From b63c1e06fc30746f2a9cf30e6b0a9e83030a2b30 Mon Sep 17 00:00:00 2001 From: Kyle Tully Date: Wed, 30 Sep 2026 16:03:12 -0400 Subject: [PATCH] ci: add dependabot.yml for scheduled npm version updates Dependabot security updates were already enabled (they open PRs on their own, e.g. #42). What was missing is scheduled VERSION updates, which is why several pnpm.overrides floors silently went stale for weeks: an upstream would ship an incremental follow-up fix, the floor would keep resolving to the older vulnerable version, and nothing refreshed the lockfile until someone looked. That is how vitest sat three weeks behind a known advisory. Weekly, grouped so dev-dependency bumps arrive as one PR rather than a dozen. Uses chore(deps) so routine bumps do not cut a release via release-please. @n8n/node-cli and n8n-workflow are ignored deliberately. Both are declared "*" in package.json, so letting Dependabot float them jumps the whole toolchain: measured at @n8n/node-cli 0.34.0 -> 0.50.3 and ~1982 lockfile lines. CLAUDE.md pins workflow behaviour to the current CLI, so those two get bumped by hand. Honest scope limit: this keeps direct devDependencies current and refreshes the lockfile, but it does not fully automate the override-floor problem. Transitive versions pinned by pnpm.overrides still need their floors raised manually, with Dependabot alerts plus `pnpm audit` as the signal. It shrinks the manual surface rather than removing it. --- .github/dependabot.yml | 37 +++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..2e38c74 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,37 @@ +# Dependabot SECURITY updates are already enabled for this repo (they open PRs on +# their own). What was missing is scheduled VERSION updates, which is why several +# pnpm.overrides floors silently went stale for weeks: an upstream would ship an +# incremental follow-up fix, the floor would keep resolving to the older +# vulnerable version, and nothing refreshed the lockfile until someone looked. +# +# Scope note: this keeps DIRECT devDependencies current and refreshes the +# lockfile. It does NOT fully automate the override-floor problem — transitive +# versions pinned by pnpm.overrides still need their floors raised by hand, with +# Dependabot alerts plus `pnpm audit` as the signal. It shrinks the manual +# surface; it does not remove it. +version: 2 +updates: + - package-ecosystem: npm + directory: "/" + schedule: + interval: weekly + day: monday + open-pull-requests-limit: 5 + commit-message: + # Conventional Commits: release-please reads these. Use chore(deps) so + # routine dependency bumps do not cut a release on their own. + prefix: chore + prefix-development: chore + include: scope + groups: + dev-dependencies: + dependency-type: development + patterns: + - "*" + ignore: + # Both are declared "*" in package.json, so letting Dependabot float them + # jumps the entire toolchain — measured at @n8n/node-cli 0.34.0 -> 0.50.3 + # and ~1982 lockfile lines in testing. CLAUDE.md pins workflow behaviour to + # the current CLI. Bump these deliberately, never automatically. + - dependency-name: "@n8n/node-cli" + - dependency-name: "n8n-workflow"