Repository navigation
ci: enable Dependabot version updates for pnpm and actions - #115
Conversation
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
@codex review |
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
|
Summary
Part of VOL-1094 (epic VOL-1077). volcano-agentic-plugins had no Dependabot config, so
pnpm-lock.yamland the pinned actions only moved when someone bumped them by hand. This adds.github/dependabot.yml.npm (pnpm workspace)
directory: "/"). Dependabot readspnpm-workspace.yaml(packages/*,plugins/*), so it covers the root,packages/coreandplugins/vscodeagainst the single lockfile.10.33.0is within Dependabot's supported v7–v10. Its npm updater image runs Node 24, which satisfiesengines.node.open-pull-requests-limit: 5. Minor and patch updates are grouped into onenpm-minor-patchPR, and each major gets its own PR.fix(deps): …when a runtime dependency changes, because it ships in the bundled plugins and release-please releasesfix. Build and test tooling getschore(deps-dev): …, which release-please hides, so tooling bumps stay out of releases and the changelog. Today every third-party dependency is a devDependency, so updates arrive aschore(deps-dev).@types/vscodemust not exceedengines.vscode(^1.85.0). Dependabot's defaultincreasestrategy would rewrite it to^1.140.0, vsce would refuse to package, and the grouped PR would failvalidate. Raise both together when the minimum VS Code version moves.@types/node, which tracks the Node 24 engine.esbuildoverride inpackage.jsonis a range (>=0.25.0), not a pin, so Dependabot bumps still move the lockfile and are not no-ops.Synced and vendored content is not bumped
gitsubmoduleentry.sync-skills.ymlmovessources/volcano-skillstogether with the materialized copies, and a bare gitlink bump would failcheck:skill-drift.plugins/<ide>/skillsare byte-identical copies of volcano-skills with no manifests. They aren't workspace packages, and the Actions entry only reads.github/workflows. volcano-skills' own.github/(including its newdependabot.yml) is excluded bysync-skills-from-source.mjs.tests/e2e-agent-evalis local test tooling outside the workspace with no lockfile. Its^1.4.1SDK range already resolves to the latest 1.x on install.github-actions
/(there are no composite actions under.github/actions).default-daysonly). Minor and patch updates are grouped, majors get their own PRs, and titles areci(deps): ….Labels: this repo has no dependency labels, so
labels: []stops Dependabot creating its defaults.Status (read-only, not changed here)
pnpm-lock.yaml(brace-expansion,braces,fast-uri,js-yaml,linkify-it,markdown-it,qs,undici), and Dependabot has never opened a PR here. The security-update runs may be failing; Insights → Dependency graph → Dependabot shows their logs. Version updates for npm only bump direct dependencies, so they won't clear these on their own.Validation
check-jsonschema --schemafile https://json.schemastore.org/dependabot-2.0.json .github/dependabot.yml: ok.chore(deps-dev): bump @vscode/vsce from 3.9.2 to 4.0.0,fix(deps): bump next from 16.3.8 to 17.0.0,ci(deps): bump actions/checkout from 5.1.0 to 6.0.0) pass commitlintconfig-conventional.packageManager: it parses onlydependencies,devDependenciesandoptionalDependencies(plus pnpm catalogs). The pinnedversion: 10.33.0inputs topnpm/action-setuptherefore stay in step with it.Notes for reviewers
validate,ci.yml'sauto-fix-skill-driftjob also runs. It mints its token before checking the cause, and Dependabot-triggered runs can't readsecrets.VOLCANO_APP_KEY, so it adds a second red job. If the failure is skill drift because volcano-skills moved upstream, comment@dependabot rebaseafter the daily sync lands onmain.pnpm update esbuild@0.28.2 --lockfile-only --no-save -r, thenpnpm install --lockfile-only) moved the lockfile from 0.28.1 to 0.28.2.@types/vscodealready resolves to 1.125.0 under the^1.85.0range, so typecheck allows APIs newer than the minimum VS Code. Pinning it to~1.85.0would enforce the engine floor, but that's a separate change.🤖 Generated with Claude Code