build(deps-dev): bump the development-minor-patch group across 1 directory with 2 updates - #59
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Two independent defects keep every Dependabot pull request in this
repository red. Both are fixed here.
1. The lock-sync gate can never pass for Dependabot.
.github/workflows/ci.yml requires requirements.lock to change whenever
requirements.txt changes, and requirements-dev.lock whenever
requirements-dev.txt changes. Dependabot's pip ecosystem edits only the
.txt manifests. It cannot regenerate these locks: dependabot-core treats
a file as a pip-compile output only when the name ends in .txt
(python/lib/dependabot/python/pip_compile_file_matcher.rb, which checks
`name.end_with?(".txt")` and looks for a sibling .in manifest). Files
named requirements.lock and requirements-dev.lock are never fetched as
lockfiles at all. #59 and #63 both fail on this.
.github/workflows/dependabot-lockfiles.yml now recompiles both locks on
Dependabot branches using the exact uv command recorded in their headers,
runs `uv pip install`, `black --check .`, `ruff check .` and `pytest -q`
against the recompiled result, and pushes the refreshed locks back to the
pull request branch. No --upgrade is passed, so uv reads the existing
output file as preferences and only the pins the manifest change forces
will move. The job is gated on
`github.event.pull_request.user.login == 'dependabot[bot]'` and on the
head branch living in this repository, and it is the only place that
holds `contents: write`.
The ci.yml lock-sync step now skips Dependabot pull requests, because the
new workflow satisfies that invariant for them by construction and runs a
strictly larger check. It is unchanged for every human pull request.
2. `ruff check .` silently redefines itself on a ruff upgrade.
There was no ruff configuration in the repository, so `ruff check .` ran
whatever ruff's built-in default selection happened to be. That default
changed in ruff 0.16. On the current tree:
ruff 0.15.21: All checks passed!
ruff 0.16.4: Found 124 errors.
(48 UP006, 36 BLE001, 17 I001, 10 UP045, 7 UP035, ...)
So #63, which bumps ruff 0.15.21 -> 0.16.4, would still fail after the
lockfile problem is fixed. ruff.toml now pins
`select = ["E4", "E7", "E9", "F"]`, which is the rule set this repository
has actually been enforcing. This makes the existing contract explicit
instead of letting a tool upgrade rewrite it. Adopting the additional
rules stays available as a deliberate, separate change.
Verified locally:
- `actionlint .github/workflows/dependabot-lockfiles.yml
.github/workflows/ci.yml` is clean.
- Recompiling both locks on the current main is a no-op apart from the uv
version string in the header comment; every pin is preserved.
- Simulating #63 on top of main (its requirements.txt and
requirements-dev.txt applied, then both locks recompiled) moves exactly
six pins in each lock -- gunicorn, mypy, python-dotenv, ruff, twilio,
typer -- and nothing else. In a Python 3.11 venv from the recompiled
requirements-dev.lock: `black --check .` passes (24 files),
`pytest -q` passes (30 passed), and `ruff check .` passes with the new
ruff.toml under both 0.15.21 and 0.16.4.
Claude-Session: https://claude.ai/code/session_01XpuXXVrWCZk3Tq5NRXejNP
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
|
@dependabot rebase Context: #64 just merged. |
…ctory with 2 updates Bumps the development-minor-patch group with 2 updates in the / directory: [pre-commit](https://github.com/pre-commit/pre-commit) and [mkdocs-material](https://github.com/squidfunk/mkdocs-material). Updates `pre-commit` from 4.6.0 to 4.6.2 - [Release notes](https://github.com/pre-commit/pre-commit/releases) - [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md) - [Commits](pre-commit/pre-commit@v4.6.0...v4.6.2) Updates `mkdocs-material` from 9.7.6 to 9.7.7 - [Release notes](https://github.com/squidfunk/mkdocs-material/releases) - [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG) - [Commits](squidfunk/mkdocs-material@9.7.6...9.7.7) --- updated-dependencies: - dependency-name: mkdocs-material dependency-version: 9.7.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: development-minor-patch - dependency-name: pre-commit dependency-version: 4.6.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: development-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
58fb885 to
5c70cc8
Compare
|
Merging with What did run and pass on this PR's head commit:
The stuck Bazel lane is a runner-capacity item for the repository owner, tracked separately. |
Bumps the development-minor-patch group with 2 updates in the / directory: pre-commit and mkdocs-material.
Updates
pre-commitfrom 4.6.0 to 4.6.2Release notes
Sourced from pre-commit's releases.
Changelog
Sourced from pre-commit's changelog.
Commits
9767b6cv4.6.242ee3ffMerge pull request #3743 from pre-commit/npm-build-scripts-11-x3056619fixlanguage: nodefor hooks with build scripts and npm 11.x242ce8av4.6.1766e550Merge pull request #3727 from pre-commit/dedupe1558d06Merge pull request #3726 from pre-commit/exists-faster8a1c47aavoid duplicate files in --all-files during conflict2e01c99faster check of rev existing locally as a commit3613bf2Merge pull request #3701 from pre-commit/autoupdate-repos1d811d9Return an error for invalid --repoUpdates
mkdocs-materialfrom 9.7.6 to 9.7.7Release notes
Sourced from mkdocs-material's releases.
Changelog
Sourced from mkdocs-material's changelog.
... (truncated)
Commits
b3e6dd8Prepare 9.7.7 release52fb6beMerge commit from fork901e633AddedSECURITY.mdwith EOL notice5b36f2aBump js-yaml from 4.1.1 to 4.2.0 (#8598)2d11e7bBump form-data from 3.0.4 to 3.0.5 (#8597)ae05a53Bump esbuild from 0.27.2 to 0.28.1 (#8596)434af93Bump shell-quote from 1.7.3 to 1.8.4 (#8593)4447cdaDocumentation (#8590)8f8d551Updated copyright year (#8588)08d8514Bump fast-uri from 3.0.3 to 3.1.2 (#8587)