chore(deps): add dependabot version updates for the five npm lockfiles - #2312
Merged
Merged
Conversation
The repo has five committed pnpm lockfiles (`/site`, `/crates/bashkit-js`, `/examples`, `/examples/browser`, `/examples/bashkit-pi`) and none of them had an `updates:` entry, so nothing kept them fresh. This is separate from Dependabot alerts and security updates, which run off the dependency graph and need no config — those already saw these trees. The gap is routine freshness: without version updates a tree drifts until the eventual security bump is a multi-major jump that cannot be landed quickly. `/site` is the sharpest case, since it is a deployed Cloudflare Worker. All five trees audit clean today (`pnpm audit`: 0 vulnerabilities across 983 resolved dependencies), so this is preventative, not a fix. One grouped entry per lockfile, matching the cargo entries' shape, so a week of bumps arrives as a single reviewable PR. `@everruns/*` is ignored everywhere: those are this repo's own published packages, pinned to the workspace version by the release process, and letting dependabot move them independently races it. Records the coverage table and the deliberate exclusions (`.deepsec/`, `crates/bashkit-wasm`, Python) in knowledge/operations/maintenance.md.
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
bashkit | 758dbad | Commit Preview URL Branch Preview URL |
Aug 19 2026, 09:13 AM |
chaliy
pushed a commit
that referenced
this pull request
Aug 19, 2026
First bump surfaced by the npm dependabot coverage added in #2312, and a two-major jump — exactly the drift that coverage was meant to stop accumulating. No CI job builds examples/browser, so the green checks on this PR say nothing about it. Verified by hand under Node 22 instead: - pnpm install --frozen-lockfile: clean, vite 8.2.1 - npx vite build: 8 modules transformed, wasm asset emitted (dist/assets/bashkit_wasm_bg-*.wasm 8,016 kB), built in 477ms - npx vite (dev server): ready in 346ms, GET / returns HTTP 200 with the demo page - node --test *.test.js: 8 of 9 pass The one failing test, dependency-security.test.js "dependencies are reproducible", fails identically on main: it requires exact versions and package.json already carried "vite": "^6.4.3". This PR keeps the caret rather than introducing it. Tracked as a follow-up, together with the reason nobody noticed — nothing in CI runs that suite.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Dependabot now opens weekly version-update PRs for the repo's five committed
pnpm lockfiles, which previously had no
updates:entry at all:site-npm/sitejs-npm/crates/bashkit-jsexamples-npm/examples,/examples/browser,/examples/bashkit-piOne grouped PR per entry per week,
chore(deps)prefix — the same shape as theexisting cargo entries, so this adds three PRs a week at most, not thirty.
@everruns/*is ignored in every entry. Those are this repo's own publishedpackages, pinned to the workspace version (
0.16.0) insite/package.jsonandexamples/browser/package.jsonand bumped by the release process. Dependabotmoving them independently would race that process and produce PRs that go stale
the moment a release lands.
knowledge/operations/maintenance.mdgains the coverage table and, moreusefully, the deliberate exclusions:
crates/bashkit-wasm(apackage.jsonwith no dependencies and no lockfile),
.deepsec/(updated by hand during thesecurity pass, because the scan runs against whatever version that pass pulls),
and Python (
pyproject.tomldeclares only optional extras with open>=boundsand no lockfile, so a pip entry would have nothing to pin).
Why
This is not about Dependabot alerts. Alerts and security updates run off the
repository dependency graph and need no config — they already saw these trees.
The gap is routine freshness, and the two interact: an ecosystem that only ever
moves when an advisory forces it drifts until the fix is a multi-major jump that
can't be landed under time pressure.
/siteis the sharpest case, being adeployed Cloudflare Worker and the only npm surface here reachable from the
public internet at runtime.
The cargo and github-actions ecosystems have had this coverage since the config
was written; npm was simply never added as the JS surface grew from one package
to five.
Before / After
Preventative, not a fix — all five trees are clean as of this commit:
Config coverage before → after:
Knowledge checks pass:
Risk
plus a knowledge doc.
/examples(ai,openai,@langchain/*). Grouping holds that to one PR aweek; if it still proves noisy, that entry can move to
monthlywithoutaffecting the other two.
directories(plural) is used for the examples entry. It is currentDependabot v2 syntax and the file parses as valid YAML, but unlike the rest of
this repo's CI it is only truly exercised once Dependabot next runs — worth a
glance at the Dependabot job log after merge.
Checklist
just check-okf,just check-doc-links, and a YAML schema parse of the configand github-actions entries are untouched
Generated by Claude Code