Repository navigation
Conversation
`e2e/` has been a Dependabot `npm` directory since apache#9089 but ships only a `package.json` with a caret range. Without a lockfile every install resolves whatever Playwright release is current, and Dependabot has to guess the "from" version (apache#9098 was titled "1.63.0 -> 1.62.1" while it actually raised the range from ^1.58.2). - Add `e2e/package-lock.json` (lockfileVersion 3, public npm registry), resolving `@playwright/test` ^1.63.0 to 1.63.0. `package.json` is the npm-init scaffold and declares no `packageManager`, so npm is the natural tool; `**/*.json` is already excluded in `.licenserc.yaml`. - Update the `/e2e` comment in `.github/dependabot.yml`: the directory now has a lockfile. `versioning-strategy: increase` stays, so the declared range and the locked version move together. Signed-off-by: DoDiODev <DoDiDev@proton.me>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
e2e/has been a Dependabotnpmdirectory since #9089, but it only contains apackage.jsonwith a caret range and no lockfile. Every install therefore resolves whatever Playwright release is current, and Dependabot has to guess the version it is updating from — #9098 was titled "bump @playwright/test from 1.63.0 to 1.62.1" although it actually raised the range from^1.58.2to^1.62.1.This PR commits a lockfile and updates the related Dependabot comment.
Changes
e2e/package-lock.json@playwright/test^1.63.0to1.63.0(plusplaywright,playwright-core).github/dependabot.yml/e2ecomment no longer says "this directory has no lockfile".versioning-strategy: increasestays so the declared range and the locked version move togetherWhy npm:
e2e/package.jsonis thenpm initscaffold and declares nopackageManager;npm ciworks with any Node installation.**/*.jsonis already excluded in.licenserc.yaml, so no license-config change is needed.No change to
package.json, test code or any workflow.Verification
npm cifrom the committed lockfileplaywright --version→ 1.63.0resolvedURLshttps://registry.npmjs.org/skywalking-eyes header checkmaine2e-mysqlande2e-postgres