chore: tune dependabot grouping and ignore eslint majors - #89
Merged
Merged
Conversation
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & Why
Four Dependabot pull requests were open and could not be cleared by merging them in order. Both causes are configuration, not dependencies.
1. Security updates were never grouped
groupsdefaults toapplies-to: version-updates. Security updates are generated from advisories rather than the weekly schedule, so they are not grouped by default and every vulnerable package gets its own pull request. The timestamps make the split visible:Those security pull requests change nothing but
package-lock.json, so merging one forces a rebase of every other. That cost a full cycle already: merging #86 closed #85 and #84, and Dependabot reopened them at newer versions as #88 (2.11.22→2.11.24) and #87 (4.28.9→4.29.0). Merging them one at a time invites the same churn again.A second group with
applies-to: security-updatesandpatterns: ["*"]collapses them into a single pull request.minor-and-patchnow statesapplies-to: version-updatesexplicitly. That is already the default and changes no behavior, but once a second group declaresapplies-to, leaving the first implicit invites the reading thatminor-and-patchcovers security updates too.2.
eslint10 cannot be adopted, and closing the PR does not stop iteslint-config-next@16.3.4declares peereslint >=9.0.0, permissive enough that Dependabot treats eslint 10 as safe. The plugins it bundles disagree:eslint-config-next)eslint-plugin-react^3 || … || ^9.7eslint-plugin-import^2 || … || ^9Both rely on a context API removed in eslint 10, so
npm run lintfails before it lints anything:There is no workaround on our side — it needs an upstream release.
Closing #83 by hand is not durable. Dependabot reads a manual close as "skip this exact version" and reopens on the next release; it has already walked
10.9.1→10.10.0on its own. Theignoreentry is scoped toversion-update:semver-major, so 9.x minor and patch updates still flow, and becausepackage.jsonpins"eslint": "^9", an eslint security fix would arrive as a 9.x update and is unaffected. The inline comment records the condition for removing the rule so it does not become permanent dead config.Not done here, on purpose
allow: dependency-type: "direct"is the obvious way to cut the pull request count, and it would have suppressed exactly the advisories that mattered:browserslist(high),baseline-browser-mapping, and@humanfs/nodeare all transitive and none appear inpackage.json. Grouping reduces how many pull requests arrive;allowwould reduce what Dependabot reports at all.This PR also does not resolve the three open advisories. #88, #87, and #81 are superseded by a separate
fix:PR that bumps all three in one lockfile change.Related Issue
N/A
How to Verify
Dependabot configuration only takes effect from the default branch, so the grouping itself cannot be exercised from this PR. What is checkable now:
The file parses and declares two distinct groups:
npm run format:check— Prettier covers YAML, and CI runs this.Confirm
ignoreis scoped toversion-update:semver-major, not all ofeslint. A baredependency-name: "eslint"would also mask 9.x security fixes.Confirm
📦 Dependenciesgrouping in.github/release.ymlis unaffected — labels are unchanged, so release-note categories behave as before.After merge:
ignorerule. If it is still open after the next Monday run, close it manually.Checklist
feat:,fix:,chore:,refactor:,docs:,i18n:)locales/ko.jsonandlocales/en.json(if UI text changed) — N/A, no UI text changed