Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 30 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
# Keeps the dependencies current without anyone remembering to.
#
# One pull request a week per ecosystem, with the npm updates grouped: a
# week's worth of bumps is one change to read and one CI run to trust, where
# a pull request per package is a queue nobody works through. The runner
# image is not pinned for the same reason -- `ubuntu-latest` moves on its
# own, and the CI run is what says whether the move held.
version: 2
updates:
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
commit-message:
prefix: "[TASK]"

- package-ecosystem: npm
directory: /
schedule:
interval: weekly
commit-message:
prefix: "[TASK]"
groups:
dependencies:
patterns: ["*"]
ignore:
# The types describe the Node the tool targets -- the current LTS -- and
# move when that target does, not when a newer major is published.
- dependency-name: "@types/node"
update-types: ["version-update:semver-major"]
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ jobs:
steps:
- uses: actions/checkout@v7

- uses: actions/setup-node@v6
- uses: actions/setup-node@v7
with:
node-version-file: .nvmrc
cache: npm
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,9 +23,9 @@ jobs:
with:
fetch-depth: 0

# v6 is the first that carries out the trusted-publishing handshake, and
# v6 was the first that carries out the trusted-publishing handshake, and
# npm has to be 11.5.1 or newer to understand it — Node 24 brings one.
- uses: actions/setup-node@v6
- uses: actions/setup-node@v7
with:
node-version-file: .nvmrc
registry-url: https://registry.npmjs.org
Expand Down
14 changes: 14 additions & 0 deletions MAINTAINERS.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,20 @@ Nothing checks these, so look at them. `KEEP=1 npm run screenshots` leaves the
run behind and prints where, which is how to open the report the pictures came
from.

## Keeping the dependencies current

Dependabot opens one pull request a week per ecosystem — the npm updates
grouped into one, the GitHub Actions on their own — from
[`.github/dependabot.yml`](.github/dependabot.yml). Merge it when CI is green;
that run is the review. Two things are deliberate about it:

- `@types/node` is held to the major of the Node the tool targets, the current
LTS, and moves when that target does. A newer major would let code compile
against APIs the target does not have.
- The workflows run on `ubuntu-latest` rather than a named image, so the
runner moves on its own too, and the CI run is what says whether the move
held.

## Cutting a release

Publishing runs on npm's trusted publishing: the workflow proves who it is with
Expand Down
Loading
Loading