Skip to content

chore(deps): freeze the paired/pinned deps out of dependabot groups - #12329

Merged
diegosouzapw merged 1 commit into
release/v3.8.51from
chore/dependabot-freeze-paired-deps
Sep 1, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.51from
chore/dependabot-freeze-paired-deps

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Both open dependabot group PRs are born red on deliberate contract tests:

This adds the two ignores (with rationale comments) so the groups recreate clean. After merge, @dependabot recreate on both PRs drops the offending packages and the remaining 14+11 healthy bumps can land.

…t of dependabot groups

onnxruntime-node only ever moves paired with @huggingface/transformers (already
frozen, #9962/#4050) — a solo bump breaks the single-copy ABI contract test and
reds every production-group PR. eslint-plugin-react-hooks stays pinned to 7.0.1
by a contract test until the 7.1.1 rule set is adopted in its own PR (the
#12146 migration completed today, so that adoption is now unblocked).
@diegosouzapw

Copy link
Copy Markdown
Owner Author

Merging with --admin: the 4 red checks on this PR's merge-ref are the 2026-09-01 base-red window (stream-utils / settings-i18n-keys / placeholder-fallback / dead collectSSE — all reproduced on the pure base tip, fix in flight in #12327). This diff is a single dependabot config file no test exercises; none of the reds can be caused by it.

@diegosouzapw
diegosouzapw merged commit 8ef3447 into release/v3.8.51 Sep 1, 2026
17 of 21 checks passed
@diegosouzapw
diegosouzapw deleted the chore/dependabot-freeze-paired-deps branch September 2, 2026 05:54
diegosouzapw added a commit that referenced this pull request Sep 2, 2026
* chore(lint): adopt eslint-plugin-react-hooks 7.1.1

The #12146 migration (284 react-hooks compiler-rule violations resolved in 8
batches) completed on 2026-09-01, unblocking the 7.1.1 adoption the pin test
was holding back. Exact pin kept in both devDependencies and overrides; the
pin test moves to 7.1.1 (the dependabot-level ignore from #12329 stays — a
lint plugin coupled to the compiler rules always bumps via its own reviewed
PR, never riding a group).

* chore(lint): lockfile for the react-hooks 7.1.1 adoption

Generated with a bare 'npm install --package-lock-only' (naming the package
on the CLI rewrites the devDependency with a caret, which npm 11 then rejects
against the exact override). Validated on the .113 with a fresh npm ci +
cold NODE_OPTIONS=8G lint:json --max-warnings 0 → exit 0 (zero new
violations from the 7.1.1 rule set) and the re-pinned version test green.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…t of dependabot groups (diegosouzapw#12329)

onnxruntime-node only ever moves paired with @huggingface/transformers (already
frozen, diegosouzapw#9962/diegosouzapw#4050) — a solo bump breaks the single-copy ABI contract test and
reds every production-group PR. eslint-plugin-react-hooks stays pinned to 7.0.1
by a contract test until the 7.1.1 rule set is adopted in its own PR (the
diegosouzapw#12146 migration completed today, so that adoption is now unblocked).
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
* chore(lint): adopt eslint-plugin-react-hooks 7.1.1

The diegosouzapw#12146 migration (284 react-hooks compiler-rule violations resolved in 8
batches) completed on 2026-09-01, unblocking the 7.1.1 adoption the pin test
was holding back. Exact pin kept in both devDependencies and overrides; the
pin test moves to 7.1.1 (the dependabot-level ignore from diegosouzapw#12329 stays — a
lint plugin coupled to the compiler rules always bumps via its own reviewed
PR, never riding a group).

* chore(lint): lockfile for the react-hooks 7.1.1 adoption

Generated with a bare 'npm install --package-lock-only' (naming the package
on the CLI rewrites the devDependency with a caret, which npm 11 then rejects
against the exact override). Validated on the .113 with a fresh npm ci +
cold NODE_OPTIONS=8G lint:json --max-warnings 0 → exit 0 (zero new
violations from the 7.1.1 rule set) and the re-pinned version test green.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant