From 9ee18e500fa5c588423773dd6b6e45478438dfca Mon Sep 17 00:00:00 2001 From: Douglas Eichelberger Date: Wed, 30 Sep 2026 11:25:19 -0700 Subject: [PATCH] Keep major npm updates out of the Dependabot group Group only minor and patch updates, so each major update arrives as its own PR and can be migrated on its own. The last grouped PR (#28) bundled five major upgrades and failed lint and test. Also switch to the increase-if-necessary versioning strategy. By default Dependabot raised every range in package.json, including @types/vscode from ^1.32.0 to ^1.138.0. That is a minor update, so it would still be grouped, and vsce refuses to package when the @types/vscode range exceeds engines.vscode. CI doesn't run vsce, so the break would go unnoticed. With increase-if-necessary, updates that fit the existing range change only the lockfile. --- .github/dependabot.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 825fa3c..1161405 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -14,9 +14,13 @@ updates: directory: "/" schedule: interval: "monthly" + versioning-strategy: "increase-if-necessary" groups: npm: patterns: - "*" + update-types: + - "minor" + - "patch" cooldown: default-days: 7