Skip to content

chore(deps): reduce uv dev dependency update cadence - #1423

Merged
amimas merged 3 commits into
mainfrom
dependabot-schedule-update
Sep 13, 2026
Merged

amimas merged 3 commits into
mainfrom
dependabot-schedule-update

Conversation

@amimas

@amimas amimas commented Sep 12, 2026 •

Copy link
Copy Markdown
Collaborator

I feel the weekly PRs opened by dependabot are a bit noisy. Usually they are just patch updates for various dev tools. There's a 5 PR limit and most of the time they are taken up by these dev tools update. Main goal of this PR is to reduce the frequency of dev tools update. Below are the changes that have been made to dependabot config.

  • Split uv updates into production and development dependency groups
  • Keep runtime deps on the normal weekly schedule
  • Set dev deps to a monthly schedule to reduce update noise
  • Merge overlapping test/lint patterns into a single dev tooling group so that they are combined into a single PR
  • Keep documentation and release tooling groups separate

I'm not sure there's an easy and reliable way to validate the config. I tested it in my forked repo and dependabot didn't seem to complain about the config. So, it should be good syntax-wise.

- Split uv updates into production and development dependency groups
- Keep runtime deps on the normal weekly schedule
- Set dev deps to a monthly schedule to reduce update noise
- Merge overlapping test/lint patterns into a single dev tooling group
- Keep documentation and release tooling groups separate
@rickbrouwer

Copy link
Copy Markdown
Collaborator

Two uv blocks share the same directory: "/", which I don't think Dependabot accepts.
This exact pattern is still open (dependabot/dependabot-core#4672), though I haven't checked whether it was implemented via another issue in the meantime.
Docs also state that multiple blocks for one ecosystem must not have overlapping directories: https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#directories-or-directory

Maybe we can use cooldown? With cooldown, I think you get what you want. Within a single uv block, without the overlapping-directories problem. Then keep the interval weekly and the existing groups, and add:

    cooldown:
      default-days: 30
      include:
        - "pytest*"
        - "mypy*"
        - "types-*"
        - "ruff"
        - "prek"
        - "commitizen"
        - "mkdocs*"

Then the dev tool releases get batched into one PR per group per month, while the other keep the default cooldown and weekly cadence.

@amimas
amimas deployed to Integrate Pull Request September 12, 2026 18:48 — with GitHub Actions Active
@amimas
amimas deployed to Integrate Pull Request September 12, 2026 18:48 — with GitHub Actions Active
@amimas

amimas commented Sep 12, 2026 •

Copy link
Copy Markdown
Collaborator Author

Thank you for that suggestion. Pushed an update using cooldown config. I think that should work. Just noticed this update triggered a dependabot config validation that passed. This didn't run for the previous commit - not sure why.

Only thing I don't like here is that we have duplicate list of package names. I considered using yaml anchor and alias, but wasn't sure if dependabot allows adding keys at the top level for defining anchor-alias.

Aside from that, do you think it's worth keeping docs and release tools as separate group? Should we merge those into the single dev-tooling group?

@rickbrouwer
rickbrouwer self-requested a review September 12, 2026 18:57
@rickbrouwer

Copy link
Copy Markdown
Collaborator

Only thing I don't like here is that we have duplicate list of package names. I considered using yaml anchor and alias, but wasn't sure if dependabot allows adding keys at the top level for defining anchor-alias.

Dependabot don't support aliases.
For the duplication, you can flip include into exclude listing the runtime deps instead. Then the cooldown list no longer overlaps the group patterns. Isn't it?

Aside from that, do you think it's worth keeping docs and release tools as separate group? Should we merge those into the single dev-tooling group?

I'd keep documentation and release-tools separate.

@rickbrouwer

rickbrouwer commented Sep 12, 2026 •

Copy link
Copy Markdown
Collaborator
    cooldown:
      default-days: 30
      exclude:
        - "certifi"
        - "cli-ui"
        - "jinja2"
        - "luddite"
        - "markupsafe"
        - "mergedeep"
        - "packaging"
        - "python-gitlab"
        - "requests"
        - "rich"
        - "ruamel.yaml"
        - "yamlpath"

@amimas

amimas commented Sep 12, 2026

Copy link
Copy Markdown
Collaborator Author

I think let's go with your original suggestion. Using include with cooldown feels more natural or intuitive when reading the config.

Should we merge this?

@amimas
amimas deployed to Integrate Pull Request September 13, 2026 01:40 — with GitHub Actions Active
@amimas
amimas deployed to Integrate Pull Request September 13, 2026 01:40 — with GitHub Actions Active
@amimas

amimas commented Sep 13, 2026

Copy link
Copy Markdown
Collaborator Author

Going ahead with merging this change before tomorrow's dependabot run, since you've reviewed the latest update already and approved. Thank you for the suggestions/hints.

@amimas
amimas enabled auto-merge (squash) September 13, 2026 01:45
@amimas
amimas merged commit 630a02e into main Sep 13, 2026
23 checks passed
@amimas
amimas deleted the dependabot-schedule-update branch September 13, 2026 02:01

This branch was successfully deployed

1 active deployment
Integrate Pull Request — 82ae9207 Deployed Sep 13, 2026 by amimas via Acceptance Tests / GitLab Premium #241
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants