mirror of
https://github.com/Fission-AI/OpenSpec.git
synced 2026-10-02 05:24:34 +08:00
The security overrides were declared twice: in pnpm-workspace.yaml, with the advisory comments explaining each pin, and again under package.json's pnpm.overrides. The copies are not additive — pnpm 10 uses package.json's block instead of the workspace list when both are present — and Dependabot rewrites plain-name entries in package.json whenever it bumps the same package. So a routine bump silently displaces the pins that patch advisories, and fails the equality test that guards them (#1812). Keeps one declaration, in the file that carries the reasoning, and asserts the mirror stays gone. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
107 lines
3.4 KiB
YAML
107 lines
3.4 KiB
YAML
version: 2
|
|
|
|
# Dependabot does not manage two dependency surfaces in this repo:
|
|
# 1. pnpm `overrides` (pnpm-workspace.yaml, root and website) — transitive
|
|
# version pins that remediate advisories Dependabot can't otherwise reach.
|
|
# It never bumps or removes these; each carries an inline advisory comment
|
|
# noting the removal condition (see pnpm-workspace.yaml). They live in
|
|
# pnpm-workspace.yaml only, because Dependabot *does* rewrite a plain-name
|
|
# override (`postcss: ^8.5.26`) mirrored under package.json's `pnpm.overrides`
|
|
# — and that block replaces the workspace list rather than merging with it,
|
|
# so the mirror displaces the real pins. See #1812.
|
|
# 2. The Nix flake (flake.nix / flake.lock). Update nixpkgs manually with
|
|
# `nix flake update`; there is no Dependabot ecosystem for Nix. Note that the
|
|
# pnpmDeps FOD hash in flake.nix must be regenerated on any root lockfile change.
|
|
|
|
updates:
|
|
# Published CLI package
|
|
- package-ecosystem: npm
|
|
directory: /
|
|
schedule:
|
|
interval: weekly
|
|
day: monday
|
|
# Let a freshly published version sit before adopting it. Security updates
|
|
# ignore the cooldown, so this only delays routine bumps — long enough for a
|
|
# compromised release to be yanked before it reaches this repo.
|
|
cooldown:
|
|
default-days: 7
|
|
semver-major-days: 30
|
|
semver-minor-days: 7
|
|
semver-patch-days: 3
|
|
open-pull-requests-limit: 5
|
|
ignore:
|
|
- dependency-name: "@types/node"
|
|
update-types:
|
|
- version-update:semver-major
|
|
# Chalk 6 requires Node 22, while the published CLI supports Node 20.19.
|
|
- dependency-name: "chalk"
|
|
update-types:
|
|
- version-update:semver-major
|
|
- dependency-name: "typescript"
|
|
update-types:
|
|
- version-update:semver-major
|
|
commit-message:
|
|
prefix: chore
|
|
include: scope
|
|
groups:
|
|
production-dependencies:
|
|
dependency-type: production
|
|
update-types:
|
|
- minor
|
|
- patch
|
|
development-dependencies:
|
|
dependency-type: development
|
|
update-types:
|
|
- minor
|
|
- patch
|
|
|
|
# Documentation site (not published to npm)
|
|
- package-ecosystem: npm
|
|
directory: /website
|
|
schedule:
|
|
interval: weekly
|
|
day: monday
|
|
# Let a freshly published version sit before adopting it. Security updates
|
|
# ignore the cooldown, so this only delays routine bumps — long enough for a
|
|
# compromised release to be yanked before it reaches this repo.
|
|
cooldown:
|
|
default-days: 7
|
|
semver-major-days: 30
|
|
semver-minor-days: 7
|
|
semver-patch-days: 3
|
|
open-pull-requests-limit: 3
|
|
ignore:
|
|
- dependency-name: "@types/node"
|
|
update-types:
|
|
- version-update:semver-major
|
|
- dependency-name: "typescript"
|
|
update-types:
|
|
- version-update:semver-major
|
|
commit-message:
|
|
prefix: chore
|
|
include: scope
|
|
groups:
|
|
website-dependencies:
|
|
patterns:
|
|
- "*"
|
|
update-types:
|
|
- minor
|
|
- patch
|
|
|
|
# CI workflow actions
|
|
- package-ecosystem: github-actions
|
|
directory: /
|
|
schedule:
|
|
interval: weekly
|
|
day: monday
|
|
# Actions are not semver-versioned the way packages are, so this ecosystem
|
|
# accepts default-days only.
|
|
cooldown:
|
|
default-days: 7
|
|
commit-message:
|
|
prefix: ci
|
|
groups:
|
|
github-actions:
|
|
patterns:
|
|
- "*"
|