chore(deps): stop Dependabot ratcheting uv dependency floors - #4087
Merged
Merged
Conversation
Dependabot's default versioning strategy raises the pyproject.toml floor to whatever version it just resolved, even when the code works fine on much older releases. #4067 is the example: it moved the floor to `packaging>=26.2` although OCS only uses `Version` and `InvalidVersion`, stable since well before 20.0. Mechanically-raised floors cost resolver headroom — they make the project unresolvable alongside any future co-installed package that caps the dependency, for no benefit. Set `versioning-strategy: increase-if-necessary` on the uv ecosystem so Dependabot updates uv.lock alone and only edits pyproject.toml when the new version genuinely falls outside the declared constraint. `increase-if-necessary` rather than `lockfile-only` so intentionally pinned or capped deps (`pyTelegramBotAPI==4.12.0`, `Django<6`, `django-oauth-toolkit<4.0.0`) can still be updated — `lockfile-only` would freeze them out of updates entirely. Also restore the `packaging` floor to `>=23.2` (its value before #4067). The resolved version in uv.lock stays 26.2. Co-authored-by: Simon Kelly <249606+snopoke@users.noreply.github.com>
snopoke
approved these changes
Aug 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Product Description
No user-facing change. Repo hygiene for how Dependabot maintains Python dependency constraints.
Technical Description
Follow-up to #4067 (review comment).
Dependabot's default versioning strategy raises the
pyproject.tomlfloor to whatever version it just resolved, whether or not the code needs it. #4067 is the example: it moved the floor topackaging>=26.2, but OCS uses onlyVersionandInvalidVersion— stable since well beforepackaging20.0.A mechanically-raised floor costs resolver headroom for nothing: it makes the project unresolvable alongside any future co-installed package that caps the dependency, without buying any capability the code actually uses.
Two changes:
.github/dependabot.yml— setversioning-strategy: "increase-if-necessary"on theuvecosystem. Dependabot now updatesuv.lockalone and editspyproject.tomlonly when the new version genuinely falls outside the declared constraint.increase-if-necessaryrather thanlockfile-onlydeliberately:lockfile-onlynever touches the manifest, which would freeze the intentionally pinned/capped deps (pyTelegramBotAPI==4.12.0,Django<6,django-oauth-toolkit>=3.2.0,<4.0.0) out of updates entirely, since their new versions fall outside the declared range by construction.The
npm,github-actionsandpre-commitecosystems are left alone — out of scope for this follow-up.pyproject.toml/uv.lock— restore thepackagingfloor to>=23.2, its value before chore(deps): bump packaging from 23.2 to 26.2 #4067. The resolved version inuv.lockstays 26.2; only the rootrequires-distspecifier changes. This stands on its own regardless of whether the config change lands.Migrations
No migrations — dependency metadata only.
Demo
The whole diff is three lines of substance:
- package-ecosystem: "uv" directory: "/" open-pull-requests-limit: 5 schedule: interval: "monthly" + versioning-strategy: "increase-if-necessary"Docs and Changelog
Verification notes — please read before merging
requires-distspecifier inuv.lockby hand rather than runninguv lock, becauseuvcommands were not permitted in my sandbox. The edit is what a re-lock produces for a floor loosening that does not change resolution (26.2 satisfies>=23.2, and nothing else in the tree constrainspackaging), but CI'scheck-uv-lockjob is the authority — if it fails, runninguv locklocally will fix it.versioning-strategyis honoured for theuvecosystem specifically. It is supported for the Python ecosystems generally anduvsupport was built on that code path, but worth a glance at Insights → Dependency graph → Dependabot after merge: an unsupported key surfaces there as a config error, and the next monthlyuvPR is the real confirmation.pytest,uv lock --check,pre-commit— nouv/pythonexecution available in this sandbox. Nothing changed here is importable code, so CI'scheck-yaml/check-toml/check-uv-lockcover it.Generated with Claude Code