Skip to content

chore: pause Dependabot bun updates until lockfile v2 works - #159

Merged
CuriosityOS merged 1 commit into
mainfrom
cursor/dependabot-bun-lockfile-247c
Sep 3, 2026
Merged

CuriosityOS merged 1 commit into
mainfrom
cursor/dependabot-bun-lockfile-247c

Conversation

@CuriosityOS

Copy link
Copy Markdown
Collaborator

What and why

The 2.2.0 Dependabot check on main failed because GitHub's bun updater still ships Bun 1.3.14, which rejects bun.lock lockfileVersion 2 (Unsupported bun.lock 'lockfileVersion' 2). Bun 1.4.0 writes v2. Project CI on that commit was green; only the Dependabot job was red.

Pause the bun ecosystem until dependabot/dependabot-core#16026 / #16071 ship. Action-pin updates stay on. Do not fall back to npm: CI uses bun install --frozen-lockfile, so a package.json-only bump would fail.

Checklist

  • bun run release:check is unrelated to this change (Dependabot YAML only; parsed with Python's PyYAML).
  • Every browser connection still goes through the guard proxy. No launch, transport, or fetch change.
  • No secret value reaches the model sandbox. No new output channel.
  • Dependency pins are still mirrored everywhere. The ignore list for playwright-core, tldts, and patchright-core is kept in the commented restore block.
  • Public API changes update types/*.d.ts in this same commit. No public API change.
  • The two branch-protected CI job names, "Worker copies in sync" and "Node tests", are unchanged, and no new action was added.
  • No unit test imports src/worker.ts or dist/src/worker.js directly.
  • User-visible behaviour is unchanged, so CHANGELOG.md is not updated.
  • Nothing private is being committed.

How it was verified

  • Failed job: Dependabot Updates run 33724445961 on b65ce1c (release: 2.2.0).
  • Error: Unsupported bun.lock 'lockfileVersion' 2 in /bun.lock. The bun version Dependabot runs supports up to 1.
  • python3 -c 'import yaml; yaml.safe_load(open(".github/dependabot.yml"))' — only github-actions remains active.
Open in Web Open in Cursor 

GitHub's bun updater still ships Bun 1.3.14 and rejects bun.lock
lockfileVersion 2, which 1.4.0 writes. That failed the Dependabot
check on every main push after 2.2.0. Keep action-pin updates, and
restore the bun block once dependabot-core can read v2.

Co-authored-by: Nav <CuriosityOS@users.noreply.github.com>
@CuriosityOS
CuriosityOS marked this pull request as ready for review September 3, 2026 07:17
@greptile-apps

greptile-apps Bot commented Sep 3, 2026

Copy link
Copy Markdown

Greptile Summary

This change pauses Dependabot’s Bun dependency updates until its runtime supports the repository’s lockfile format, while retaining weekly GitHub Actions dependency updates. The configuration was parsed and compared with the prior version: GitHub Actions remains active weekly, and no active Bun updater remains.

Confidence Score: 5/5

Safe to merge based on the validated Dependabot configuration behavior.

The modified YAML was checked against the prior configuration and correctly preserves GitHub Actions updates while disabling only the Bun updater.

Files Needing Attention: No files need further attention.

T-Rex T-Rex Logs

What T-Rex did

  • The validation script was run against the baseline Dependabot YAML and confirmed that it parsed with active GitHub Actions and Bun updates.
  • The validation script was run against the current Dependabot YAML and confirmed that it parses, retains weekly GitHub Actions updates, has no active Bun updater, and the Bun block remains commented.

View all artifacts

T-Rex Ran code and verified through T-Rex

Reviews (1): Last reviewed commit: "chore: pause Dependabot bun updates unti..." | Re-trigger Greptile

@CuriosityOS
CuriosityOS merged commit e89f34e into main Sep 3, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants