Commit 79d9815
committed
fix(ci): ensure Dependabot PRs include yarn.lock updates
Problem:
- Dependabot was updating package.json without yarn.lock
- canary.yml failed with 'lockfile would have been modified' error
- dev.yml incorrectly passed by skipping install on cache hit
Solution:
- Add versioning-strategy: increase to dependabot.yml for all npm ecosystems
- Remove conditional install in dev.yml to always validate lockfile
- Add cache step id to canary.yml for consistency
This ensures:
1. Dependabot generates complete PRs with lockfile updates
2. Both workflows consistently validate lockfile integrity
3. Out-of-sync dependencies are caught early in CI
resolve #2841 parent e15354d commit 79d9815
3 files changed
Lines changed: 4 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
10 | 11 | | |
11 | 12 | | |
12 | 13 | | |
| |||
30 | 31 | | |
31 | 32 | | |
32 | 33 | | |
| 34 | + | |
33 | 35 | | |
34 | 36 | | |
35 | 37 | | |
| |||
50 | 52 | | |
51 | 53 | | |
52 | 54 | | |
| 55 | + | |
53 | 56 | | |
54 | 57 | | |
55 | 58 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
| 38 | + | |
38 | 39 | | |
39 | 40 | | |
40 | 41 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
48 | 48 | | |
49 | 49 | | |
50 | 50 | | |
51 | | - | |
52 | 51 | | |
53 | 52 | | |
54 | 53 | | |
| |||
0 commit comments