319de80f fix[smartling][utils]: ENG-13615 plugin sends enum field values from custom components to translation jobs (#4826)
## Description
A customer reported that Smartling translation jobs were full of junk
strings like White, Left, and Bottom. These are dropdown (enum) values
from custom component fields (these are settings, not text anyone should
translate)
**Root Cause:**
When a custom component has a `localized` list field,
`getTranslateableFields` first looks for child values that are
individually marked as localized. If it doesn't find any, it falls back
to grabbing every string inside the list.
That fallback isn't a bug on its own, it's what makes ordinary lists
translatable and there's a test pinning it. The real issue is that the
extractor has no way to tell a **headline** from a **dropdown value**.
It runs on the server against raw content JSON, and a component's
`inputs` schema only exists in the app code. The server never sees enum:
["Left", "Center", "Right"].
**Fix:**
Blocks can now carry a list of input paths that should be
non-translatable:
```
meta.nonTranslatableInputs: [
'textColumns.*.textColumnAlignment',
'textColumns.*.textRowAlignment',
'textColumns.*.backgroundColor',
]
```
`getTranslateableFields` reads that list and skips those leaves. The *
stands in for list indices, so one item's schema covers the whole list.
**Link to JIRA ticket (if applicable):**
https://builder-io.atlassian.net/browse/ENG-13615
**Screenshot/Clip**
https://clips.agent-native.com/r/ATlR8Yi3xWgq
<!-- CURSOR_SUMMARY -->
---
> [!NOTE]
> **Medium Risk**
> Changes core translation extract/apply logic for custom components;
incorrect path matching could omit real copy or mishandle locale
seeding, though behavior without `nonTranslatableInputs` is explicitly
preserved by tests.
>
> **Overview**
> Stops **dropdown/enum values** (e.g. alignment, background color) from
being sent to translation providers when custom components use localized
list fields whose string leaves were previously all extracted.
>
> Blocks can declare **`meta.nonTranslatableInputs`** with wildcard
paths (`textColumns.*.textColumnAlignment`).
**`getTranslateableFields`** normalizes paths (indices → `*`, `#`/`.`
equivalent) and omits those leaves during nested extraction; behavior is
unchanged when the list is empty.
>
> **`applyTranslation`** mirrors the same exclusions: it drops compound
keys for excluded paths, **ignores legacy job payloads** that still
contain translated enums, and **seeds the target locale from source**
when an input has no translatable leaves (so lists do not resolve to
`undefined` and disappear). Broad test coverage was added for
TextColumns-style scenarios and all-excluded inputs.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
cb6ba9b1f5f4670db49d31705d2ca44786bc18bf. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY --> 7c8cab91 chore: add dependabot config for npm and github-actions (#4794)
## What
Adds `.github/dependabot.yml` (new file — the repo had no dependabot
config tracked in git).
**Root `/` npm** — weekly, 14-day cooldown, minor/patch grouped into one
`routine-updates` PR, security updates grouped separately, `chore`
commit prefix, limit 10 open PRs.
**Root `/` github-actions** — same shape, `ci` commit prefix, limit 5
open PRs.
**Security-only for 12 packages** — `json-schema`, `admin-sdk`,
`angular`, `cli`, `create-builder.io`, `gatsby`, `plugin-loader`,
`plugin-tools`, `shopify`, `utils`, `webcomponents`, `widgets`. Each
uses `open-pull-requests-limit: 0` so routine version bumps are
suppressed and only grouped security updates open PRs.
## Why
The 14-day cooldown avoids churn from same-week patch releases, and
grouping keeps routine updates to one PR per ecosystem instead of one
per dependency. Security updates bypass grouping-with-routine so they
land on their own and are easy to triage.
## Not included
`examples/` and `plugins/` directories — intentionally left out.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
<!-- CURSOR_SUMMARY -->
---
> [!NOTE]
> **Low Risk**
> CI/automation config only; no application runtime or auth logic
changes, though future Dependabot PRs will need normal review.
>
> **Overview**
> Introduces **`.github/dependabot.yml`** so the repo gets automated
dependency PRs where none existed before.
>
> **Root npm (`/`)** runs weekly with a 14-day cooldown, up to 10 open
PRs, `chore` commits, and grouped **minor/patch** (`routine-updates`)
plus separate **security** groups.
>
> **Root `github-actions`** mirrors that pattern with `ci` commits and a
cap of 5 open PRs.
>
> **Twelve package workspaces** under `packages/*` each get weekly npm
monitoring with **`open-pull-requests-limit: 0`**, so only grouped
**security** updates open PRs—no routine version bumps for those paths.
>
> `examples/` and `plugins/` are not configured.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
5da495ed92e2987a6077fe2423125730c80a7fb7. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>