Skip to content

chore(deps): hold TypeScript major bumps until typescript-eslint supports them - #88

Closed
vpetersson-bot wants to merge 1 commit into
mainfrom
chore/hold-typescript-majors
Closed

vpetersson-bot wants to merge 1 commit into
mainfrom
chore/hold-typescript-majors

Conversation

@vpetersson-bot

Copy link
Copy Markdown
Contributor

What this does

Tells Dependabot to skip major TypeScript bumps in the npm group. Minors and patches are unaffected.

Why it is wrong today

typescript-eslint 8.x — the parser behind edge-apps-scripts lint — declares:

peer typescript@">=4.8.4 <6.1.0"

There is no published typescript-eslint release that accepts anything newer (latest is 8.70.1, same range). So every major TypeScript bump is unmergeable by construction, in two different shapes:

  • Here, npm ci hard-fails:

    npm error While resolving: typescript-eslint@8.70.0
    npm error Found: typescript@7.0.2
    npm error peer typescript@">=4.8.4 <6.1.0" from typescript-eslint@8.70.0
    

    That is what all four checks on chore(deps): bump the npm group across 1 directory with 18 updates #87 are failing on.

  • In the edge apps that install @screenly/edge-apps, Bun resolves it anyway and lint crashes at runtime:

    ESLint: 10.2.0
    TypeError: Cannot read properties of undefined (reading 'Cjs')
        at node_modules/@typescript-eslint/typescript-estree/dist/create-program/shared.js:59:14
    

Because npm updates here are grouped under a single '*' pattern, one unmergeable TypeScript major also blocks every other bump riding in the same PR.

How I know the change is right

  • The peer range was read off the published package metadata for typescript-eslint 8.57.0 → 8.70.1; all of them cap at <6.1.0.
  • The two failure modes above are the actual CI output on chore(deps): bump the npm group across 1 directory with 18 updates #87 and on the edge-app dependency PRs, not a guess.
  • ignore with update-types: [version-update:semver-major] is scoped to majors only, so security and minor/patch updates for TypeScript still come through.

The same ignore block belongs in the edge apps' own dependabot.yml files — they each declare typescript directly and are each sitting on a red bun-group PR for this reason. Happy to follow up with those once this lands.

🤖 Generated with Claude Code

…orts them

typescript-eslint 8.x declares peer typescript '>=4.8.4 <6.1.0', and no
released version accepts anything newer. It is the parser behind
`edge-apps-scripts lint`, so a major TypeScript bump breaks two ways:

  - here, `npm ci` fails with ERESOLVE (peer typescript vs typescript@7)
  - in every edge app that installs @screenly/edge-apps, lint dies with
    `TypeError: Cannot read properties of undefined (reading 'Cjs')`

Because the npm updates are grouped, one unmergeable TypeScript major also
holds back every other bump in the group. Ignoring only major TypeScript
updates lets the rest of the group land; minors and patches are unaffected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: multica-agent <github@multica.ai>
Copilot AI lite review requested due to automatic review settings September 23, 2026 08:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The scoped rule addresses the compatibility issue without blocking minor or patch updates.

Review effort: Lite
Findings: None

What changed in this PR

Defers Dependabot TypeScript major updates until typescript-eslint supports them, while preserving minor and patch updates.

Changes:

  • Ignores typescript semver-major updates.
  • Keeps minor and patch updates enabled.
File Description
.github/​dependabot.yml Adds the TypeScript major-version ignore rule.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This was referenced Sep 26, 2026
@vpetersson-bot

Copy link
Copy Markdown
Contributor Author

Superseded by #90, which carries this same Dependabot ignore for typescript and applies the rest of the group update that the TypeScript 7 bump was holding back. Closing this one to keep a single PR per repo.

@vpetersson-bot
vpetersson-bot deleted the chore/hold-typescript-majors branch October 3, 2026 08:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants