Skip to content

chore: remove dependabot - #22

Merged
tjklint merged 2 commits into
mainfrom
fix/dependabot-bun-ecosystem
Sep 26, 2026
Merged

tjklint merged 2 commits into
mainfrom
fix/dependabot-bun-ecosystem

Conversation

@tjklint

@tjklint tjklint commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Remove dependabot, so dependency bumps are deliberate.

tjklint and others added 2 commits September 26, 2026 16:15
Removes .github/dependabot.yml rather than repointing it at the bun
ecosystem.

The config was left on package-ecosystem 'npm' by the pnpm-to-bun move,
which is broken: the npm ecosystem updates package.json and leaves
bun.lock alone, and CI runs bun install --frozen-lockfile. Verified by
simulating the bot's change --

  $ bun install --frozen-lockfile
  error: lockfile had changes, but lockfile is frozen
  EXIT CODE: 1

-- so every dependabot PR would have failed CI.

Switching to 'bun' would fix that, but not immediately: dependabot's
updater image ships bun 1.3.14, which reads only lockfileVersion 1,
while our bun.lock is version 2 written by bun 1.4. Until
dependabot-core#16071 lands, that config produces no updates at all --
silently. Deleting the file avoids both the broken state and the silent
one, and there are only seven dependencies to track by hand.

Cost of removing: we also lose the github-actions ecosystem entry, which
was working and would have flagged updates for actions/checkout@v4 and
oven-sh/setup-bun@v2. Bump those deliberately; they move rarely.

bun outdated covers the dependency side locally:

  $ bun outdated

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Removes the last automated updater, so AGENTS.md should say where to
look instead. Points at bun outdated for packages, and at the workflow
file by eye for the pinned action versions, which nothing watches now.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@tjklint
tjklint merged commit 8fb51fc into main Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant