Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
version: 2

updates:
- package-ecosystem: npm
directory: "/"
schedule:
interval: daily
# Only fontdue-js. Without this allow-list Dependabot would also start
# opening PRs for Next, React and every other dependency in the tree.
allow:
- dependency-name: fontdue-js
# Bump the pin in place (3.0.5 -> 3.0.6) rather than widening it to a range.
versioning-strategy: increase
open-pull-requests-limit: 1
80 changes: 80 additions & 0 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,80 @@
name: build

on:
pull_request:
push:
branches: [main]

jobs:
build:
runs-on: ubuntu-latest
permissions:
# Write so the lockfile-repair step below can push to Dependabot branches.
contents: write
env:
# Public staging backend. The build prerenders pages, so it needs a
# reachable Fontdue server -- there is nothing secret here.
NEXT_PUBLIC_FONTDUE_URL: https://example.fontdue.xyz
steps:
- uses: actions/checkout@v4
with:
# Dependabot PRs: check out the branch itself rather than the
# ephemeral merge ref so the lockfile repair can be pushed back.
ref: ${{ github.event.pull_request.user.login == 'dependabot[bot]' && github.event.pull_request.head.ref || '' }}
- uses: actions/setup-node@v4
with:
node-version: 22
cache: npm

# Dependabot regenerates package-lock.json with a newer npm (11) that
# omits entries npm 10 (node 22, and most dev machines) requires: nested
# copies for optional peer deps whose hoisted version is too old. `npm ci`
# then fails with EUSAGE "Missing: <pkg> from lock file". Regenerating
# with this runner's npm yields a lockfile both npm 10 and 11 accept.
- name: Repair Dependabot lockfile
if: github.event_name == 'pull_request' && github.event.pull_request.user.login == 'dependabot[bot]'
run: |
npm install --package-lock-only
if ! git diff --quiet package-lock.json; then
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git commit -m "Regenerate package-lock.json with npm 10" package-lock.json
git push
fi

- run: npm ci
- run: npm run build

# Dependabot opens fontdue-js bumps (see .github/dependabot.yml). `needs: build`
# is what makes merging them unattended safe -- without it this would merge a
# release that doesn't compile against this framework.
#
# The repository_owner check keeps unattended merges scoped to the fontdue
# org. If you cloned this repo as a starting point for your own site, you
# still get Dependabot's fontdue-js update PRs and the build check above,
# but nothing lands on your main branch without you. If you'd like updates
# to merge themselves once they build -- say your site deploys from main and
# you want font releases to flow through unattended -- change 'fontdue' to
# your own GitHub username or org.
automerge:
needs: build
if: >-
github.event_name == 'pull_request' &&
github.event.pull_request.user.login == 'dependabot[bot]' &&
github.repository_owner == 'fontdue'
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
steps:
- uses: dependabot/fetch-metadata@v2
id: meta
with:
github-token: ${{ secrets.GITHUB_TOKEN }}

# Major bumps land in a human's inbox: those are the ones that break templates.
- if: steps.meta.outputs.update-type != 'version-update:semver-major'
run: gh pr merge --squash --delete-branch "$PR_URL"
env:
PR_URL: ${{ github.event.pull_request.html_url }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
28 changes: 14 additions & 14 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
},
"dependencies": {
"@graphql-tools/import": "^7.1.14",
"fontdue-js": "3.2.0",
"fontdue-js": "3.6.0",
"graphql": "^16.14.2",
"html-react-parser": "^5",
"next": "^15.5.14",
Expand Down
Loading