From fb91f3df9046c0b4b252b18441e042df81ad68b0 Mon Sep 17 00:00:00 2001 From: asepharyana Date: Sun, 20 Sep 2026 22:08:14 +0700 Subject: [PATCH] chore(dependabot): fix ignore patterns (exact names, no wildcard) + checkout v7 - dependabot ignore for npm does NOT support wildcards (only groups.patterns does). The '@tsparticles/*' rule was silently ignored -> v4 bumps kept landing. Replace with exact scoped names. - bump actions/checkout v5->v7 (closes dependabot PR #5); the CI failure on that PR was a stale-branch format-check, not checkout v7. Open @tsparticles PRs now closed (#9 already closed earlier). --- .github/dependabot.yml | 8 +++++++- .github/workflows/ci.yml | 2 +- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 7bfac09..b503613 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -29,7 +29,13 @@ updates: update-types: ["version-update:semver-major"] # @tsparticles v4 changed its exported API; the vendored SparklesCore from the # Aceternity registry targets the v3 API (initParticlesEngine, IEffect.fill...). - - dependency-name: "@tsparticles/*" + # NOTE: dependabot `ignore` does NOT support wildcards (only `groups` does) — + # list each exact scoped package. + - dependency-name: "@tsparticles/react" + update-types: ["version-update:semver-major"] + - dependency-name: "@tsparticles/engine" + update-types: ["version-update:semver-major"] + - dependency-name: "@tsparticles/slim" update-types: ["version-update:semver-major"] # eslint-config-next majors follow Next.js majors and can pull incompatible # plugin versions; framework majors are deliberate, not auto-bumps. diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 853de05..537c693 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -16,7 +16,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v5 + uses: actions/checkout@v7 - name: Set up Bun uses: oven-sh/setup-bun@v2