Files
OpenSpec/.github/dependabot.yml
T
Clay GoodandClaude Opus 5 e4e112d94f chore(deps): declare pnpm overrides only in pnpm-workspace.yaml (#1816)
The security overrides were declared twice: in pnpm-workspace.yaml, with
the advisory comments explaining each pin, and again under
package.json's pnpm.overrides. The copies are not additive — pnpm 10
uses package.json's block instead of the workspace list when both are
present — and Dependabot rewrites plain-name entries in package.json
whenever it bumps the same package. So a routine bump silently
displaces the pins that patch advisories, and fails the equality test
that guards them (#1812).

Keeps one declaration, in the file that carries the reasoning, and
asserts the mirror stays gone.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-09 17:47:22 +00:00

107 lines
3.4 KiB
YAML

version: 2
# Dependabot does not manage two dependency surfaces in this repo:
# 1. pnpm `overrides` (pnpm-workspace.yaml, root and website) — transitive
# version pins that remediate advisories Dependabot can't otherwise reach.
# It never bumps or removes these; each carries an inline advisory comment
# noting the removal condition (see pnpm-workspace.yaml). They live in
# pnpm-workspace.yaml only, because Dependabot *does* rewrite a plain-name
# override (`postcss: ^8.5.26`) mirrored under package.json's `pnpm.overrides`
# — and that block replaces the workspace list rather than merging with it,
# so the mirror displaces the real pins. See #1812.
# 2. The Nix flake (flake.nix / flake.lock). Update nixpkgs manually with
# `nix flake update`; there is no Dependabot ecosystem for Nix. Note that the
# pnpmDeps FOD hash in flake.nix must be regenerated on any root lockfile change.
updates:
# Published CLI package
- package-ecosystem: npm
directory: /
schedule:
interval: weekly
day: monday
# Let a freshly published version sit before adopting it. Security updates
# ignore the cooldown, so this only delays routine bumps — long enough for a
# compromised release to be yanked before it reaches this repo.
cooldown:
default-days: 7
semver-major-days: 30
semver-minor-days: 7
semver-patch-days: 3
open-pull-requests-limit: 5
ignore:
- dependency-name: "@types/node"
update-types:
- version-update:semver-major
# Chalk 6 requires Node 22, while the published CLI supports Node 20.19.
- dependency-name: "chalk"
update-types:
- version-update:semver-major
- dependency-name: "typescript"
update-types:
- version-update:semver-major
commit-message:
prefix: chore
include: scope
groups:
production-dependencies:
dependency-type: production
update-types:
- minor
- patch
development-dependencies:
dependency-type: development
update-types:
- minor
- patch
# Documentation site (not published to npm)
- package-ecosystem: npm
directory: /website
schedule:
interval: weekly
day: monday
# Let a freshly published version sit before adopting it. Security updates
# ignore the cooldown, so this only delays routine bumps — long enough for a
# compromised release to be yanked before it reaches this repo.
cooldown:
default-days: 7
semver-major-days: 30
semver-minor-days: 7
semver-patch-days: 3
open-pull-requests-limit: 3
ignore:
- dependency-name: "@types/node"
update-types:
- version-update:semver-major
- dependency-name: "typescript"
update-types:
- version-update:semver-major
commit-message:
prefix: chore
include: scope
groups:
website-dependencies:
patterns:
- "*"
update-types:
- minor
- patch
# CI workflow actions
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
day: monday
# Actions are not semver-versioned the way packages are, so this ecosystem
# accepts default-days only.
cooldown:
default-days: 7
commit-message:
prefix: ci
groups:
github-actions:
patterns:
- "*"