diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 350b6e7..c374c25 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -18,7 +18,7 @@ updates: ignore: - dependency-name: "@types/node" update-types: ["version-update:semver-major"] - # Forced in package.json overrides (see CLAUDE.md → package.json overrides). + # Forced in package.json overrides (see each repo's CLAUDE.md → package.json overrides). # Dependabot PRs would fight the pin / reopen known-accepted risk. - dependency-name: "lodash" - dependency-name: "three" diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 910486b..e87506e 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -3,6 +3,10 @@ name: Deploy on: push: branches: [main] + # Manual dispatch, so the site can be published without waiting for a push and + # so a deploy that never fired can be recovered by hand. Matches Baton's own + # pages.yml, which carries the same pair of triggers. + workflow_dispatch: concurrency: group: pages-${{ github.ref }}