Skip to content

Conversation

@mcoetzee
Copy link
Contributor

@mcoetzee mcoetzee commented Jan 7, 2026

Relates to https://github.com/api3dao/tasks/issues/1777

I'm leaving lockFileMaintenance disabled, because enabling it with yarn v1 would increase the risk of supply chain attacks.

@mcoetzee mcoetzee requested a review from dcroote January 7, 2026 13:15
@mcoetzee mcoetzee self-assigned this Jan 7, 2026
@mcoetzee
Copy link
Contributor Author

mcoetzee commented Jan 7, 2026

@dcroote Have you guys considered migrating from yarn to pnpm?

Copy link
Contributor

@dcroote dcroote left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One minor request, but otherwise looks good, and I agree with the lock file choice.

As for pnpm, yes a transition from yarn is overdue.

renovate.json Outdated
"packageRules": [
{
"matchPackageNames": ["chalk", "hardhat", "ora", "node", "@openzeppelin/contracts", "zod"],
"matchPackageNames": ["ora", "node", "@openzeppelin/contracts"],
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you retain zod too please? We manually update it with OIS package bumps because we've had compatibility issues when the versions are mismatched, see https://github.com/api3dao/ois?tab=readme-ov-file#make-sure-only-one-zod-version-is-installed

@mcoetzee mcoetzee merged commit 0fc2ed6 into master Jan 8, 2026
25 checks passed
@mcoetzee mcoetzee deleted the use-renovate-preset branch January 8, 2026 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants