Repository navigation
chore: pause Dependabot bun updates until lockfile v2 works - #159
Merged
Merged
Conversation
GitHub's bun updater still ships Bun 1.3.14 and rejects bun.lock lockfileVersion 2, which 1.4.0 writes. That failed the Dependabot check on every main push after 2.2.0. Keep action-pin updates, and restore the bun block once dependabot-core can read v2. Co-authored-by: Nav <CuriosityOS@users.noreply.github.com>
CuriosityOS
marked this pull request as ready for review
September 3, 2026 07:17
Greptile SummaryThis change pauses Dependabot’s Bun dependency updates until its runtime supports the repository’s lockfile format, while retaining weekly GitHub Actions dependency updates. The configuration was parsed and compared with the prior version: GitHub Actions remains active weekly, and no active Bun updater remains. Confidence Score: 5/5Safe to merge based on the validated Dependabot configuration behavior. The modified YAML was checked against the prior configuration and correctly preserves GitHub Actions updates while disabling only the Bun updater. Files Needing Attention: No files need further attention.
What T-Rex did
Reviews (1): Last reviewed commit: "chore: pause Dependabot bun updates unti..." | Re-trigger Greptile |
4 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
The 2.2.0 Dependabot check on
mainfailed because GitHub's bun updater still ships Bun 1.3.14, which rejectsbun.locklockfileVersion2 (Unsupported bun.lock 'lockfileVersion' 2). Bun 1.4.0 writes v2. Project CI on that commit was green; only the Dependabot job was red.Pause the
bunecosystem until dependabot/dependabot-core#16026 / #16071 ship. Action-pin updates stay on. Do not fall back tonpm: CI usesbun install --frozen-lockfile, so apackage.json-only bump would fail.Checklist
bun run release:checkis unrelated to this change (Dependabot YAML only; parsed with Python's PyYAML).types/*.d.tsin this same commit. No public API change.src/worker.tsordist/src/worker.jsdirectly.CHANGELOG.mdis not updated.How it was verified
b65ce1c(release: 2.2.0).Unsupported bun.lock 'lockfileVersion' 2 in /bun.lock. The bun version Dependabot runs supports up to 1.python3 -c 'import yaml; yaml.safe_load(open(".github/dependabot.yml"))'— onlygithub-actionsremains active.