Skip to content

ci(dependabot): move pydantic-core only together with pydantic - #159

Merged
tunjayoff merged 1 commit into
mainfrom
ci/dependabot-pydantic
Oct 6, 2026
Merged

tunjayoff merged 1 commit into
mainfrom
ci/dependabot-pydantic

Conversation

@tunjayoff

Copy link
Copy Markdown
Owner

Problem

Dependabot keeps proposing pydantic-core on its own (#31, #144, #151, #157). pydantic pins its core exactly (pydantic 2.13.5 requires pydantic-core==2.46.5), so every one of these pull requests fails to install. The @dependabot ignore this dependency comment on #151 had no effect: that form only works on single-dependency pull requests. On a grouped pull request the command needs the name (@dependabot ignore pydantic-core), so the update came back in the python-minor-patch group as #157.

Why Dependabot does this

  • For plain requirements and constraints files (no .in, Pipfile or Poetry lock), the pip PipVersionResolver does not run pip or a resolver. It takes the latest version and only checks it against the pinned dependencies in pyproject.toml. So pydantic's == pin on pydantic-core is never consulted.
  • pydantic-core is released ahead of pydantic. Today PyPI has pydantic-core 2.49.0, but the newest pydantic, 2.13.5, still pins 2.46.5.

Why an ignore and not only a pydantic group

A group with patterns [pydantic, pydantic-core] would not be enough. Each member of a group is still bumped to its own latest version, and the group opens a pull request as soon as any member has an update. With pydantic-core ahead of pydantic, as it is now, that group would contain pydantic-core alone and fail in the same way. Even when both update together, the latest pydantic-core does not have to be the one the latest pydantic pins.

Change (only .github/dependabot.yml, pip block)

  • ignore: - dependency-name: "pydantic-core" (all update types). Ignore conditions are applied before grouping, so pydantic-core is also left out of the python-minor-patch group. Unlike a comment-based ignore, this one is visible and under version control.
  • A new pydantic group (pattern pydantic, minor and patch), placed before python-minor-patch. A dependency goes into the first group it matches, and the pattern matches the exact name only, not pydantic-core. As a result, the pydantic pull request, which needs a hand edit, does not block the other minor and patch updates.
  • Manual step: in a pydantic pull request, set pydantic-core in constraints.txt to the version the new pydantic pins (requires_dist on PyPI) before merging. CI fails until this is done, so the step cannot be missed by accident.

Multi-ecosystem groups are not relevant here: they combine ecosystems (pip, npm, actions) into one pull request and do not change how versions are chosen within pip.

Validation

  • The YAML parses, and the file validates against the SchemaStore dependabot-2.0.json schema. The schema is strict: a test with an unknown key in ignore was rejected.

pydantic pins pydantic-core exactly and pydantic-core is released ahead of
pydantic (PyPI today: pydantic 2.13.5 -> pydantic-core==2.46.5, latest
pydantic-core 2.49.0). Dependabot's pip updater does not resolve
requirements/constraints files against package metadata, so it proposed
pydantic-core on its own (#31, #144, #151, #157), which cannot install.

Ignore pydantic-core in the pip config and put pydantic in its own group;
a pydantic pull request needs its pydantic-core pin moved by hand.
@tunjayoff
tunjayoff merged commit 0c9b72f into main Oct 6, 2026
3 checks passed
@tunjayoff
tunjayoff deleted the ci/dependabot-pydantic branch October 6, 2026 19:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant