From dc42735008311bbf0aca840c6b83b6bd25b4d7ee Mon Sep 17 00:00:00 2001 From: "pulse-triage[bot]" <249995291+pulse-triage[bot]@users.noreply.github.com> Date: Wed, 23 Sep 2026 06:32:54 +0100 Subject: [PATCH] chore(deps): keep TypeScript majors as explicit Dependabot work Dependabot #2100 and #2101 propose TypeScript 5.9.3 -> 7.0.2, but the checked-in @typescript-eslint/eslint-plugin@8.70.0, @typescript-eslint/parser@8.70.0 and typescript-eslint@8.70.0 each declare a peer dependency of "typescript": ">=4.8.4 <6.1.0". The proposals therefore fail ERESOLVE and all frontend E2E shards, with no security advisory behind them. Add a semver-major ignore for typescript in the npm ecosystem so majors stay explicit work alongside a lint-toolchain upgrade, and update the config guard test to pin both the browser-runtime and TypeScript ignores. Change-source: pulse-maintainer --- .github/dependabot.yml | 8 ++++++++ scripts/tests/test_dependabot_config.py | 11 +++++++++-- 2 files changed, 17 insertions(+), 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index fcd4a579f..d82bd615d 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -96,6 +96,14 @@ updates: - "version-update:semver-major" - "version-update:semver-minor" - "version-update:semver-patch" + # TypeScript majors must land with the lint toolchain: + # @typescript-eslint/eslint-plugin@8.70.0, @typescript-eslint/parser@8.70.0 + # and typescript-eslint@8.70.0 each declare a peer dependency of + # "typescript": ">=4.8.4 <6.1.0". Keep TypeScript majors as explicit work + # rather than opening proposals the checked-in toolchain cannot build. + - dependency-name: "typescript" + update-types: + - "version-update:semver-major" - package-ecosystem: "docker" directories: diff --git a/scripts/tests/test_dependabot_config.py b/scripts/tests/test_dependabot_config.py index ce8b6a180..2052a3af9 100644 --- a/scripts/tests/test_dependabot_config.py +++ b/scripts/tests/test_dependabot_config.py @@ -148,9 +148,16 @@ class DependabotConfigTest(unittest.TestCase): } self.assertEqual( set(ignored), - {"playwright", "playwright-core", "@playwright/test"}, + {"playwright", "playwright-core", "@playwright/test", "typescript"}, + ) + for browser_runtime in ("playwright", "playwright-core", "@playwright/test"): + self.assertEqual(ignored[browser_runtime], all_semver) + # TypeScript majors must land with the @typescript-eslint peer range + # (">=4.8.4 <6.1.0"), so keep them as explicit work. + self.assertEqual( + ignored["typescript"], + {"version-update:semver-major"}, ) - self.assertTrue(all(types == all_semver for types in ignored.values())) def test_weekly_scan_covers_the_same_lockfiles(self) -> None: workflow = yaml.safe_load(SECURITY_SCAN.read_text(encoding="utf-8"))