Repository navigation
Keep major npm updates out of the Dependabot group - #35
Merged
Merged
Conversation
Group only minor and patch updates, so each major update arrives as its own PR and can be migrated on its own. The last grouped PR (#28) bundled five major upgrades and failed lint and test. Also switch to the increase-if-necessary versioning strategy. By default Dependabot raised every range in package.json, including @types/vscode from ^1.32.0 to ^1.138.0. That is a minor update, so it would still be grouped, and vsce refuses to package when the @types/vscode range exceeds engines.vscode. CI doesn't run vsce, so the break would go unnoticed. With increase-if-necessary, updates that fit the existing range change only the lockfile.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes the npm Dependabot config so major updates no longer arrive bundled together, as they did in #28 (five majors in one PR, failing lint and test).
Changes
Majors ungrouped: the
npmgroup now matches onlyminorandpatchupdates. Each major update gets its own PR, so it can be migrated on its own the way Migrate tests to @vscode/test-cli #29, Migrate to ESLint 10 flat config and TypeScript 6 with strict mode #31 and Upgrade chai to 6 and type packages, remove unused sinon #33 were.versioning-strategy: increase-if-necessary: by default, Dependabot raised every range inpackage.json, even when the new version already fit. For example, Bump the npm group with 11 updates #28 changed@types/vscodefrom^1.32.0to^1.138.0. That's a minor update, so it would still be grouped after this change, andvsce packagerejects it:CI doesn't run
vsce, so that failure wouldn't show up until release. Withincrease-if-necessary, updates that fit the existing range change onlyyarn.lock, as in Resolve Dependabot alerts and add npm to Dependabot config #27 and Upgrade chai to 6 and type packages, remove unused sinon #33. Ranges change only when a version falls outside them, which in practice means majors.The github-actions entry and the 7-day cooldown are unchanged.
Testing
.github/dependabot.ymlvalidates against the SchemaStoredependabot-2.0schema.vsceerror above locally by setting the@types/vscoderange to^1.138.0.Expected follow-ups
Dependabot should now open separate PRs for majors that are available but not adopted. That includes
typescript7, which will fail lint because typescript-eslint supports only<6.1.0, and@types/node26, while the extension host runs Node 24. Commenting@dependabot ignore this major versionon those PRs stops them from coming back until the next major.