From 2ede610f1eae748826784cc58090fab5ad0928c6 Mon Sep 17 00:00:00 2001 From: Bharath Sendhurpandi Date: Wed, 9 Sep 2026 10:55:52 +0530 Subject: [PATCH] chore(deps): declare the npm ecosystem for Dependabot CI already builds and tests every proposal; the major group exists for rendering changes it cannot assert. Signed-off-by: Bharath Sendhurpandi --- .github/dependabot.yml | 48 +++++++++++++++++++++++++++++++++++++----- 1 file changed, 43 insertions(+), 5 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 0be8c66..8cb031c 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -59,8 +59,46 @@ updates: # anything. Ungrouped, it is what split the first batch. open-pull-requests-limit: 5 -# ADDING THE BUILD'S OWN ECOSYSTEM is a separate decision, deliberately not made here. -# Actions are infrastructure and a bump is a security question. A compile-time -# dependency is not: a Minecraft plugin is built against a specific server API, and a -# bot raising that version is a compatibility change wearing a security change's -# clothes. Add `gradle`, `npm` or whatever applies only when someone owns the review. +# THE BUILD'S OWN ECOSYSTEM. The template leaves this decision to each repository and +# asks that it only be made when someone owns the review. It is made here, and the npm +# block below is the result. +# +# The template's caution is about a Minecraft plugin compiled against a specific server +# API, where a bot raising the version is a compatibility change wearing a security +# change's clothes. Nothing here is that: @resvg/resvg-js and archiver are ordinary +# runtime dependencies of a build tool, and neither decides what this repository is +# compatible WITH. So there is no ignore list, unlike the plugin repositories. +# +# CI carries the review here. ci.yml runs npm ci, builds the pack at all five +# resolutions and runs the animation, palette, base-sync, tiling-rules and sync-studio +# suites, so a proposal that breaks the toolchain fails before anyone reads it. What CI +# does NOT assert is rendered OUTPUT: @resvg/resvg-js is a native module, and a major +# that changes rasterisation would build green and ship different pixels. That is what +# the separate major group is for - it arrives on its own, to be looked at. + + - package-ecosystem: npm + directory: / + schedule: + interval: weekly + day: monday + groups: + npm: + applies-to: version-updates + patterns: + - '*' + update-types: + - minor + - patch + npm-major: + applies-to: version-updates + patterns: + - '*' + update-types: + - major + commit-message: + # `build` rather than `ci`: ci is the Conventional Commits type for workflow + # actions, build is the one for build-system dependencies. + prefix: build + labels: + - dependencies + open-pull-requests-limit: 5