Skip to content

chore: configure Dependabot at Yarn lockfile roots - #735

Merged
roncohen merged 1 commit into
mainfrom
fix/dependabot-workspaces
Sep 15, 2026
Merged

roncohen merged 1 commit into
mainfrom
fix/dependabot-workspaces

Conversation

@roncohen

Copy link
Copy Markdown
Contributor

Summary

  • Configure root workspace security updates at / instead of per-workspace manifests.
  • Retain separate update entries only for the two standalone examples with their own yarn.lock.
  • Group Vitest security updates; disable routine version-update PRs to avoid introducing a new backlog.

Validation: inspected workspace membership and all tracked lockfile locations; formatting passed.

This should prevent the manifest-only Next.js PR pattern that failed yarn install --immutable. Dependency migrations still require review, especially Next.js major versions and the Cloudflare worker pool.

Copilot AI lite review requested due to automatic review settings September 15, 2026 09:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@roncohen
roncohen added this pull request to the merge queue Sep 15, 2026
Merged via the queue into main with commit 97a7431 Sep 15, 2026
7 of 8 checks passed
@roncohen
roncohen deleted the fix/dependabot-workspaces branch September 15, 2026 09:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants