chore(deps): switch Dependabot from npm to bun ecosystem - #27
Merged
Conversation
Dependabot's npm ecosystem updates package.json but leaves bun.lock untouched, so every Dependabot PR here fails CI on `bun install --frozen-lockfile` until someone regenerates the lockfile by hand. The bun ecosystem updates the lockfile in the same PR. Proven out on the viewer repo (viewer#3), where subsequent Dependabot PRs have gone green without manual work.
Contributor
|
Need an experimental publish for this PR? Add the While the label is present, every push publishes fresh canaries with the |
scottbenton
approved these changes
Jul 31, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dependabot on the
npmecosystem updatespackage.jsonbut leavesbun.lockuntouched, so every Dependabot PR here fails CI onbun install --frozen-lockfileand needs a manual lockfile regeneration.Most recent instance: community-content#8 (starforged 0.2.2 → 0.2.4) — the commit changed exactly one file,
package.json, and the build died at the install step.The
bunecosystem updates the lockfile in the same PR. This was proven out on the viewer repo in viewer#3; the Dependabot PRs it has produced since (viewer#6) go green with no manual work.One-line change, no behavior change beyond the lockfile being included.