📋 Dependabot research: Continue manual dependency management until uv support
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 25/100
- Loại issue
- Tài liệu
- Độ rõ ràng
- Cần làm rõ
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- github-actions, python
- Lĩnh vực
- devops, documentation
Hướng nghiên cứu
Read the dependency workflow in requirements/main.in, requirements/dev.in, requirements/production.in and their compiled .txt files, then review the task dependencies:upgrade and task dependencies:security commands. Compare the linked Dependabot and uv discussions; this issue is complete when the manual-management decision and conditions for revisiting it are clearly recorded.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Executive Summary
After researching Dependabot integration with our current uv-based dependency management workflow, we've decided to continue with manual dependency management for now and revisit when Dependabot adds native uv support.
Current Dependency Workflow
Our project uses a multi-file requirements approach:
- Source files:
requirements/main.in,requirements/dev.in,requirements/production.in(dependencies without pinned versions) - Compiled files:
requirements/main.txt,requirements/dev.txt,requirements/production.txt(auto-generated with exact pinned versions viauv pip compile)
Existing tools that work well:
task dependencies:upgrade- Update all dependenciestask dependencies:security- Vulnerability scanning with pip-audit- Dependabot security alerts - Already active (GitHub default feature)
Research Findings
1. uv is NOT natively supported by Dependabot (December 2024)
Despite strong community interest:
- Support python uv as pip-compile compatible replacement (185+ 👍)
- Support updating uv.lock (572+ 👍)
- See this interesting comment: GitHub's response on uv.lock support status
2. Version Pinning Problem
- Our
.infiles specify dependencies without exact versions (e.g.,DjangonotDjango==6.0) - Only
.txtfiles have exact pinned versions (auto-generated) - Dependabot can't effectively monitor
.infiles without version constraints - Monitoring
.txtfiles would create PRs for auto-generated files (breaks our workflow)
3. Current Workaround Requires Major Migration
The recommended approach requires:
- Migrating to
pyproject.tomlfor dependency specification - GitHub Action to auto-regenerate lockfiles when Dependabot updates
pyproject.toml - Significant project restructuring
See: Keep uv.lock file up-to-date with Dependabot updates
4. pip-compile Support Has Limitations
While Dependabot supports pip-compile, there are known issues:
- Formatting changes between pip-tools versions
- Transitive dependency conflicts
Decision: Continue Manual Workflow
Reasons:
- ✅ uv is not yet supported natively by Dependabot
- ✅ Current workflow with
task dependencies:*commands works well - ✅ Security alerts are already active (most critical feature)
- ✅ Migration to pyproject.toml would be a significant change
- ✅ Can revisit when Dependabot adds native uv support
What We Keep Monitoring
- Dependabot security alerts (already active)
- Manual updates via
task dependencies:upgrade - Vulnerability scanning via
task dependencies:security - Progress on the uv support issues linked above
When to Revisit
We'll reconsider Dependabot version updates when:
- Native uv support is added to Dependabot, OR
- We migrate to pyproject.toml for other reasons
References
- Ngôn ngữ chính
- Python
- Star
- 17
- Fork
- 27
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của PythonIreland/website
-
PSF Grant -Urgent Đang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 15/100
PythonIreland/website#205 ·
-
Sponsorship Brochure- Urgent! Đang mở
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 25/100
PythonIreland/website#204 ·
-
dependencies enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 52/100
PythonIreland/website#187 ·
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
PythonIreland/website#177 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100
PythonIreland/website#171 ·
Tất cả issue của PythonIreland/website
Issue tương tự
-
[Bug] reef-hermes tells me to resume with hermes --resume, which does not work from my shell Đang mởarea: harness bug status: needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
Human-Agent-Society/reef#625 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 80/100
learningequality/kolibri#15351 · 2 bình luận ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
Name consistency Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
eellak/triplestore#65 · 1 bình luận ·