diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 585ad76..388da65 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -68,6 +68,31 @@ updates: commit-message: prefix: "deps" groups: + # vitest and @vitest/coverage-v8 (and other @vitest/* packages) peer + # each other exactly, so bumping one without the other breaks + # `npm ci` with an ERESOLVE. Bump the whole family together in one + # PR. Must come before security/patch/minor below — Dependabot + # assigns each update to the FIRST matching group. + vitest: + patterns: + - "vitest" + - "@vitest/*" + # @eslint/js peers eslint with a major-locked range ("^10.0.0"), so a + # future eslint major bump without @eslint/js moving too would hit + # the same npm ci ERESOLVE class as the vitest/coverage-v8 split. + # @cldmv/eslint-plugin-jsonv doesn't peer eslint directly but is + # bundled here to keep the lint-config family moving together. + eslint: + patterns: + - "eslint" + - "@eslint/*" + - "@cldmv/eslint-plugin-*" + # @cldmv/prettier-plugin-jsonv peers prettier with a major-locked + # range ("^3.0.0") — same reasoning as the eslint group above. + prettier: + patterns: + - "prettier" + - "@cldmv/prettier-plugin-*" security: applies-to: security-updates patterns: ["*"] diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7ae96db..3c11218 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -54,15 +54,15 @@ on: required: false default: "lts/*" min_node_version: - description: "Minimum Node.js version for matrix testing (default: 20, oldest non-EOL)" + description: "Minimum Node.js version for matrix testing (default: 22.12.0 — the floor vitest 5 actually runs on)" type: string required: false - default: "20" + default: "22.12.0" max_node_major: - description: "Override max Node.js major version (default: 22)" + description: "Override max Node.js major version (default: 26)" type: string required: false - default: "22" + default: "26" lts_only_matrix: description: "Only include even-numbered (LTS) Node.js major versions in the test matrix" type: boolean @@ -197,8 +197,8 @@ jobs: .gitignore debug: ${{ github.event.inputs.debug == 'true' }} node_version: ${{ github.event.inputs.node_version || 'lts/*' }} - min_node_version: ${{ github.event.inputs.min_node_version || '20' }} - max_node_major: ${{ github.event.inputs.max_node_major || '22' }} + min_node_version: ${{ github.event.inputs.min_node_version || '22.12.0' }} + max_node_major: ${{ github.event.inputs.max_node_major || '26' }} # LTS-only matrix (even majors: 20, 22, 24, …) on every event. Odd majors # (21, 23, …) are non-LTS interim releases, and the native-binding test # toolchain (vitest 4 / rolldown / vite 8) excludes them via `engines` diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 27ba71e..9acb04c 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -60,15 +60,15 @@ on: required: false default: true min_node_version: - description: "Minimum Node.js version for matrix testing (enables matrix when set)" + description: "Minimum Node.js version for matrix testing (default: 22.12.0 — the floor vitest 5 actually runs on)" type: string required: false - default: "20" + default: "22.12.0" max_node_major: - description: "Override max Node.js major version (default: 22)" + description: "Override max Node.js major version (default: 26)" type: string required: false - default: "22" + default: "26" use_gpg: description: "Enable GPG signing (if GPG secrets provided)" type: boolean @@ -101,8 +101,8 @@ jobs: publish_to_github_packages: false publish_command: "" github_packages_publish_command: "" - min_node_version: ${{ github.event.inputs.min_node_version || '20' }} - max_node_major: ${{ github.event.inputs.max_node_major || '22' }} + min_node_version: ${{ github.event.inputs.min_node_version || '22.12.0' }} + max_node_major: ${{ github.event.inputs.max_node_major || '26' }} test_command: "npm test" # Use defaults: NODE_ENV=development, NODE_OPTIONS=--conditions=development # test_command: "NODE_OPTIONS='--conditions=slothlet-dev' npm test" # Override NODE_OPTIONS only # test_command: "NODE_ENV=test npm test" # Override NODE_ENV only