Skip to content

chore: commit lockfile and set up Dependabot - #487

Merged
camden11 merged 3 commits into
mainfrom
chore/commit-lockfile-and-dependabot
Sep 16, 2026
Merged

camden11 merged 3 commits into
mainfrom
chore/commit-lockfile-and-dependabot

Conversation

@camden11

@camden11 camden11 commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

This library previously committed no lockfile (.yarnrc forced --no-lockfile and yarn.lock was gitignored). Without a lockfile, Dependabot builds its npm graph from package.json alone and is blind to transitive dependencies, so its security and version updates only ever cover direct deps. A committed lockfile does not ship to consumers (yarn.lock is excluded from the npm tarball), so this only affects local and CI installs and restores full dependency visibility.

  • Remove .yarnrc no-lockfile directives and un-ignore yarn.lock
  • Commit yarn.lock
  • Add .github/dependabot.yml (npm at /, github-actions; @hubspot/* grouped separately, 7-day cooldown on each entry)

Description and Context

Pre-review checklist

  • The /ldl:code-check skill has been run and the feedback has been addressed
  • Tests have been added for new behaviors
  • Manually tested the changes

Screenshots

TODO

Who to Notify

camden11 and others added 3 commits September 16, 2026 14:37
This library previously committed no lockfile (.yarnrc forced --no-lockfile
and yarn.lock was gitignored). Without a lockfile, Dependabot builds its npm
graph from package.json alone and is blind to transitive dependencies, so its
security and version updates only ever cover direct deps. A committed lockfile
does not ship to consumers (yarn.lock is excluded from the npm tarball), so this
only affects local and CI installs and restores full dependency visibility.

- Remove .yarnrc no-lockfile directives and un-ignore yarn.lock
- Commit yarn.lock
- Add .github/dependabot.yml (npm at /, github-actions; @hubspot/* grouped
  separately, 7-day cooldown on each entry)
- Add a daily fresh-install-check workflow that does a clean install from
  package.json then build + test, as a smoke test for upstream breakage that a
  fresh consumer install would hit. It never commits or opens a PR.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The CLI's fresh-install check already resolves this library's runtime deps
floating, as a real consumer install does. For the library itself the committed
lockfile, normal CI, and Dependabot (which re-runs full CI on each bump) provide
adequate coverage, so a separate daily check here is redundant.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Major versions are breaking and cannot be merged without additional work, so
they should not arrive as routine dependency PRs. Ignore semver-major for all
version updates across every ecosystem. This does not affect security updates,
which are exempt from update-types ignores, so Dependabot can still propose a
major bump when it is required to fix a vulnerability.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@camden11
camden11 marked this pull request as ready for review September 16, 2026 19:10
@camden11
camden11 requested a review from a team September 16, 2026 19:10
@camden11
camden11 merged commit 7da03d4 into main Sep 16, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants