins:
  typescript 6.0.3, eslint 9.39.5, @tsparticles/{react,engine,slim} 3.x
  (exact versions, no ranges dependabot can widen)
- Close dependabot PR #19 (tsparticles 4.4.0)
This commit is contained in:
asepharyana
2026-09-21 11:03:34 +07:00
parent b1238d4363
commit 02b4437eb3
4 changed files with 123 additions and 99 deletions
+5 -5
View File
@@ -34,9 +34,9 @@
"@tabler/icons-react": "^3.47.0",
"@tanstack/react-query": "^5.103.1",
"@tanstack/react-table": "^9.2.4",
"@tsparticles/engine": "~3.9.0",
"@tsparticles/react": "~3.0.0",
"@tsparticles/slim": "~4.4.0",
"@tsparticles/engine": "3.9.1",
"@tsparticles/react": "3.0.0",
"@tsparticles/slim": "3.9.1",
"better-auth": "^1.7.5",
"class-variance-authority": "^0.7.1",
"clsx": "^2.1.1",
@@ -81,7 +81,7 @@
"@types/react": "^19",
"@types/react-dom": "^19",
"@vitest/coverage-v8": "^5.0.1",
"eslint": ">=9.24.0 <11",
"eslint": "9.39.5",
"eslint-config-next": "16.3.5",
"eslint-plugin-react": "^7.37.5",
"husky": "^9.1.7",
@@ -91,7 +91,7 @@
"prettier": "^3.9.8",
"prettier-plugin-tailwindcss": "^0.8.1",
"tailwindcss": "^4",
"typescript": "^7.0.2",
"typescript": "6.0.3",
"typescript-eslint": "^8.70.0",
"vitest": "^5.0.1"
},