Skip to content

chore(ci): SHA-pin third-party actions, add uv Dependabot coverage - #205

Merged
jfrench9 merged 1 commit into
mainfrom
chore/ci-dependency-posture
Sep 1, 2026
Merged

chore(ci): SHA-pin third-party actions, add uv Dependabot coverage#205
jfrench9 merged 1 commit into
mainfrom
chore/ci-dependency-posture

Conversation

@jfrench9

@jfrench9 jfrench9 commented Sep 1, 2026

Copy link
Copy Markdown
Member

Brings this repo up to the CI dependency posture the three frontend apps landed today. It was the fleet's blind spot: dependabot.yml declared only the github-actions ecosystem, so nothing was ever proposed for pyproject.toml or uv.lock — the runtime dependencies of a published package had no update coverage at all.

Changes

Dependabot gains the uv ecosystem, mirroring the robosystems backend.

Four third-party actions pinned by commit SHA. GitHub-owned actions (actions/checkout, actions/setup-python) stay on tags, matching the frontends' convention. The action-gh-release and claude-code-action SHAs are the ones already running across the three frontends.

Two pins worth a closer look:

  • pypa/gh-action-pypi-publish moves from the release/v1 branch to dc37677b # v1.14.2. That commit is the current release/v1 head, so nothing about what runs today changes — it just stops the reference being a moving branch, and gives Dependabot a version to track. This is the action that publishes to PyPI, so an unpinned moving reference was the most consequential one in the fleet.
  • astral-sh/setup-uv is pinned where it already sat, v9.0.0, and majors are now ignored — closing the loop on PR chore(deps): bump astral-sh/setup-uv from 9.0.0 to 10.0.1 #203 and the two earlier declines.

Why v9 rather than matching the backend's v8.3.2

The backend holds at v8.3.2 because v9 flipped prune-cache to false and would grow its uv cache. This repo is not downgraded to match, because neither v9's nor v10's breaking change actually bites here: no workflow triggers on release, pull_request_target or workflow_run, which is the only surface v10's cache guard touches. Downgrading would be churn with a real behavior change and no security gain.

So what the fleet shares is the rule — don't take setup-uv majors without a deliberate decision — not the version number. The comment in dependabot.yml says exactly that, rather than copying the backend's cache rationale, which isn't true of this repo.

Note on the uv block

Intentionally no groups. Unlike the backend there's no version-coupled family here — httpx, pydantic, attrs and typing-extensions move independently — and majors on those land on consumers of the published package, so they're left ungrouped for individual triage.

Verification

All workflow YAML parses, and the dependabot.yml schema is validated by GitHub's own check on this PR. Changes are workflow/config YAML only; no Python source touched.

…ndabot coverage

This repo had no Dependabot coverage for the packages it actually depends on
— dependabot.yml declared only the github-actions ecosystem, so nothing was
ever proposed for pyproject.toml or uv.lock. Adds the uv ecosystem, mirroring
the robosystems backend, and pins the four third-party actions by commit SHA.

Pinning follows the frontend apps' convention: third-party actions by SHA,
GitHub-owned actions (actions/checkout, actions/setup-python) left on tags.
The action-gh-release and claude-code-action SHAs are the ones already running
across the three frontends.

Two pins worth calling out:

- pypa/gh-action-pypi-publish moves from the `release/v1` branch to
  dc37677b # v1.14.2. That commit *is* the current release/v1 head, so this
  changes nothing about what runs today — it just stops the reference being a
  moving branch, and gives Dependabot a version it can track.
- astral-sh/setup-uv is pinned where it already sat, v9.0.0, and majors are
  now ignored. The backend holds at v8.3.2 for cache reasons; this repo is
  not downgraded to match, because neither v9's nor v10's breaking change
  actually bites here — no workflow triggers on release, pull_request_target
  or workflow_run, which is the only surface v10's cache guard touches. What
  the fleet shares is the rule, not the version.

The uv block intentionally has no groups: unlike the backend, there is no
version-coupled family here (httpx, pydantic, attrs and typing-extensions are
independent), and majors on those land on consumers of the published package,
so they are left ungrouped for individual triage.
@jfrench9
jfrench9 merged commit 25c4609 into main Sep 1, 2026
5 checks passed
@jfrench9
jfrench9 deleted the chore/ci-dependency-posture branch September 1, 2026 17:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant