chore(dependabot): add 7-day cooldown to align with Yarn age gate - #2857
Merged
Merged
Conversation
`.yarnrc.yml` sets `npmMinimalAgeGate: 7d`, enforced by Yarn at install
time. Dependabot has no knowledge of Yarn config — it resolves against the
npm registry directly — so it opens PRs (and locks versions) the moment a
release is published, which `yarn install` in CI then rejects for being
younger than 7 days.
Add Dependabot's native `cooldown: { default-days: 7 }` to the npm
ecosystem so it waits out the same window before raising a PR. Security
updates intentionally ignore cooldown.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Pull request overview
Aligns Dependabot’s npm update behavior with this repo’s Yarn npmMinimalAgeGate: 7d so Dependabot won’t open dependency PRs that CI can’t install yet due to Yarn’s age gate.
Changes:
- Add a Dependabot npm
cooldownof 7 days to delay version-update PRs until packages are old enough for Yarn to accept. - Document the rationale inline, including the note that security updates intentionally ignore cooldown.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TL;DR
Makes Dependabot wait 7 days after a package is released before opening a PR for it, so it stops proposing versions that our Yarn config (
npmMinimalAgeGate: 7d) would then refuse to install — which is what's been causing fresh dependency PRs to fail CI onyarn install.Implementation details (for agents)
What changed (
.github/dependabot.yml): addedcooldown: { default-days: 7 }to thenpmecosystem block.Why:
.yarnrc.ymlsetsnpmMinimalAgeGate: 7d, which Yarn enforces at install time —yarn installrefuses any version younger than 7 days. Dependabot doesn't run Yarn and ignores.yarnrc.ymlentirely; it resolves against the npm registry and opens PRs the instant a release lands. The result is a PR that locks, e.g.,form-data@4.0.6(published 6/12) intoyarn.lock, which CI'syarnstep then rejects until 6/19 (see the age-gate flag on #2851).cooldownis Dependabot's native equivalent of the Yarn gate, so the two now align.Scope / caveats:
npmMinimalAgeGateis npm-specific. GitHub Actions cooldown is a separate, optional decision (not added here).npmPreapprovedPackagesbypass in.yarnrc.ymlif it's urgent.cooldownalso supportssemver-{major,minor,patch}-daysandinclude/excludelists if per-package tuning is wanted later.Verification: YAML structure validated (consistent indentation, no tabs). No effect until Dependabot's next run.
🤖 Generated with Claude Code