From 2b0ff8dd0ee821e792ee0d5d7e35a1046467eab4 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Thu, 3 Sep 2026 07:10:53 +0000 Subject: [PATCH] chore: pause Dependabot bun updates until lockfile v2 works GitHub's bun updater still ships Bun 1.3.14 and rejects bun.lock lockfileVersion 2, which 1.4.0 writes. That failed the Dependabot check on every main push after 2.2.0. Keep action-pin updates, and restore the bun block once dependabot-core can read v2. Co-authored-by: Nav --- .github/dependabot.yml | 28 ++++++++++++++++++---------- 1 file changed, 18 insertions(+), 10 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 0b49a5ec..8398a145 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -13,13 +13,21 @@ updates: # full rationale lives in scripts/check-versions.ts). Those bumps must be # deliberate, so Dependabot only proposes devDependency updates, and the # ignore list restates the pinned three in case the allow scope ever widens. - - package-ecosystem: bun - directory: / - schedule: - interval: weekly - allow: - - dependency-type: development - ignore: - - dependency-name: playwright-core - - dependency-name: tldts - - dependency-name: patchright-core + # + # The bun updater is paused. GitHub's image still ships Bun 1.3.14, which + # rejects bun.lock lockfileVersion 2 (Dependabot::DependencyFileNotSupported + # on every main push after 2.2.0). Bun 1.4.0 writes v2 by default. Track + # dependabot/dependabot-core#16026 and #16071. Restore the block below once + # that image can read v2. Do not switch this back to npm: CI installs with + # `bun install --frozen-lockfile`, so a package.json-only bump would fail. + # + # - package-ecosystem: bun + # directory: / + # schedule: + # interval: weekly + # allow: + # - dependency-type: development + # ignore: + # - dependency-name: playwright-core + # - dependency-name: tldts + # - dependency-name: patchright-core