Skip to content

ci: add dependabot.yml for scheduled npm version updates - #46

Merged
noctisreus merged 1 commit into
mainfrom
ci/add-dependabot-version-updates
Sep 30, 2026
Merged

noctisreus merged 1 commit into
mainfrom
ci/add-dependabot-version-updates

Conversation

@noctisreus

Copy link
Copy Markdown
Collaborator

Summary

Addresses the root cause behind #43 and #45, rather than just their symptoms.

Dependabot security updates were already enabled here — they open PRs on their own (#42 is one). What was missing is scheduled version updates. That gap is why several pnpm.overrides floors silently went stale for weeks: an upstream would ship an incremental follow-up fix, the floor would keep resolving to the older now-vulnerable version, and nothing refreshed the lockfile until someone thought to look. vitest sat three weeks behind a known advisory that way, and by the time this was checked pnpm audit had reached 29 findings.

  • Weekly, grouped so dev-dependency bumps arrive as one reviewable PR instead of a dozen.
  • chore(deps) prefix so routine bumps don't cut a release through release-please.
  • @n8n/node-cli and n8n-workflow are ignored deliberately. Both are declared "*" in package.json, so letting Dependabot float them jumps the entire toolchain — measured at @n8n/node-cli 0.34.0 → 0.50.3 and ~1982 lockfile lines while investigating fix: raise eight stale pnpm override floors to clear 27 advisories #43. CLAUDE.md pins workflow behaviour to the current CLI, so those two stay manual and deliberate.

Honest scope limit

Worth being clear so this isn't mistaken for a complete fix: it keeps direct devDependencies current and refreshes the lockfile, which is what would have caught the vitest lag. It does not fully automate the override-floor problem — transitive versions pinned by pnpm.overrides still need their floors raised by hand, with Dependabot alerts plus pnpm audit as the signal. It shrinks the manual surface; it doesn't remove it.

Changes

  • .github/dependabot.yml — new file, 37 lines including the rationale comments.

Test plan

  • YAML parses and matches Dependabot's v2 schema (groups.dependency-type, ignore.dependency-name)
  • No code, dependency, or lockfile changes — nothing to build or test
  • CI green on this PR
  • After merge: confirm GitHub accepts the config at Insights → Dependency graph → Dependabot (a malformed file surfaces as an error there), and that the first weekly PR excludes @n8n/node-cli and n8n-workflow

Dependabot security updates were already enabled (they open PRs on their own,
e.g. #42). What was missing is scheduled VERSION updates, which is why several
pnpm.overrides floors silently went stale for weeks: an upstream would ship an
incremental follow-up fix, the floor would keep resolving to the older
vulnerable version, and nothing refreshed the lockfile until someone looked.
That is how vitest sat three weeks behind a known advisory.

Weekly, grouped so dev-dependency bumps arrive as one PR rather than a dozen.
Uses chore(deps) so routine bumps do not cut a release via release-please.

@n8n/node-cli and n8n-workflow are ignored deliberately. Both are declared "*"
in package.json, so letting Dependabot float them jumps the whole toolchain:
measured at @n8n/node-cli 0.34.0 -> 0.50.3 and ~1982 lockfile lines. CLAUDE.md
pins workflow behaviour to the current CLI, so those two get bumped by hand.

Honest scope limit: this keeps direct devDependencies current and refreshes the
lockfile, but it does not fully automate the override-floor problem.
Transitive versions pinned by pnpm.overrides still need their floors raised
manually, with Dependabot alerts plus `pnpm audit` as the signal. It shrinks
the manual surface rather than removing it.
@github-actions github-actions Bot added the ci CI/CD workflows and repo automation label Sep 30, 2026
@noctisreus
noctisreus merged commit a7bc397 into main Sep 30, 2026
7 checks passed
@noctisreus
noctisreus deleted the ci/add-dependabot-version-updates branch September 30, 2026 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD workflows and repo automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant