Skip to content

docs(roadmap): ground dependabot-core upstream assumptions (uv versioning-strategy)#34

Merged
ajbarea merged 1 commit into
mainfrom
docs/ground-dependabot-uv-versioning
May 30, 2026
Merged

docs(roadmap): ground dependabot-core upstream assumptions (uv versioning-strategy)#34
ajbarea merged 1 commit into
mainfrom
docs/ground-dependabot-uv-versioning

Conversation

@ajbarea
Copy link
Copy Markdown
Owner

@ajbarea ajbarea commented May 30, 2026

Sweep stop #5 — grounding techne's own ROADMAP, focused on the two upstream dependabot-core issues it's been waiting on.

#12162 (uv versioning-strategy) — now unblocked ✓

The item said "versioning-strategy: lockfile-only isn't supported for uv yet (#12162, open)." #12162 is now closed (completed, ~2026-02) — uv versioning-strategy support landed. So the queued fix to stop the fleet's ruff/ty floor churn is live: add versioning-strategy: lockfile-only to the uv dependabot entries. One caveat carried into the ROADMAP: #12162 tracked the umbrella feature (its requester wanted increase), so verify uv accepts lockfile-only specifically before the fleet-wide edit.

#14004 (uv workspace mis-targeting) — still open

Re-checked: still open, so kourai's uv-dependabot deferral correctly stands. Re-validated, not changed.

Bonus accuracy fix

The SHA-pinning item said "propagate the check_action_pins.sh guard … only techne enforces it today" — which misreads as "the fleet isn't pin-protected." Verified: every sister already enforces pin-pinning via an inline regex in its own pin-check.yml; only the shared script is techne-only. Reworded so it's clearly a DRY-consolidation step, not a coverage gap.

Docs-only; research(2026-05) provenance inline. Note: the actual fleet-wide lockfile-only dependabot edit is not done here — flagged as the now-unblocked follow-up (and it wants the lockfile-only-value verification first).

…ning-strategy)

Re-checked the two dependabot-core issues this ROADMAP waits on:
- #12162 (uv versioning-strategy support) is now CLOSED/completed (~2026-02) —
  the "not supported yet" assumption is stale and the queued lockfile-only fix
  to end the ruff/ty floor churn is unblocked (verify uv accepts lockfile-only
  before the fleet edit, since #12162 tracked the umbrella feature).
- #14004 (uv workspace mis-targeting) is still OPEN — kourai's uv deferral stands.

Also corrected the SHA-pinning item's "only techne enforces it" framing: every
sister enforces pin-pinning via inline pin-check.yml regex (coverage is
fleet-wide); only the shared check_action_pins.sh script is techne-only, so the
remaining work is DRY consolidation, not a coverage gap.
@ajbarea ajbarea enabled auto-merge (squash) May 30, 2026 10:39
@ajbarea ajbarea merged commit 58f66fa into main May 30, 2026
2 checks passed
@ajbarea ajbarea deleted the docs/ground-dependabot-uv-versioning branch May 30, 2026 10:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant