diff --git a/.github/dependabot.yml b/.github/dependabot.yml index fcd4a579f..d82bd615d 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -96,6 +96,14 @@ updates: - "version-update:semver-major" - "version-update:semver-minor" - "version-update:semver-patch" + # TypeScript majors must land with the lint toolchain: + # @typescript-eslint/eslint-plugin@8.70.0, @typescript-eslint/parser@8.70.0 + # and typescript-eslint@8.70.0 each declare a peer dependency of + # "typescript": ">=4.8.4 <6.1.0". Keep TypeScript majors as explicit work + # rather than opening proposals the checked-in toolchain cannot build. + - dependency-name: "typescript" + update-types: + - "version-update:semver-major" - package-ecosystem: "docker" directories: diff --git a/scripts/tests/test_dependabot_config.py b/scripts/tests/test_dependabot_config.py index ce8b6a180..2052a3af9 100644 --- a/scripts/tests/test_dependabot_config.py +++ b/scripts/tests/test_dependabot_config.py @@ -148,9 +148,16 @@ class DependabotConfigTest(unittest.TestCase): } self.assertEqual( set(ignored), - {"playwright", "playwright-core", "@playwright/test"}, + {"playwright", "playwright-core", "@playwright/test", "typescript"}, + ) + for browser_runtime in ("playwright", "playwright-core", "@playwright/test"): + self.assertEqual(ignored[browser_runtime], all_semver) + # TypeScript majors must land with the @typescript-eslint peer range + # (">=4.8.4 <6.1.0"), so keep them as explicit work. + self.assertEqual( + ignored["typescript"], + {"version-update:semver-major"}, ) - self.assertTrue(all(types == all_semver for types in ignored.values())) def test_weekly_scan_covers_the_same_lockfiles(self) -> None: workflow = yaml.safe_load(SECURITY_SCAN.read_text(encoding="utf-8"))