chore: update renovate to refresh lockfile 1x a month#4138
Merged
castastrophe merged 1 commit intoAug 18, 2025
Conversation
|
Contributor
File metricsSummaryTotal size: 1.43 MB* 🎉 No changes detected in any packages * Size is the sum of all main files for packages in the library.* An ASCII character in UTF-8 is 8 bits or 1 byte. |
Contributor
📚 Branch previewPR #4138 has been deployed to Azure Blob Storage: https://spectrumcss.z13.web.core.windows.net/pr-4138/index.html. |
cdransf
approved these changes
Aug 18, 2025
4 tasks
This was referenced Aug 27, 2025
14 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This update adds monthly lockfile maintenance to Renovate configuration to ensure dependency lockfiles are regularly refreshed. The primary goal is to keep
caniusedband other indirect dependencies up-to-date, even when they're not direct project dependencies.Motivation and context
Lockfiles can become stale over time, especially for indirect dependencies like
caniusedbthat are pulled in by other packages. By enabling monthly lockfile maintenance, we ensure that:This change helps maintain the overall health and security of the dependency tree without requiring manual intervention.
Author's checklist
Reviewer's checklist
patch,minor, ormajorfeaturesManual review test cases
Verify Renovate configuration is valid
.github/renovate.jsonfilelockFileMaintenancesection is properly configuredConfirm lockfile maintenance behavior
caniusedband other indirect dependencies to be refreshed