Skip to content

chore: tune dependabot grouping and ignore eslint majors - #89

Merged
Jiseoup merged 2 commits into
mainfrom
chore/tune-dependabot-config
Sep 16, 2026
Merged

Jiseoup merged 2 commits into
mainfrom
chore/tune-dependabot-config

Conversation

@Jiseoup

@Jiseoup Jiseoup commented Sep 16, 2026

Copy link
Copy Markdown
Owner

What & Why

Four Dependabot pull requests were open and could not be cleared by merging them in order. Both causes are configuration, not dependencies.

1. Security updates were never grouped

groups defaults to applies-to: version-updates. Security updates are generated from advisories rather than the weekly schedule, so they are not grouped by default and every vulnerable package gets its own pull request. The timestamps make the split visible:

#82, #83, #86                  Monday 01:45    grouped version updates
#81  2026-09-03 17:40
#84  2026-09-07 14:23          unscheduled     one security PR per package
#85  2026-09-11 03:55

Those security pull requests change nothing but package-lock.json, so merging one forces a rebase of every other. That cost a full cycle already: merging #86 closed #85 and #84, and Dependabot reopened them at newer versions as #88 (2.11.22 → 2.11.24) and #87 (4.28.9 → 4.29.0). Merging them one at a time invites the same churn again.

A second group with applies-to: security-updates and patterns: ["*"] collapses them into a single pull request.

minor-and-patch now states applies-to: version-updates explicitly. That is already the default and changes no behavior, but once a second group declares applies-to, leaving the first implicit invites the reading that minor-and-patch covers security updates too.

2. eslint 10 cannot be adopted, and closing the PR does not stop it

eslint-config-next@16.3.4 declares peer eslint >=9.0.0, permissive enough that Dependabot treats eslint 10 as safe. The plugins it bundles disagree:

Plugin (bundled by eslint-config-next) Latest Peer range
eslint-plugin-react 7.37.5 ^3 || … || ^9.7
eslint-plugin-import 2.32.0 ^2 || … || ^9

Both rely on a context API removed in eslint 10, so npm run lint fails before it lints anything:

TypeError: Error while loading rule 'react/display-name':
contextOrFilename.getFilename is not a function

There is no workaround on our side — it needs an upstream release.

Closing #83 by hand is not durable. Dependabot reads a manual close as "skip this exact version" and reopens on the next release; it has already walked 10.9.1 → 10.10.0 on its own. The ignore entry is scoped to version-update:semver-major, so 9.x minor and patch updates still flow, and because package.json pins "eslint": "^9", an eslint security fix would arrive as a 9.x update and is unaffected. The inline comment records the condition for removing the rule so it does not become permanent dead config.

Not done here, on purpose

allow: dependency-type: "direct" is the obvious way to cut the pull request count, and it would have suppressed exactly the advisories that mattered: browserslist (high), baseline-browser-mapping, and @humanfs/node are all transitive and none appear in package.json. Grouping reduces how many pull requests arrive; allow would reduce what Dependabot reports at all.

This PR also does not resolve the three open advisories. #88, #87, and #81 are superseded by a separate fix: PR that bumps all three in one lockfile change.

Related Issue

N/A

How to Verify

Dependabot configuration only takes effect from the default branch, so the grouping itself cannot be exercised from this PR. What is checkable now:

  1. The file parses and declares two distinct groups:

    python3 -c "import yaml,json; print(json.dumps(yaml.safe_load(open('.github/dependabot.yml'))['updates'][0]['groups'], indent=2))"
    
  2. npm run format:check — Prettier covers YAML, and CI runs this.

  3. Confirm ignore is scoped to version-update:semver-major, not all of eslint. A bare dependency-name: "eslint" would also mask 9.x security fixes.

  4. Confirm 📦 Dependencies grouping in .github/release.yml is unaffected — labels are unchanged, so release-note categories behave as before.

After merge:

  1. Dependabot re-evaluates on its next run and should close chore: bump eslint from 9.39.4 to 10.10.0 #83 itself, since eslint 10 now matches an ignore rule. If it is still open after the next Monday run, close it manually.
  2. The next security advisory affecting more than one package should arrive as a single grouped pull request instead of one per package.

Checklist

  • PR title follows Conventional Commits (feat:, fix:, chore:, refactor:, docs:, i18n:)
  • Translations added to both locales/ko.json and locales/en.json (if UI text changed) — N/A, no UI text changed
  • Tested on mobile viewport (if UI changed) — N/A, no UI change

@Jiseoup Jiseoup self-assigned this Sep 16, 2026
@Jiseoup Jiseoup added the chore Maintenance, config, CI label Sep 16, 2026
@Jiseoup
Jiseoup merged commit 49892aa into main Sep 16, 2026
3 checks passed
@Jiseoup
Jiseoup deleted the chore/tune-dependabot-config branch September 16, 2026 15:57

This branch was successfully deployed

1 active deployment
Preview — a9ae58bf Deployed Sep 16, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Maintenance, config, CI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant