Skip to content

Commit 8bd9ffb

Browse files
authored
ci: enable grouped dependabot updates for npm (#391)
## Summary There is no `.github/dependabot.yml` today, so dependabot runs **security updates only**, and those bump one package at a time. Astro releases `astro` and `@astrojs/*` in lockstep with narrow peer ranges, so a single-package bump inside that family frequently cannot resolve at all: #384 fails `npm ci` with ERESOLVE, as did #337 before it. This enables npm version updates with three groups: - `astro` / `astro-security` — `astro` + `@astrojs/*` in one PR, so dependabot resolves the family in a single pass. This is the fix for the #384 class. - `rest` — everything else in one PR, so the weekly run stays at two PRs. ## What this does not fix Grouping fixes resolution, not code. A Starlight minor is a breaking release, so a grouped PR still fails the build check whenever the new version needs source changes (0.39 changed the `autogenerate` sidebar shape, 0.42 rewrote the mobile-menu markup). Those still get taken over by hand on an `infra/` branch, which is also the only way to get a preview: `preview-deployment.yml` is skipped on dependabot PRs because their token is read-only. `.agents/upstream-tracking.md` gains a section recording that, plus the two lockfile and rendering checks worth running when taking a bump over.
1 parent 0c2dc8f commit 8bd9ffb

2 files changed

Lines changed: 78 additions & 0 deletions

File tree

‎.agents/upstream-tracking.md‎

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -235,3 +235,41 @@ If a shallow clone cannot resolve a pinned commit:
235235
git -C .sources/<repo> fetch --unshallow
236236
git -C .sources/<repo> checkout <commit>
237237
```
238+
239+
## Build dependencies (npm)
240+
241+
The packages in `package.json` are a separate axis: they decide whether the site
242+
builds, not whether its content is accurate. `.github/dependabot.yml` keeps them
243+
current with weekly version updates plus security updates.
244+
245+
`astro` and `@astrojs/*` are grouped into a single PR because Astro releases them
246+
in lockstep and pins their peer ranges narrowly. A bump to one of them alone often
247+
cannot resolve at all: astro 7.2.10, for example, moved its
248+
`@astrojs/markdown-remark` peer from an exact pin to `^7.3.0`, which only
249+
`@astrojs/mdx` 8 satisfies, which only ships with Starlight 0.42. Grouping lets
250+
dependabot resolve the whole family in one pass.
251+
252+
Grouping a security update coalesces only the family members that each carry an
253+
advisory, so an advisory against `astro` alone still arrives as a one-package PR
254+
that cannot resolve. The weekly version update is what keeps that rare, by
255+
leaving little room between the family's releases and what is committed.
256+
257+
Grouping fixes the resolution, not the code. A Starlight minor is a breaking
258+
release, so a grouped PR still fails the build check whenever the new version
259+
needs source changes (0.39 changed the `autogenerate` sidebar shape; 0.42
260+
rewrote the mobile-menu markup). Take those over by hand on an `infra/` branch:
261+
`preview-deployment.yml` is skipped on dependabot PRs, whose token is read-only,
262+
so a bump with visual impact needs a maintainer branch to get a preview at all.
263+
264+
Two things to check when taking one over:
265+
266+
- Regenerating `package-lock.json` on macOS prunes what does not apply locally:
267+
the `libc` fields on the Linux binding packages, and, when `node_modules` is
268+
present, the top-level `@emnapi/*` packages that `npm ci` needs on Linux. Move
269+
`node_modules` aside, regenerate with `npm install --package-lock-only`, copy
270+
the `libc` fields back from the previous lockfile, then validate with `npm ci`,
271+
which reads the lock without rewriting it.
272+
- `npm ci && npm run build` is the gate, but it exits 0 on rendering
273+
regressions. Diff `dist/` against a `main` baseline: `llms.txt`,
274+
`llms-full.txt`, `sitemap.xml` and the `.md` endpoints should be identical,
275+
and every HTML difference should trace to a documented upstream change.

‎.github/dependabot.yml‎

Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
version: 2
2+
3+
updates:
4+
# Version updates are enabled only so that lockstep families can be bumped
5+
# together. Without them, dependabot runs security updates only, and those
6+
# touch one package at a time: an astro security bump alone cannot resolve,
7+
# because astro pins its @astrojs/* peers to a narrow range (see #384).
8+
- package-ecosystem: npm
9+
directory: "/"
10+
schedule:
11+
interval: weekly
12+
day: monday
13+
open-pull-requests-limit: 5
14+
commit-message:
15+
prefix: "chore(deps)"
16+
groups:
17+
# astro and @astrojs/* are released in lockstep; one PR per family so
18+
# dependabot resolves them in a single pass.
19+
astro:
20+
applies-to: version-updates
21+
patterns:
22+
- "astro"
23+
- "@astrojs/*"
24+
# Only coalesces family members that each carry an advisory, so a single
25+
# astro advisory still arrives as a one-package PR that cannot resolve.
26+
# What keeps that rare is the weekly version update above; when one does
27+
# show up, take it over by hand.
28+
astro-security:
29+
applies-to: security-updates
30+
patterns:
31+
- "astro"
32+
- "@astrojs/*"
33+
# Everything else in one PR, to keep the weekly run to two PRs.
34+
rest:
35+
applies-to: version-updates
36+
patterns:
37+
- "*"
38+
exclude-patterns:
39+
- "astro"
40+
- "@astrojs/*"

0 commit comments

Comments
 (0)