Skip to content

chore(deps): ignore @zxcvbn-ts/* at v4 (close the per-package split)#517

Merged
mattrobinsonsre merged 1 commit into
mainfrom
chore/ignore-zxcvbn-v4-scope
Jun 15, 2026
Merged

chore(deps): ignore @zxcvbn-ts/* at v4 (close the per-package split)#517
mattrobinsonsre merged 1 commit into
mainfrom
chore/ignore-zxcvbn-v4-scope

Conversation

@mattrobinsonsre

Copy link
Copy Markdown
Owner

Dependabot splits the held zxcvbn v4 upgrade into separate per-package PRs — @zxcvbn-ts/language-common (#509) and @zxcvbn-ts/core (#515). The name-specific ignore I added in #513 only silenced language-common, so core reopened as #515.

Widens the existing npm ignore to the whole @zxcvbn-ts/* scope at >=4, so every package in the v4 set (core, language-common, dictionary-compression) stays held until the coordinated upgrade — no more whack-a-mole.

#509 and #515 are already closed; this stops dependabot reopening either. Lift the ignore when doing the v4 upgrade (bump core + language-common together + the admin/users code changes).

YAML validated.

…uage-common

Dependabot splits the held zxcvbn v4 upgrade into per-package PRs
(language-common #509, core #515). A name-specific ignore only silences
one half, so the other keeps reopening. Widen the ignore to the
@zxcvbn-ts/* scope at >=4 so both (and dictionary-compression) stay held
until the coordinated v4 upgrade lands.
@mattrobinsonsre mattrobinsonsre enabled auto-merge (squash) June 15, 2026 10:30
@mattrobinsonsre mattrobinsonsre merged commit e3810a3 into main Jun 15, 2026
51 checks passed
@mattrobinsonsre mattrobinsonsre deleted the chore/ignore-zxcvbn-v4-scope branch June 15, 2026 10:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant