ci(dependabot): update the Python projects as uv projects and cover every manifest - #497
Merged
Merged
Conversation
…very manifest The Python projects pin their dependencies in uv.lock and keep open ranges in pyproject.toml. Dependabot's "pip" ecosystem reads requirements.txt and pyproject.toml pins but not uv.lock, so the weekly Python update has had nothing to bump since the configuration landed; only security updates, which come from the dependency graph, have been opened. Switching the entry to "uv" lets Dependabot update pyproject.toml and uv.lock together. The directory list also drifted: the Databricks converter moved its Python project under python/ and gained a Java module, and six converters were added after the configuration was written. Each directory with a pyproject.toml and a committed uv.lock is listed, and the Java module joins the Maven group. The wisdom converter has no committed uv.lock yet and is left out until it does. Generated-by: Claude Code
jbonofre
self-requested a review
October 2, 2026 15:27
jbonofre
requested changes
Oct 2, 2026
wisdom has no committed uv.lock, but Dependabot's uv fetcher only needs a pyproject.toml, so it can be updated with the other Python projects instead of being dropped from the configuration. Generated-by: Claude Code
jbonofre
approved these changes
Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Dependabot has not opened a single Python version update since the configuration landed in #282. The reason is the ecosystem, not the schedule: the Python projects keep open ranges in pyproject.toml and pin in uv.lock, and the "pip" ecosystem reads requirements.txt and pyproject.toml pins but not uv.lock, so the weekly run had nothing to bump. The two PRs that did touch a uv.lock (#202, #427 on orionbelt) were security updates, which come from the dependency graph regardless of this file. The "uv" ecosystem updates pyproject.toml and uv.lock together.
The directory list had also drifted. #333 moved the Databricks Python project under python/ and added a Java module, so the pip entry pointed at a directory with no manifest and the Java module was outside the Maven group; six converters (nvidia, ontology, sigma, microsoft, cube, thoughtspot) were added after the file was written. Every directory with a pyproject.toml is now listed, and databricks/java joins the Maven group. wisdom has no committed uv.lock, but the uv fetcher in dependabot-core only requires a pyproject.toml, so it stays in the list rather than being dropped.
I kept an explicit list rather than a /converters/* glob, since several directories under converters have no uv manifest and the docs do not say whether such a directory is skipped or fails the run. Once this is merged, the Dependabot tab under Insights should show one job per directory; I cannot see that page, so a glance from a maintainer would confirm it picked everything up.
Related Issues
None. Follow-up to the configuration added in #282.
Checklist
Specification, Ontology, Converters, Validation, Documentation, Examples: not applicable, this changes only
.github/dependabot.yml.Tests
git diff --checkis clean)Compliance