Repository navigation
fix(deps): keep bun.lock at lockfileVersion 1 for dependabot - #11
Merged
Merged
Conversation
Dependabot's bun updater bundles bun 1.3.14, which reads only lockfileVersion 1, so every bun update run failed on the version 2 files bun 1.4 wrote. Versions 1 and 2 hold the same content: the field was set to 1 and bun 1.4.2 re-saved both files with no other change and no resolution change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Every Dependabot bun update run (
/and/site) has failed since the move to bun 1.4.2. This keeps bothbun.lockfiles atlockfileVersion1, which Dependabot can read, with no dependency resolution change, and adds a test so they stay there.Root cause
Bun 1.4 writes
"lockfileVersion": 2for a new lockfile. Dependabot's bun updater image bundles bun 1.3.14 (ARG BUN_VERSION=1.3.14in dependabot-core'sbun/Dockerfile,MAX_SUPPORTED_LOCKFILE_VERSION = 1) and ignorespackageManager(dependabot-core#15897). Since dependabot-core#15896 it rejects a newer lockfile instead of silently downgrading it, so runs 36300871692 (/) and 36300871693 (/site) both fail with:Upstream: dependabot/dependabot-core#16026 (open) and dependabot/dependabot-core#16071 (open, bumps the image to bun 1.4.0 and accepts versions 2 and 3; no review yet).
Why version 1 is safe here
bunfig.tomlkey that writes version 1, but its writer keeps the version a lockfile was loaded with. Versions 1 and 2 hold the same content (install: bump default lockfileVersion to 2, gate stricter parse checks behind it oven-sh/bun#31539); version 2 only adds two parse checks, covered below.--frozen-lockfilepasses.--frozen-lockfileand re-saves them byte-identical.bun addplusbun remove, andbun update, under bun 1.4.2 keep version 1.dependabot.ymlnow say to review lockfile diffs for both.bun.lock, so that would leave no automated bun updates at all.Changes
bun.lock,site/bun.lock:lockfileVersion2 to 1, exactly as bun 1.4.2 re-saved them.test/lockfile-version.test.ts: fails when either lockfile is not version 1, with a message saying how to restore it and when to move to 2. Checked by settingbun.lockback to 2: that test failed, the site one passed.CONTRIBUTING.md: the toolchain lines now say why the lockfiles stay at version 1, never to delete and regenerate one, and how to move to 2 once dependabot-core#16071 ships..github/dependabot.yml: the same note, next to the bun entries.This PR merges cleanly with #8: its
site/bun.lockchanges start at line 8, and the version field is on line 2.After merge
The next scheduled (weekly) or manually triggered bun update run for
/and/siteshould succeed. It will likely open pull requests for pending minor and patch updates (for example the rollup and @types/node patches above, grouped as configured), each keepinglockfileVersion1. Once Dependabot runs a bun that reads version 2, set the field back to 2 in both lockfiles and update the test, CONTRIBUTING anddependabot.yml.Test plan
bun install --frozen-lockfileat the root and insite/(bun 1.4.2)bun run typecheckbun run test: 22 files, 248 passed, 2 skipped (Windows only)bun run --cwd site test: 156 passbun run docs:build