Repository navigation
ci(dependabot): move pydantic-core only together with pydantic - #159
Merged
Merged
Conversation
pydantic pins pydantic-core exactly and pydantic-core is released ahead of pydantic (PyPI today: pydantic 2.13.5 -> pydantic-core==2.46.5, latest pydantic-core 2.49.0). Dependabot's pip updater does not resolve requirements/constraints files against package metadata, so it proposed pydantic-core on its own (#31, #144, #151, #157), which cannot install. Ignore pydantic-core in the pip config and put pydantic in its own group; a pydantic pull request needs its pydantic-core pin moved by hand.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Dependabot keeps proposing
pydantic-coreon its own (#31, #144, #151, #157). pydantic pins its core exactly (pydantic 2.13.5requirespydantic-core==2.46.5), so every one of these pull requests fails to install. The@dependabot ignore this dependencycomment on #151 had no effect: that form only works on single-dependency pull requests. On a grouped pull request the command needs the name (@dependabot ignore pydantic-core), so the update came back in the python-minor-patch group as #157.Why Dependabot does this
.in, Pipfile or Poetry lock), the pipPipVersionResolverdoes not run pip or a resolver. It takes the latest version and only checks it against the pinned dependencies inpyproject.toml. So pydantic's==pin on pydantic-core is never consulted.Why an
ignoreand not only apydanticgroupA group with patterns
[pydantic, pydantic-core]would not be enough. Each member of a group is still bumped to its own latest version, and the group opens a pull request as soon as any member has an update. With pydantic-core ahead of pydantic, as it is now, that group would contain pydantic-core alone and fail in the same way. Even when both update together, the latest pydantic-core does not have to be the one the latest pydantic pins.Change (only
.github/dependabot.yml, pip block)ignore: - dependency-name: "pydantic-core"(all update types). Ignore conditions are applied before grouping, so pydantic-core is also left out of thepython-minor-patchgroup. Unlike a comment-based ignore, this one is visible and under version control.pydanticgroup (patternpydantic, minor and patch), placed beforepython-minor-patch. A dependency goes into the first group it matches, and the pattern matches the exact name only, notpydantic-core. As a result, the pydantic pull request, which needs a hand edit, does not block the other minor and patch updates.pydanticpull request, setpydantic-coreinconstraints.txtto the version the new pydantic pins (requires_diston PyPI) before merging. CI fails until this is done, so the step cannot be missed by accident.Multi-ecosystem groups are not relevant here: they combine ecosystems (pip, npm, actions) into one pull request and do not change how versions are chosen within pip.
Validation
dependabot-2.0.jsonschema. The schema is strict: a test with an unknown key inignorewas rejected.