chore(deps): keep TypeScript majors as explicit Dependabot work

Dependabot #2100 and #2101 propose TypeScript 5.9.3 -> 7.0.2, but the checked-in @typescript-eslint/eslint-plugin@8.70.0, @typescript-eslint/parser@8.70.0 and typescript-eslint@8.70.0 each declare a peer dependency of "typescript": ">=4.8.4 <6.1.0". The proposals therefore fail ERESOLVE and all frontend E2E shards, with no security advisory behind them.

Add a semver-major ignore for typescript in the npm ecosystem so majors stay explicit work alongside a lint-toolchain upgrade, and update the config guard test to pin both the browser-runtime and TypeScript ignores.

Change-source: pulse-maintainer
This commit is contained in:
pulse-triage[bot] 2026-09-23 06:32:54 +01:00
parent 064e776dd0
commit dc42735008
2 changed files with 17 additions and 2 deletions

View file

@ -96,6 +96,14 @@ updates:
- "version-update:semver-major"
- "version-update:semver-minor"
- "version-update:semver-patch"
# TypeScript majors must land with the lint toolchain:
# @typescript-eslint/eslint-plugin@8.70.0, @typescript-eslint/parser@8.70.0
# and typescript-eslint@8.70.0 each declare a peer dependency of
# "typescript": ">=4.8.4 <6.1.0". Keep TypeScript majors as explicit work
# rather than opening proposals the checked-in toolchain cannot build.
- dependency-name: "typescript"
update-types:
- "version-update:semver-major"
- package-ecosystem: "docker"
directories:

View file

@ -148,9 +148,16 @@ class DependabotConfigTest(unittest.TestCase):
}
self.assertEqual(
set(ignored),
{"playwright", "playwright-core", "@playwright/test"},
{"playwright", "playwright-core", "@playwright/test", "typescript"},
)
for browser_runtime in ("playwright", "playwright-core", "@playwright/test"):
self.assertEqual(ignored[browser_runtime], all_semver)
# TypeScript majors must land with the @typescript-eslint peer range
# (">=4.8.4 <6.1.0"), so keep them as explicit work.
self.assertEqual(
ignored["typescript"],
{"version-update:semver-major"},
)
self.assertTrue(all(types == all_semver for types in ignored.values()))
def test_weekly_scan_covers_the_same_lockfiles(self) -> None:
workflow = yaml.safe_load(SECURITY_SCAN.read_text(encoding="utf-8"))