Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

📋 Dependabot research: Continue manual dependency management until uv support

Open
#184 8 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
25/100
Issue type
Documentation
Clarity
Needs clarification
Activity status
Stale
Tech stack
github-actions, python

Research direction

Read the dependency workflow in requirements/main.in, requirements/dev.in, requirements/production.in and their compiled .txt files, then review the task dependencies:upgrade and task dependencies:security commands. Compare the linked Dependabot and uv discussions; this issue is complete when the manual-management decision and conditions for revisiting it are clearly recorded.

Written by the indexing model from the issue text.

Description

dependencies enhancement

Executive Summary

After researching Dependabot integration with our current uv-based dependency management workflow, we've decided to continue with manual dependency management for now and revisit when Dependabot adds native uv support.

Current Dependency Workflow

Our project uses a multi-file requirements approach:

  • Source files: requirements/main.in, requirements/dev.in, requirements/production.in (dependencies without pinned versions)
  • Compiled files: requirements/main.txt, requirements/dev.txt, requirements/production.txt (auto-generated with exact pinned versions via uv pip compile)

Existing tools that work well:

  • task dependencies:upgrade - Update all dependencies
  • task dependencies:security - Vulnerability scanning with pip-audit
  • Dependabot security alerts - Already active (GitHub default feature)

Research Findings

1. uv is NOT natively supported by Dependabot (December 2024)

Despite strong community interest:

2. Version Pinning Problem
  • Our .in files specify dependencies without exact versions (e.g., Django not Django==6.0)
  • Only .txt files have exact pinned versions (auto-generated)
  • Dependabot can't effectively monitor .in files without version constraints
  • Monitoring .txt files would create PRs for auto-generated files (breaks our workflow)
3. Current Workaround Requires Major Migration

The recommended approach requires:

  • Migrating to pyproject.toml for dependency specification
  • GitHub Action to auto-regenerate lockfiles when Dependabot updates pyproject.toml
  • Significant project restructuring

See: Keep uv.lock file up-to-date with Dependabot updates

4. pip-compile Support Has Limitations

While Dependabot supports pip-compile, there are known issues:

  • Formatting changes between pip-tools versions
  • Transitive dependency conflicts

Decision: Continue Manual Workflow

Reasons:

  1. ✅ uv is not yet supported natively by Dependabot
  2. ✅ Current workflow with task dependencies:* commands works well
  3. ✅ Security alerts are already active (most critical feature)
  4. ✅ Migration to pyproject.toml would be a significant change
  5. ✅ Can revisit when Dependabot adds native uv support

What We Keep Monitoring

  • Dependabot security alerts (already active)
  • Manual updates via task dependencies:upgrade
  • Vulnerability scanning via task dependencies:security
  • Progress on the uv support issues linked above

When to Revisit

We'll reconsider Dependabot version updates when:

  • Native uv support is added to Dependabot, OR
  • We migrate to pyproject.toml for other reasons

References

Dominant language
Python
Stars
17
Forks
27
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from PythonIreland/website

All issues in PythonIreland/website

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.