Repository navigation
ci: add dependabot.yml for scheduled npm version updates - #46
Merged
Merged
Conversation
Dependabot security updates were already enabled (they open PRs on their own, e.g. #42). What was missing is scheduled VERSION updates, which is why several pnpm.overrides floors silently went stale for weeks: an upstream would ship an incremental follow-up fix, the floor would keep resolving to the older vulnerable version, and nothing refreshed the lockfile until someone looked. That is how vitest sat three weeks behind a known advisory. Weekly, grouped so dev-dependency bumps arrive as one PR rather than a dozen. Uses chore(deps) so routine bumps do not cut a release via release-please. @n8n/node-cli and n8n-workflow are ignored deliberately. Both are declared "*" in package.json, so letting Dependabot float them jumps the whole toolchain: measured at @n8n/node-cli 0.34.0 -> 0.50.3 and ~1982 lockfile lines. CLAUDE.md pins workflow behaviour to the current CLI, so those two get bumped by hand. Honest scope limit: this keeps direct devDependencies current and refreshes the lockfile, but it does not fully automate the override-floor problem. Transitive versions pinned by pnpm.overrides still need their floors raised manually, with Dependabot alerts plus `pnpm audit` as the signal. It shrinks the manual surface rather than removing it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Addresses the root cause behind #43 and #45, rather than just their symptoms.
Dependabot security updates were already enabled here — they open PRs on their own (#42 is one). What was missing is scheduled version updates. That gap is why several
pnpm.overridesfloors silently went stale for weeks: an upstream would ship an incremental follow-up fix, the floor would keep resolving to the older now-vulnerable version, and nothing refreshed the lockfile until someone thought to look. vitest sat three weeks behind a known advisory that way, and by the time this was checkedpnpm audithad reached 29 findings.chore(deps)prefix so routine bumps don't cut a release through release-please.@n8n/node-cliandn8n-workfloware ignored deliberately. Both are declared"*"inpackage.json, so letting Dependabot float them jumps the entire toolchain — measured at@n8n/node-cli0.34.0 → 0.50.3 and ~1982 lockfile lines while investigating fix: raise eight stale pnpm override floors to clear 27 advisories #43.CLAUDE.mdpins workflow behaviour to the current CLI, so those two stay manual and deliberate.Honest scope limit
Worth being clear so this isn't mistaken for a complete fix: it keeps direct devDependencies current and refreshes the lockfile, which is what would have caught the vitest lag. It does not fully automate the override-floor problem — transitive versions pinned by
pnpm.overridesstill need their floors raised by hand, with Dependabot alerts pluspnpm auditas the signal. It shrinks the manual surface; it doesn't remove it.Changes
.github/dependabot.yml— new file, 37 lines including the rationale comments.Test plan
groups.dependency-type,ignore.dependency-name)@n8n/node-cliandn8n-workflow