Commit 8bd9ffb
authored
ci: enable grouped dependabot updates for npm (#391)
## Summary
There is no `.github/dependabot.yml` today, so dependabot runs
**security updates only**, and those bump one package at a time. Astro
releases `astro` and `@astrojs/*` in lockstep with narrow peer ranges,
so a single-package bump inside that family frequently cannot resolve at
all: #384 fails `npm ci` with ERESOLVE, as did #337 before it.
This enables npm version updates with three groups:
- `astro` / `astro-security` — `astro` + `@astrojs/*` in one PR, so
dependabot resolves the family in a single pass. This is the fix for the
#384 class.
- `rest` — everything else in one PR, so the weekly run stays at two
PRs.
## What this does not fix
Grouping fixes resolution, not code. A Starlight minor is a breaking
release, so a grouped PR still fails the build check whenever the new
version needs source changes (0.39 changed the `autogenerate` sidebar
shape, 0.42 rewrote the mobile-menu markup). Those still get taken over
by hand on an `infra/` branch, which is also the only way to get a
preview: `preview-deployment.yml` is skipped on dependabot PRs because
their token is read-only.
`.agents/upstream-tracking.md` gains a section recording that, plus the
two lockfile and rendering checks worth running when taking a bump over.1 parent 0c2dc8f commit 8bd9ffb
2 files changed
Lines changed: 78 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
235 | 235 | | |
236 | 236 | | |
237 | 237 | | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
0 commit comments