Skip to content

Add Dependabot version updates for uv and GitHub Actions - #475

Open
alex-clickhouse wants to merge 2 commits into
mainfrom
alex-clickhouse/dependabot-uv-actions
Open

alex-clickhouse wants to merge 2 commits into
mainfrom
alex-clickhouse/dependabot-uv-actions

Conversation

@alex-clickhouse

@alex-clickhouse alex-clickhouse commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

What

Adds .github/dependabot.yml with monthly version updates (first day of each month) for two ecosystems:

  • uv: pyproject.toml and uv.lock
  • github-actions: .github/workflows/

Why

#320 locked all dependencies in uv.lock. Nothing moves those pins. They go stale without a signal, the lock does not pick up fixes, and the eventual relock changes many packages at once. A dry run today moves 55 of the 123 locked packages.

Monthly Dependabot PRs keep each lock change small. The backend-tests job runs uv sync --locked, so CI tests exactly the versions that each PR proposes.

How

uv entry:

  • cooldown.default-days: 7: Dependabot does not propose a release until it is 7 days old. Malicious releases (account takeover, typosquat) are usually found and yanked within a few days. Cooldown applies only to version updates, so security updates are not delayed.
  • allow: dependency-type: all: the default updates only direct dependencies. Most of uv.lock is transitive (123 locked packages, 25 declared). Without this, those pins stay stale.
  • versioning-strategy: increase-if-necessary: Dependabot keeps each requirement in pyproject.toml as written, and changes a bound only when the new version is outside it. Without this, Dependabot decides between "app" and "library" by looking up a PyPI project with the same name. A project named nerve exists on PyPI with a different summary, so this repo is treated as an app, which raises every >= floor to the latest version in every PR. The floors in pyproject.toml have comments that explain them (claude-agent-sdk>=0.2.158, mcp>=2,<3), so they must stay as written.
  • groups: one PR for all minor and patch updates. Each major update gets its own PR. memu-py also gets its own PR, because nerve monkey-patches its internals (memu_bridge._patch_sqlite_bugs) and a bump needs a manual review.

github-actions entry: same schedule and cooldown, with minor and patch updates grouped.

Monthly, not weekly, to keep the number of PRs low. In a usual month this gives one grouped PR per ecosystem, plus one PR for each major update. Security updates do not use this schedule, so they still arrive when an alert opens. With the 7-day cooldown, a new release reaches a PR 7 to 38 days after it is published.

What to expect from the first run

Dependabot runs once within minutes of the merge, and then on the first day of each month.

Based on a dry run of uv lock --upgrade with uv 0.12.19 (the version Dependabot uses):

  • One grouped PR with about 51 minor and patch updates.
  • A separate PR for anthropic 0.123 → 1.10 (major).
  • A separate PR for filelock 3 → 4 (transitive, major).
  • A separate PR for memu-py 1.4.0 → 1.5.1, which changes the == pin in pyproject.toml. Do not merge this PR until someone has examined _patch_sqlite_bugs against 1.5.1 and updated _MEMU_PATCHED_VERSION. On a version mismatch, the bridge only logs a warning and still applies the patches.

Releases from the last 7 days are not in these PRs, so the exact numbers will be a little different.

Not in this PR

  • web/ (npm) is not in this file. Dependabot security updates for web/ continue as before. All 30 open alerts are in web/package-lock.json, and Bump web dependencies to fix Dependabot security alerts #469 addresses them.
  • Dependabot does not change the version: "0.12.0" input of astral-sh/setup-uv in ci.yml. Bump that input manually.
  • Python 3.14 coverage and a scheduled cold uv sync --locked --no-cache job are separate follow-ups.

Testing

No runtime code changed, and no code or test reads .github/.

  • Validated the file against the SchemaStore dependabot-2.0 JSON schema: 0 errors. A negative test with a misspelled key or an unknown strategy gives 1 error each, so the schema is strict.
  • Checked cooldown, versioning-strategy, and allow: dependency-type support for uv and github-actions against the Dependabot options reference and the dependabot-core source.
  • Lock format compatibility: uv 0.12.19 uv lock --check accepts the current lock (written by 0.12.0). CI's uv 0.12.0 uv lock --check accepts a lock written by uv 0.12.19.
  • .venv/bin/pytest tests/: 3901 passed with the fully upgraded lock from the dry run (all 55 updates, including anthropic 1.10 and filelock 4). This did not include memu-py 1.5.1, because uv lock --upgrade keeps == pins.

After merge: the Dependabot tab under Insights > Dependency graph shows both entries. Use "Check for updates" there to start a run at any time.

🤖 Generated with Claude Code

alex-clickhouse and others added 2 commits September 30, 2026 19:01
uv.lock pins every dependency, but nothing moves the pins. They go
stale without a signal, and the eventual relock changes many packages
at once. Weekly Dependabot PRs make each lock change small, and CI's
`uv sync --locked` tests exactly the versions each PR proposes.

- Releases must be 7 days old before Dependabot proposes them.
  Security updates are not delayed.
- Transitive pins are included. Most of uv.lock is transitive.
- `increase-if-necessary` keeps the floors in pyproject.toml. The
  default for an app raises every floor in every PR.
- Minor and patch updates share one PR per ecosystem. Majors and
  memu-py, whose internals nerve monkey-patches, get their own PRs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Weekly runs give more PRs than the project wants to review. Monthly
runs on the first day of each month. Security updates do not use this
schedule, so they are not delayed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@alex-clickhouse
alex-clickhouse marked this pull request as ready for review October 1, 2026 13:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant