Skip to content

chore(dependabot): add 7-day cooldown to align with Yarn age gate - #2857

Merged
piyalbasu merged 1 commit into
masterfrom
chore/dependabot-cooldown
Jun 18, 2026
Merged

piyalbasu merged 1 commit into
masterfrom
chore/dependabot-cooldown

Conversation

@piyalbasu

Copy link
Copy Markdown
Contributor

TL;DR

Makes Dependabot wait 7 days after a package is released before opening a PR for it, so it stops proposing versions that our Yarn config (npmMinimalAgeGate: 7d) would then refuse to install — which is what's been causing fresh dependency PRs to fail CI on yarn install.

Implementation details (for agents)

What changed (.github/dependabot.yml): added cooldown: { default-days: 7 } to the npm ecosystem block.

Why: .yarnrc.yml sets npmMinimalAgeGate: 7d, which Yarn enforces at install time — yarn install refuses any version younger than 7 days. Dependabot doesn't run Yarn and ignores .yarnrc.yml entirely; it resolves against the npm registry and opens PRs the instant a release lands. The result is a PR that locks, e.g., form-data@4.0.6 (published 6/12) into yarn.lock, which CI's yarn step then rejects until 6/19 (see the age-gate flag on #2851). cooldown is Dependabot's native equivalent of the Yarn gate, so the two now align.

Scope / caveats:

  • Applied to npm only — npmMinimalAgeGate is npm-specific. GitHub Actions cooldown is a separate, optional decision (not added here).
  • Security updates ignore cooldown by design — a fresh security advisory can still trip the Yarn gate; for those, use the npmPreapprovedPackages bypass in .yarnrc.yml if it's urgent.
  • cooldown also supports semver-{major,minor,patch}-days and include/exclude lists if per-package tuning is wanted later.
  • Independent of the security-grouping change (chore(dependabot): group security updates into consolidated PRs #2853, already merged); both live in the same npm block.

Verification: YAML structure validated (consistent indentation, no tabs). No effect until Dependabot's next run.

🤖 Generated with Claude Code

`.yarnrc.yml` sets `npmMinimalAgeGate: 7d`, enforced by Yarn at install
time. Dependabot has no knowledge of Yarn config — it resolves against the
npm registry directly — so it opens PRs (and locks versions) the moment a
release is published, which `yarn install` in CI then rejects for being
younger than 7 days.

Add Dependabot's native `cooldown: { default-days: 7 }` to the npm
ecosystem so it waits out the same window before raising a PR. Security
updates intentionally ignore cooldown.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 18, 2026 20:12
@piyalbasu
piyalbasu merged commit cece0a5 into master Jun 18, 2026
10 of 11 checks passed
@piyalbasu
piyalbasu deleted the chore/dependabot-cooldown branch June 18, 2026 20:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Aligns Dependabot’s npm update behavior with this repo’s Yarn npmMinimalAgeGate: 7d so Dependabot won’t open dependency PRs that CI can’t install yet due to Yarn’s age gate.

Changes:

  • Add a Dependabot npm cooldown of 7 days to delay version-update PRs until packages are old enough for Yarn to accept.
  • Document the rationale inline, including the note that security updates intentionally ignore cooldown.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions github-actions Bot mentioned this pull request Jul 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants