Skip to content

Commit ff9a8f0

Browse files
mattgloryclaude
andcommitted
Block all major version upgrades in Dependabot
Use wildcard ignore to prevent any major version PRs across all dependencies. Only patch and minor updates will be proposed. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
1 parent 259d4e7 commit ff9a8f0

1 file changed

Lines changed: 5 additions & 10 deletions

File tree

.github/dependabot.yml

Lines changed: 5 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -7,9 +7,9 @@ updates:
77
interval: "weekly"
88
open-pull-requests-limit: 5
99
ignore:
10-
# Only allow patch updates for esbuild (major/minor can break builds)
11-
- dependency-name: "esbuild"
12-
update-types: ["version-update:semver-major", "version-update:semver-minor"]
10+
# Block ALL major version upgrades — require manual migration
11+
- dependency-name: "*"
12+
update-types: ["version-update:semver-major"]
1313

1414
# Frontend (web/)
1515
- package-ecosystem: "npm"
@@ -18,11 +18,6 @@ updates:
1818
interval: "weekly"
1919
open-pull-requests-limit: 5
2020
ignore:
21-
# Block major version upgrades for Next.js (14→15 requires migration)
22-
- dependency-name: "next"
23-
update-types: ["version-update:semver-major"]
24-
# Block major React upgrades (tied to Next.js version)
25-
- dependency-name: "react"
26-
update-types: ["version-update:semver-major"]
27-
- dependency-name: "react-dom"
21+
# Block ALL major version upgrades — require manual migration
22+
- dependency-name: "*"
2823
update-types: ["version-update:semver-major"]

0 commit comments

Comments
 (0)