ci(deps): split sensitive dependency updates (#1409)

This commit is contained in:
4gray authored and GitHub committed 2026-08-11 02:56:50 +02:00
1 parent 73f6eb9b17
commit 861c6798ee
2 files changed
+16 -3

No files matched your search

+11 -3
View File
@@ -1,8 +1,10 @@
# Every Dependabot PR triggers the full pipeline (~15 jobs), so version
# updates are batched weekly. Nx minor+patch updates use a dedicated group so
# official packages move together; Nx majors are manual coordinated migrations,
# and other minor+patch updates are grouped per ecosystem. Security updates are
# separate and are not limited by this schedule; CI enforces complete Nx lockstep.
# official packages move together; Nx majors are manual coordinated migrations.
# Native packaging, parser, and version-locked playback dependencies stay in
# standalone PRs; other minor+patch updates are grouped per ecosystem. Security
# updates are separate and are not limited by this schedule; CI enforces complete
# Nx lockstep.
version: 2
updates:
- package-ecosystem: npm
@@ -36,8 +38,14 @@ updates:
npm-minor-patch:
applies-to: version-updates
exclude-patterns:
- better-sqlite3
- electron
- electron-builder
- epg-parser
- mpegts.js
- nx
- '@nx/*'
- shaka-player
update-types:
- minor
- patch
+5
View File
@@ -324,6 +324,11 @@ Toolchain notes for the Electron 41 upgrade:
carries the v26 backport that fully extracts the Snap template's `.tar.7z`
payload; 26.15.0–26.15.6 can
produce a Snap that is missing `desktop-init.sh`. CI already runs Node 22.
4. Dependabot keeps Electron, native database, packaging, EPG parser, and
version-locked Shaka/mpegts updates out of the shared npm minor/patch group.
Those dependencies require standalone PRs so their dedicated package,
worker, playback, and diagnostic-contract validation cannot be hidden by an
unrelated grouped update.
Known caveats: