From 6afeb93d7dee7e9ef384bf40fb00d80f39b50525 Mon Sep 17 00:00:00 2001 From: Charles Ewert Date: Fri, 29 May 2026 00:03:38 -0400 Subject: [PATCH] feat(renovate): pin npm deps to exact versions org-wide MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add :pinAllExceptPeerDependencies so dependencies/devDependencies pin to exact versions (peerDependencies stay ranges). config:recommended preserved whatever range style each manifest used, so deps like @astrojs/starlight stayed on carets (^0.39.0) and silently drifted within-range between installs. The org has no published npm library (shared-ui is private, consumed from GitHub at build time), so no downstream consumer depends on these ranges — exact pins give reproducible installs and clean update diffs. Enabling this opens a one-time 'Pin dependencies' PR per repo (update type 'pin', which the automerge rule does not match, so each is human-reviewed). --- renovate/README.md | 10 ++++++++++ renovate/default.json | 3 ++- 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/renovate/README.md b/renovate/README.md index 88be4d0..e641573 100644 --- a/renovate/README.md +++ b/renovate/README.md @@ -32,6 +32,16 @@ The org default carries: - **Digest pinning** for GitHub Actions, Dockerfiles, and docker-compose files. Tag aliases (`v4`, `:latest`) silently re-point upstream; digests don't. +- **Exact-version pinning** for npm deps via + `:pinAllExceptPeerDependencies` — `dependencies` and + `devDependencies` are pinned to exact versions (`^0.39.0` → + `0.39.0`); `peerDependencies` stay as ranges. The org has no + published npm library (`shared-ui` is `private`, consumed at build + time from GitHub), so nothing downstream depends on these ranges — + exact pins give reproducible installs and clean, reviewable update + diffs. Enabling this opens a one-time **"Pin dependencies"** PR per + repo; that PR's update type is `pin`, which the automerge rule does + **not** match, so a human reviews each one. - **JS lint stack grouping** — `eslint`, `prettier`, `jshint`, plus glob-matched `@eslint/*`, `eslint-config-*`, `eslint-plugin-*`. One coordinated PR instead of one-per-plugin. diff --git a/renovate/default.json b/renovate/default.json index 6ce43a0..5b134c4 100644 --- a/renovate/default.json +++ b/renovate/default.json @@ -3,7 +3,8 @@ "extends": [ "config:recommended", ":disableDependencyDashboard", - ":rebaseStalePrs" + ":rebaseStalePrs", + ":pinAllExceptPeerDependencies" ], "addLabels": ["dependencies"], "rollbackPrs": true,