pnpm install after a dependabot bump keeps duplicate versions of packages that happen to be pinned via overlapping semver ranges. For singleton-ish libraries (i18next, react-i18next) that's a latent bug: the server's module instance and the client's module instance each hold their own state, and SSR output doesn't match CSR. #272 ran into this with an i18next patch bump — the bumped version stayed on some dep paths while other paths kept the old version. A manual `pnpm dedupe` collapsed them and hydration worked again. This workflow fires on every dependabot PR, runs `pnpm dedupe`, and pushes the resulting lockfile update back to the PR branch so CI runs against the deduped tree. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| workflows | ||
| copilot-instructions.md | ||
| dependabot.yml | ||