Repository navigation
chore(deps): reduce uv dev dependency update cadence - #1423
Conversation
- Split uv updates into production and development dependency groups - Keep runtime deps on the normal weekly schedule - Set dev deps to a monthly schedule to reduce update noise - Merge overlapping test/lint patterns into a single dev tooling group - Keep documentation and release tooling groups separate
|
Two uv blocks share the same directory: "/", which I don't think Dependabot accepts. Maybe we can use Then the dev tool releases get batched into one PR per group per month, while the other keep the default cooldown and weekly cadence. |
…em with same directory
|
Thank you for that suggestion. Pushed an update using Only thing I don't like here is that we have duplicate list of package names. I considered using yaml anchor and alias, but wasn't sure if dependabot allows adding keys at the top level for defining anchor-alias. Aside from that, do you think it's worth keeping docs and release tools as separate group? Should we merge those into the single dev-tooling group? |
Dependabot don't support aliases.
I'd keep |
|
|
I think let's go with your original suggestion. Using Should we merge this? |
|
Going ahead with merging this change before tomorrow's dependabot run, since you've reviewed the latest update already and approved. Thank you for the suggestions/hints. |
I feel the weekly PRs opened by dependabot are a bit noisy. Usually they are just patch updates for various dev tools. There's a 5 PR limit and most of the time they are taken up by these dev tools update. Main goal of this PR is to reduce the frequency of dev tools update. Below are the changes that have been made to dependabot config.
Split uv updates into production and development dependency groupsI'm not sure there's an easy and reliable way to validate the config. I tested it in my forked repo and dependabot didn't seem to complain about the config. So, it should be good syntax-wise.