build(deps): pin Playwright to the offline browser runtime line

The npm-minor-patch group (Dependabot #2115) has been held since 17 Sep
because it bundles @playwright/test, playwright and playwright-core
1.56.1 -> 1.63.0 with 12 safe frontend updates. The offline
browser-verification runtime is pinned to Playwright 1.56.1, so a lockfile
bump breaks browser-proof parity; holding the whole group blocked the safe
updates instead.

Ignore Playwright version updates on the governed 1.56.1 line, matching the
docker governed-tag policy, so the remaining grouped updates can be reviewed
on their own. Security updates stay covered by the weekly npm-audit scan and
the frontend dependencySecurity proof. Extend the dependabot config guard to
lock the policy in.

Change-source: pulse-maintainer
This commit is contained in:
pulse-triage[bot] 2026-09-20 03:23:38 +01:00
parent 042431dd20
commit fbfa870b95
2 changed files with 36 additions and 0 deletions

View file

@ -76,6 +76,26 @@ updates:
applies-to: "security-updates"
patterns:
- "*"
# The offline browser-verification runtime is pinned to Playwright 1.56.1,
# so frontend browser proofs require lockfile parity. Keep Playwright on the
# governed 1.56.1 line; review upgrades as explicit work alongside a runtime
# change, matching the docker governed-tag policy.
ignore:
- dependency-name: "playwright"
update-types:
- "version-update:semver-major"
- "version-update:semver-minor"
- "version-update:semver-patch"
- dependency-name: "playwright-core"
update-types:
- "version-update:semver-major"
- "version-update:semver-minor"
- "version-update:semver-patch"
- dependency-name: "@playwright/test"
update-types:
- "version-update:semver-major"
- "version-update:semver-minor"
- "version-update:semver-patch"
- package-ecosystem: "docker"
directories:

View file

@ -136,6 +136,22 @@ class DependabotConfigTest(unittest.TestCase):
],
)
def test_npm_updates_preserve_browser_runtime_parity(self) -> None:
all_semver = {
"version-update:semver-major",
"version-update:semver-minor",
"version-update:semver-patch",
}
ignored = {
item["dependency-name"]: set(item["update-types"])
for item in self.updates["npm"]["ignore"]
}
self.assertEqual(
set(ignored),
{"playwright", "playwright-core", "@playwright/test"},
)
self.assertTrue(all(types == all_semver for types in ignored.values()))
def test_weekly_scan_covers_the_same_lockfiles(self) -> None:
workflow = yaml.safe_load(SECURITY_SCAN.read_text(encoding="utf-8"))
jobs = workflow["jobs"]