Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
60 changes: 60 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
# Dependabot configuration for RuneBolt.
#
# Scope: only the live tree. `legacy/` holds an archived, non-building snapshot of
# the Taproot-Assets-era code (full history preserved at tag
# legacy/taproot-assets-era-final) and is deliberately NOT tracked here — chasing
# lockfiles for deleted code produced failing "Dependabot Updates" runs.
#
# Grouping: minor+patch version updates arrive as ONE PR per ecosystem, majors
# stay separate (they need a human), and security fixes arrive as ONE PR per
# ecosystem instead of one PR per package.
version: 2

updates:
# pnpm workspace: the root pnpm-lock.yaml covers packages/* as well, so a
# single "/" entry is the whole JS dependency surface.
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
day: "monday"
time: "06:00"
timezone: "America/Los_Angeles"
open-pull-requests-limit: 5
labels:
- "dependencies"
groups:
npm-minor-and-patch:
applies-to: version-updates
patterns:
- "*"
update-types:
- "minor"
- "patch"
npm-security:
applies-to: security-updates
patterns:
- "*"

- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
day: "monday"
time: "06:00"
timezone: "America/Los_Angeles"
open-pull-requests-limit: 5
labels:
- "dependencies"
groups:
actions-minor-and-patch:
applies-to: version-updates
patterns:
- "*"
update-types:
- "minor"
- "patch"
actions-security:
applies-to: security-updates
patterns:
- "*"
10 changes: 8 additions & 2 deletions legacy/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,8 +34,14 @@ RuneBolt hub, locked $DOG (`DOG•GO•TO•THE•MOON`, rune id `1:0`) on L1, t
off-chain against a hub-operated ledger. Backend (Express + SQLite + WebSocket), Next.js frontend,
`@runebolt/sdk`, Docker/Vault/Grafana infrastructure, and a large body of UX and security research.

`legacy/ci/ci-cd.yml` is the old GitHub Actions workflow, parked here so it no longer runs.
It is retained; the code it built now lives only under the tag above.
The old GitHub Actions workflow that built it (`legacy/ci/ci-cd.yml`) has now been removed
from `main` too. Parking it here already stopped it running, but it kept this directory
looking like a live build surface and it only ever built deleted code. It is preserved
unchanged under the tag above (blob `4dc9c28`):

```sh
git show legacy/taproot-assets-era-final:legacy/ci/ci-cd.yml
```

## Why it was superseded

Expand Down
Loading
Loading