🤖 Integrate Renovatebot for Automated Dependency Updates
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 52/100
Hướng nghiên cứu
Start with the proposed renovate.json configuration and inspect the requirements/.in and requirements/.txt workflow, including task dependencies:upgrade. Install the Mend Renovate GitHub App, add the configuration, merge the onboarding PR, and verify that generated dependency-update PRs include the expected source and compiled-file changes and pass CI.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Overview
Explore integrating Renovatebot as our automated dependency management solution. This complements our recent migration to uv while providing automated dependency updates without requiring migration to pyproject.toml immediately.
Why Renovatebot?
Following discussion in #184, Renovatebot emerged as a superior alternative to Dependabot for our workflow:
✅ Advantages over Manual Workflow
- Automated security updates: Get notified of vulnerabilities with automated fix PRs
- Time savings: No more manual
task dependencies:upgraderuns - Granular control: Group related updates (e.g., Django ecosystem), schedule updates (e.g., Mondays only)
- Better visibility: Track all dependency updates in one place with proper PR descriptions
✅ Advantages over Dependabot
Based on research and community feedback (see #184):
- ✅ Native
uvsupport: Handles bothuv.lockand pip-compile workflows - ✅ Better lock file handling: No issues with marking security fixes as resolved without updating locks
- ✅ More mature: ~10 years old, actively maintained
- ✅ Better configuration: Advanced grouping, scheduling, automerge options
- ✅ Higher API limits: 15,000 requests/hour vs 5,000/hour
✅ Works with Our Current Workflow
Renovatebot supports our current requirements/*.in → requirements/*.txt (pip-compile) workflow:
- Updates source files (
.in) - Automatically regenerates compiled files (
.txt) - Creates PRs with both changes included
Heroku Native uv Support
Heroku now supports uv natively (announcement, docs) as of May 2025.
Requirements for Heroku uv support:
pyproject.toml+uv.lock+.python-version- Must remove
requirements.txtfiles (other package managers take precedence)
Implication: To use Heroku's native uv support, we'd need to migrate from our current .in/.txt workflow to pyproject.toml + uv.lock.
Renovatebot advantage: Supports BOTH workflows, so we can:
- Enable Renovatebot now with our current pip-compile setup
- Migrate to
pyproject.toml+uv.lockwhen ready for Heroku's native uv support - Renovatebot will continue working seamlessly after migration
Implementation Cost
Zero cost, minimal setup:
- ✅ Free: Mend Renovate GitHub App is free for open source projects
- ✅ No infrastructure: Cloud-hosted, no self-hosting required
- ✅ 5-minute setup: Install GitHub App + merge onboarding PR
- ✅ No scripts: Just a
renovate.jsonconfig file
Proposed Configuration
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": ["config:recommended"],
"pip-compile": {
"managerFilePatterns": ["requirements/.*\\.txt$"]
},
"pip_requirements": { "enabled": false },
"packageRules": [
{
"groupName": "Django ecosystem",
"matchPackagePatterns": ["^[Dd]jango", "^[Ww]agtail"],
"schedule": ["before 9am on monday"]
},
{
"matchUpdateTypes": ["patch"],
"automerge": true,
"automergeType": "pr"
}
],
"lockFileMaintenance": {
"enabled": true,
"schedule": ["before 9am on the first day of the month"]
}
}
Key features:
- Groups Django/Wagtail updates together
- Schedules updates for Monday mornings
- Auto-merges patch updates (e.g., 6.0.1 → 6.0.2)
- Monthly lock file refresh for transitive dependencies
Migration Path
Phase 1: Enable Renovatebot (current workflow)
- Install Mend Renovate GitHub App
- Configure for pip-compile workflow
- Merge onboarding PR
- Monitor and tune configuration
Phase 2 (Future): Migrate to pyproject.toml + uv.lock
When ready to use Heroku's native uv support:
- Migrate to
pyproject.toml+uv.lock - Update Renovatebot config to use PEP 621 manager
- Remove pip-compile configuration
- Benefit from Heroku's faster uv deployments
Comparison with Manual Workflow
| Aspect | Manual (task dependencies:upgrade) |
Renovatebot |
|---|---|---|
| Frequency | When we remember | Automated schedule |
| Security alerts | Manual monitoring | Automated PRs |
| Granularity | All-or-nothing | Per-package or grouped |
| Test before merge | Manual | CI runs automatically |
| Time investment | ~30min monthly | ~5min to review PRs |
Next Steps
- Community feedback on this proposal
- Install Mend Renovate GitHub App: https://github.com/apps/renovate
- Create
renovate.jsonwith proposed configuration - Merge onboarding PR
- Monitor first round of dependency update PRs
- Fine-tune configuration based on experience
References
- Issue #184: Dependabot research discussion
- Renovatebot pip-compile docs
- Renovatebot PEP 621/uv docs
- Using uv with dependency bots
- Heroku uv support announcement
- Heroku uv buildpack changelog
- Ngôn ngữ chính
- Python
- Star
- 17
- Fork
- 27
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của PythonIreland/website
-
PSF Grant -Urgent Đang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 15/100
PythonIreland/website#205 ·
-
Sponsorship Brochure- Urgent! Đang mở
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 25/100
PythonIreland/website#204 ·
-
dependencies enhancement
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
PythonIreland/website#184 · 8 bình luận ·
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
PythonIreland/website#177 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100
PythonIreland/website#171 ·
Tất cả issue của PythonIreland/website
Issue tương tự
-
[Bug] reef-hermes tells me to resume with hermes --resume, which does not work from my shell Đang mởarea: harness bug status: needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
Human-Agent-Society/reef#625 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 80/100
learningequality/kolibri#15351 · 2 bình luận ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
Name consistency Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
eellak/triplestore#65 · 1 bình luận ·