From 7cd7d3758417b424d33212b2cd355d1da0914780 Mon Sep 17 00:00:00 2001 From: Gleb Sidora Date: Mon, 28 Sep 2026 14:13:22 +0100 Subject: [PATCH] chore(ci): skip generated python-tools lock, hold better-auth at 1.6 Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/dependabot.yml | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index e4db30f0c1..79c64413dd 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -24,6 +24,13 @@ updates: - "*" update-types: - major + ignore: + # better-auth 1.7 changes the socialProviders types and breaks the sign-in + # integration tests. Ignore only 1.7 and above, so 1.6.x patches still + # arrive. Drop this entry once the 1.7 migration lands. + - dependency-name: better-auth + versions: + - ">= 1.7.0" - package-ecosystem: github-actions directory: / @@ -37,12 +44,13 @@ updates: patterns: - "*" - # Python — every packages/* dir with a pyproject.toml + uv.lock, plus the - # pinned agent tool lock under sandbox-images. + # Python — every packages/* dir with a pyproject.toml + uv.lock. The + # sandbox-images/locks/python-tools project is left out: `sandbox:images lock` + # generates it from the image tool manifest, so edits to it fail the + # freshness check. - package-ecosystem: uv directories: - /packages/* - - /packages/sandbox-images/locks/python-tools schedule: interval: weekly day: monday