From 2b65da022dbf43da86875f656a3a38f140651d7e Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Fri, 18 Sep 2026 14:33:20 +0000 Subject: [PATCH] Sync from next-template@385fc32 --- .github/dependabot.yml | 14 +++++++ .github/workflows/build.yml | 80 +++++++++++++++++++++++++++++++++++++ package-lock.json | 28 ++++++------- package.json | 2 +- 4 files changed, 109 insertions(+), 15 deletions(-) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/build.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..4759643 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,14 @@ +version: 2 + +updates: + - package-ecosystem: npm + directory: "/" + schedule: + interval: daily + # Only fontdue-js. Without this allow-list Dependabot would also start + # opening PRs for Next, React and every other dependency in the tree. + allow: + - dependency-name: fontdue-js + # Bump the pin in place (3.0.5 -> 3.0.6) rather than widening it to a range. + versioning-strategy: increase + open-pull-requests-limit: 1 diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml new file mode 100644 index 0000000..820c47d --- /dev/null +++ b/.github/workflows/build.yml @@ -0,0 +1,80 @@ +name: build + +on: + pull_request: + push: + branches: [main] + +jobs: + build: + runs-on: ubuntu-latest + permissions: + # Write so the lockfile-repair step below can push to Dependabot branches. + contents: write + env: + # Public staging backend. The build prerenders pages, so it needs a + # reachable Fontdue server -- there is nothing secret here. + NEXT_PUBLIC_FONTDUE_URL: https://example.fontdue.xyz + steps: + - uses: actions/checkout@v4 + with: + # Dependabot PRs: check out the branch itself rather than the + # ephemeral merge ref so the lockfile repair can be pushed back. + ref: ${{ github.event.pull_request.user.login == 'dependabot[bot]' && github.event.pull_request.head.ref || '' }} + - uses: actions/setup-node@v4 + with: + node-version: 22 + cache: npm + + # Dependabot regenerates package-lock.json with a newer npm (11) that + # omits entries npm 10 (node 22, and most dev machines) requires: nested + # copies for optional peer deps whose hoisted version is too old. `npm ci` + # then fails with EUSAGE "Missing: from lock file". Regenerating + # with this runner's npm yields a lockfile both npm 10 and 11 accept. + - name: Repair Dependabot lockfile + if: github.event_name == 'pull_request' && github.event.pull_request.user.login == 'dependabot[bot]' + run: | + npm install --package-lock-only + if ! git diff --quiet package-lock.json; then + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git commit -m "Regenerate package-lock.json with npm 10" package-lock.json + git push + fi + + - run: npm ci + - run: npm run build + + # Dependabot opens fontdue-js bumps (see .github/dependabot.yml). `needs: build` + # is what makes merging them unattended safe -- without it this would merge a + # release that doesn't compile against this framework. + # + # The repository_owner check keeps unattended merges scoped to the fontdue + # org. If you cloned this repo as a starting point for your own site, you + # still get Dependabot's fontdue-js update PRs and the build check above, + # but nothing lands on your main branch without you. If you'd like updates + # to merge themselves once they build -- say your site deploys from main and + # you want font releases to flow through unattended -- change 'fontdue' to + # your own GitHub username or org. + automerge: + needs: build + if: >- + github.event_name == 'pull_request' && + github.event.pull_request.user.login == 'dependabot[bot]' && + github.repository_owner == 'fontdue' + runs-on: ubuntu-latest + permissions: + contents: write + pull-requests: write + steps: + - uses: dependabot/fetch-metadata@v2 + id: meta + with: + github-token: ${{ secrets.GITHUB_TOKEN }} + + # Major bumps land in a human's inbox: those are the ones that break templates. + - if: steps.meta.outputs.update-type != 'version-update:semver-major' + run: gh pr merge --squash --delete-branch "$PR_URL" + env: + PR_URL: ${{ github.event.pull_request.html_url }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/package-lock.json b/package-lock.json index 216a3d0..7b2b1ea 100644 --- a/package-lock.json +++ b/package-lock.json @@ -9,7 +9,7 @@ "version": "0.1.0", "dependencies": { "@graphql-tools/import": "^7.1.14", - "fontdue-js": "3.2.0", + "fontdue-js": "3.6.0", "graphql": "^16.14.2", "html-react-parser": "^5", "next": "^15.5.14", @@ -5882,9 +5882,9 @@ "license": "ISC" }, "node_modules/fontdue-js": { - "version": "3.2.0", - "resolved": "https://registry.npmjs.org/fontdue-js/-/fontdue-js-3.2.0.tgz", - "integrity": "sha512-VvMyYzQ4q1hTQny0MkH5sGL1XiO0grP5Mj1E8APVSw6cVab9osnvLHiCvmj7MheWvOjTsGwBL8t+YKjNg43HGw==", + "version": "3.6.0", + "resolved": "https://registry.npmjs.org/fontdue-js/-/fontdue-js-3.6.0.tgz", + "integrity": "sha512-MA+uAM2bB8HtR7cnyouzmwIoQwZyfizj/cAuNML6z8Xqw206o9xYSRFLNWG9RIBFcIrvsibgGXvbzK+sXI1ehQ==", "license": "MIT", "dependencies": { "@emotion/react": "^11.14.0", @@ -5912,14 +5912,14 @@ } }, "node_modules/fontdue-js/node_modules/@types/node": { - "version": "26.1.1", - "resolved": "https://registry.npmjs.org/@types/node/-/node-26.1.1.tgz", - "integrity": "sha512-nxAkRSVkN1Y0JC1W8ky/fTfkGsMmcrRsbx+3XoZE+rMOX71kLYTV7fLXpqud1GpbpP5TuffXFqfX7fH2GgZREw==", + "version": "26.5.1", + "resolved": "https://registry.npmjs.org/@types/node/-/node-26.5.1.tgz", + "integrity": "sha512-CzNm2FezW4VR/LjG6yUdiEgLE/rAQ9Slj5gCu/C2VrdcW7I0ahNZ8DRbHT7zOZ6r3ONgd/bsQIeSaoDGrd1C6g==", "license": "MIT", "optional": true, "peer": true, "dependencies": { - "undici-types": "~8.3.0" + "undici-types": "~8.9.0" } }, "node_modules/fontdue-js/node_modules/balanced-match": { @@ -6114,9 +6114,9 @@ } }, "node_modules/fontdue-js/node_modules/yaml": { - "version": "2.9.0", - "resolved": "https://registry.npmjs.org/yaml/-/yaml-2.9.0.tgz", - "integrity": "sha512-2AvhNX3mb8zd6Zy7INTtSpl1F15HW6Wnqj0srWlkKLcpYl/gMIMJiyuGq2KeI2YFxUPjdlB+3Lc10seMLtL4cA==", + "version": "2.9.1", + "resolved": "https://registry.npmjs.org/yaml/-/yaml-2.9.1.tgz", + "integrity": "sha512-3NxN8+78OdzbT7C/WjGsyfPAtJaN3FNDsWxv7Y7mcDsT/oOmgW8BpyQQFFBnvZE3j9Y2Sdz1ULFLezL7Eb2yFw==", "license": "ISC", "optional": true, "peer": true, @@ -10331,9 +10331,9 @@ } }, "node_modules/undici-types": { - "version": "8.3.0", - "resolved": "https://registry.npmjs.org/undici-types/-/undici-types-8.3.0.tgz", - "integrity": "sha512-j375ScV60dom+YkPFIfTLcOiPxkN/buHz5GobjLhixFuANaNs3C9l4GmrWqejgXWJ7BbJcFYpTEUkS1Ge8bpZQ==", + "version": "8.9.0", + "resolved": "https://registry.npmjs.org/undici-types/-/undici-types-8.9.0.tgz", + "integrity": "sha512-KTDyRTYX8sWmKXAikPHHSyc63CRPETMctyjKFupcC6OBLXT3xsN0e9aF7m+mIXutFWpUXuedtowG7iLOzp0kQg==", "license": "MIT", "optional": true, "peer": true diff --git a/package.json b/package.json index 3c9834e..851f9f4 100644 --- a/package.json +++ b/package.json @@ -12,7 +12,7 @@ }, "dependencies": { "@graphql-tools/import": "^7.1.14", - "fontdue-js": "3.2.0", + "fontdue-js": "3.6.0", "graphql": "^16.14.2", "html-react-parser": "^5", "next": "^15.5.14",