Skip to content

ci(dependabot): update the Python projects as uv projects and cover every manifest - #497

Merged
jbonofre merged 2 commits into
apache:mainfrom
kayemkim:ci/dependabot-uv
Oct 3, 2026
Merged

jbonofre merged 2 commits into
apache:mainfrom
kayemkim:ci/dependabot-uv

Conversation

@kayemkim

@kayemkim kayemkim commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Dependabot has not opened a single Python version update since the configuration landed in #282. The reason is the ecosystem, not the schedule: the Python projects keep open ranges in pyproject.toml and pin in uv.lock, and the "pip" ecosystem reads requirements.txt and pyproject.toml pins but not uv.lock, so the weekly run had nothing to bump. The two PRs that did touch a uv.lock (#202, #427 on orionbelt) were security updates, which come from the dependency graph regardless of this file. The "uv" ecosystem updates pyproject.toml and uv.lock together.

The directory list had also drifted. #333 moved the Databricks Python project under python/ and added a Java module, so the pip entry pointed at a directory with no manifest and the Java module was outside the Maven group; six converters (nvidia, ontology, sigma, microsoft, cube, thoughtspot) were added after the file was written. Every directory with a pyproject.toml is now listed, and databricks/java joins the Maven group. wisdom has no committed uv.lock, but the uv fetcher in dependabot-core only requires a pyproject.toml, so it stays in the list rather than being dropped.

I kept an explicit list rather than a /converters/* glob, since several directories under converters have no uv manifest and the docs do not say whether such a directory is skipped or fails the run. Once this is merged, the Dependabot tab under Insights should show one job per directory; I cannot see that page, so a glance from a maintainer would confirm it picked everything up.

Related Issues

None. Follow-up to the configuration added in #282.

Checklist

Specification, Ontology, Converters, Validation, Documentation, Examples: not applicable, this changes only .github/dependabot.yml.

Tests

  • All existing tests pass (no workflow is triggered by this file; YAML parses, git diff --check is clean)

Compliance

  • ASF license headers are present on all new source files (no new files)
  • No third-party dependencies are added without PMC/IPMC approval

…very manifest

The Python projects pin their dependencies in uv.lock and keep open
ranges in pyproject.toml. Dependabot's "pip" ecosystem reads
requirements.txt and pyproject.toml pins but not uv.lock, so the weekly
Python update has had nothing to bump since the configuration landed;
only security updates, which come from the dependency graph, have been
opened. Switching the entry to "uv" lets Dependabot update pyproject.toml
and uv.lock together.

The directory list also drifted: the Databricks converter moved its
Python project under python/ and gained a Java module, and six
converters were added after the configuration was written. Each
directory with a pyproject.toml and a committed uv.lock is listed, and
the Java module joins the Maven group. The wisdom converter has no
committed uv.lock yet and is left out until it does.

Generated-by: Claude Code
@github-actions github-actions Bot added the infra label Oct 2, 2026
@jbonofre
jbonofre self-requested a review October 2, 2026 15:27
Comment thread .github/dependabot.yml
wisdom has no committed uv.lock, but Dependabot's uv fetcher only needs
a pyproject.toml, so it can be updated with the other Python projects
instead of being dropped from the configuration.

Generated-by: Claude Code
@jbonofre
jbonofre merged commit 689fafa into apache:main Oct 3, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants