Repository navigation
Add Dependabot version updates for uv and GitHub Actions - #475
Open
alex-clickhouse wants to merge 2 commits into
Open
alex-clickhouse wants to merge 2 commits into
alex-clickhouse wants to merge 2 commits into
Conversation
uv.lock pins every dependency, but nothing moves the pins. They go stale without a signal, and the eventual relock changes many packages at once. Weekly Dependabot PRs make each lock change small, and CI's `uv sync --locked` tests exactly the versions each PR proposes. - Releases must be 7 days old before Dependabot proposes them. Security updates are not delayed. - Transitive pins are included. Most of uv.lock is transitive. - `increase-if-necessary` keeps the floors in pyproject.toml. The default for an app raises every floor in every PR. - Minor and patch updates share one PR per ecosystem. Majors and memu-py, whose internals nerve monkey-patches, get their own PRs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Weekly runs give more PRs than the project wants to review. Monthly runs on the first day of each month. Security updates do not use this schedule, so they are not delayed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
alex-clickhouse
marked this pull request as ready for review
October 1, 2026 13:54
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds
.github/dependabot.ymlwith monthly version updates (first day of each month) for two ecosystems:uv:pyproject.tomlanduv.lockgithub-actions:.github/workflows/Why
#320 locked all dependencies in
uv.lock. Nothing moves those pins. They go stale without a signal, the lock does not pick up fixes, and the eventual relock changes many packages at once. A dry run today moves 55 of the 123 locked packages.Monthly Dependabot PRs keep each lock change small. The
backend-testsjob runsuv sync --locked, so CI tests exactly the versions that each PR proposes.How
uventry:cooldown.default-days: 7: Dependabot does not propose a release until it is 7 days old. Malicious releases (account takeover, typosquat) are usually found and yanked within a few days. Cooldown applies only to version updates, so security updates are not delayed.allow: dependency-type: all: the default updates only direct dependencies. Most ofuv.lockis transitive (123 locked packages, 25 declared). Without this, those pins stay stale.versioning-strategy: increase-if-necessary: Dependabot keeps each requirement inpyproject.tomlas written, and changes a bound only when the new version is outside it. Without this, Dependabot decides between "app" and "library" by looking up a PyPI project with the same name. A project namednerveexists on PyPI with a different summary, so this repo is treated as an app, which raises every>=floor to the latest version in every PR. The floors inpyproject.tomlhave comments that explain them (claude-agent-sdk>=0.2.158,mcp>=2,<3), so they must stay as written.groups: one PR for all minor and patch updates. Each major update gets its own PR.memu-pyalso gets its own PR, because nerve monkey-patches its internals (memu_bridge._patch_sqlite_bugs) and a bump needs a manual review.github-actionsentry: same schedule and cooldown, with minor and patch updates grouped.Monthly, not weekly, to keep the number of PRs low. In a usual month this gives one grouped PR per ecosystem, plus one PR for each major update. Security updates do not use this schedule, so they still arrive when an alert opens. With the 7-day cooldown, a new release reaches a PR 7 to 38 days after it is published.
What to expect from the first run
Dependabot runs once within minutes of the merge, and then on the first day of each month.
Based on a dry run of
uv lock --upgradewith uv 0.12.19 (the version Dependabot uses):anthropic0.123 → 1.10 (major).filelock3 → 4 (transitive, major).memu-py1.4.0 → 1.5.1, which changes the==pin inpyproject.toml. Do not merge this PR until someone has examined_patch_sqlite_bugsagainst 1.5.1 and updated_MEMU_PATCHED_VERSION. On a version mismatch, the bridge only logs a warning and still applies the patches.Releases from the last 7 days are not in these PRs, so the exact numbers will be a little different.
Not in this PR
web/(npm) is not in this file. Dependabot security updates forweb/continue as before. All 30 open alerts are inweb/package-lock.json, and Bump web dependencies to fix Dependabot security alerts #469 addresses them.version: "0.12.0"input ofastral-sh/setup-uvinci.yml. Bump that input manually.uv sync --locked --no-cachejob are separate follow-ups.Testing
No runtime code changed, and no code or test reads
.github/.dependabot-2.0JSON schema: 0 errors. A negative test with a misspelled key or an unknown strategy gives 1 error each, so the schema is strict.cooldown,versioning-strategy, andallow: dependency-typesupport foruvandgithub-actionsagainst the Dependabot options reference and the dependabot-core source.uv lock --checkaccepts the current lock (written by 0.12.0). CI's uv 0.12.0uv lock --checkaccepts a lock written by uv 0.12.19..venv/bin/pytest tests/: 3901 passed with the fully upgraded lock from the dry run (all 55 updates, includinganthropic1.10 andfilelock4). This did not includememu-py1.5.1, becauseuv lock --upgradekeeps==pins.After merge: the Dependabot tab under Insights > Dependency graph shows both entries. Use "Check for updates" there to start a run at any time.
🤖 Generated with Claude Code