dependabot[bot]
c7fe66d490
Bump astral-sh/setup-uv from 7.3.0 to 8.1.0 ( #172 )
...
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv ) from
7.3.0 to 8.1.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/setup-uv/releases ">astral-sh/setup-uv's
releases</a>.</em></p>
<blockquote>
<h2>v8.1.0 🌈 New input <code>no-project</code></h2>
<h2>Changes</h2>
<p>This add the a new boolean input <code>no-project</code>.
It only makes sense to use in combination with
<code>activate-environment: true</code> and will append <code>--no
project</code> to the <code>uv venv</code> call. This is for example
useful <a
href="https://redirect.github.com/astral-sh/setup-uv/issues/854 ">if you
have a pyproject.toml file with parts unparseable by uv</a></p>
<h2>🚀 Enhancements</h2>
<ul>
<li>Add input no-project in combination with activate-environment <a
href="https://github.com/eifinger "><code>@eifinger</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/856 ">#856</a>)</li>
</ul>
<h2>🧰 Maintenance</h2>
<ul>
<li>fix: grant contents:write to validate-release job <a
href="https://github.com/eifinger "><code>@eifinger</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/860 ">#860</a>)</li>
<li>Add a release-gate step to the release workflow <a
href="https://github.com/zanieb "><code>@zanieb</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/859 ">#859</a>)</li>
<li>Draft commitish releases <a
href="https://github.com/eifinger "><code>@eifinger</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/858 ">#858</a>)</li>
<li>Add action-types.yml to instructions <a
href="https://github.com/eifinger "><code>@eifinger</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/857 ">#857</a>)</li>
<li>chore: update known checksums for 0.11.7 @<a
href="https://github.com/apps/github-actions ">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/853 ">#853</a>)</li>
<li>Refactor version resolving <a
href="https://github.com/eifinger "><code>@eifinger</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/852 ">#852</a>)</li>
<li>chore: update known checksums for 0.11.6 @<a
href="https://github.com/apps/github-actions ">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/850 ">#850</a>)</li>
<li>chore: update known checksums for 0.11.5 @<a
href="https://github.com/apps/github-actions ">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/845 ">#845</a>)</li>
<li>chore: update known checksums for 0.11.4 @<a
href="https://github.com/apps/github-actions ">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/843 ">#843</a>)</li>
<li>Add a release workflow <a
href="https://github.com/zanieb "><code>@zanieb</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/839 ">#839</a>)</li>
<li>chore: update known checksums for 0.11.3 @<a
href="https://github.com/apps/github-actions ">github-actions[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/836 ">#836</a>)</li>
</ul>
<h2>📚 Documentation</h2>
<ul>
<li>Update ignore-nothing-to-cache documentation <a
href="https://github.com/eifinger "><code>@eifinger</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/833 ">#833</a>)</li>
<li>Pin setup-uv docs to v8 <a
href="https://github.com/eifinger "><code>@eifinger</code></a> (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/829 ">#829</a>)</li>
</ul>
<h2>⬆️ Dependency updates</h2>
<ul>
<li>chore(deps): bump release-drafter/release-drafter from 7.1.1 to
7.2.0 @<a href="https://github.com/apps/dependabot ">dependabot[bot]</a>
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/855 ">#855</a>)</li>
</ul>
<h2>v8.0.0 🌈 Immutable releases and secure tags</h2>
<h1>This is the first immutable release of <code>setup-uv</code> 🥳 </h1>
<p>All future releases are also immutable, if you want to know more
about what this means checkout <a
href="https://docs.github.com/en/code-security/concepts/supply-chain-security/immutable-releases ">the
docs</a>.</p>
<p>This release also has two breaking changes</p>
<h2>New format for <code>manifest-file</code></h2>
<p>The previously deprecated way of defining a custom version manifest
to control which <code>uv</code> versions are available and where to
download them from got removed. The functionality is still there but you
have to use the <a
href="https://github.com/astral-sh/setup-uv/blob/main/docs/customization.md#format ">new
format</a>.</p>
<h2>No more major and minor tags</h2>
<p>To increase <strong>security</strong> even more we will <strong>stop
publishing minor tags</strong>. You won't be able to use
<code>@v8</code> or <code>@v8.0</code> any longer. We do this because
pinning to major releases opens up users to supply chain attacks like
what happened to <a
href="https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/ ">tj-actions</a>.</p>
<blockquote>
<p>[!TIP]
Use the immutable tag as a version
<code>astral-sh/setup-uv@v8.0.0</code>
Or even better the githash
<code>astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57</code></p>
</blockquote>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="08807647e7 "><code>0880764</code></a>
fix: grant contents:write to validate-release job (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/860 ">#860</a>)</li>
<li><a
href="717d6aba0f "><code>717d6ab</code></a>
Add a release-gate step to the release workflow (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/859 ">#859</a>)</li>
<li><a
href="5a911eb3a3 "><code>5a911eb</code></a>
Draft commitish releases (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/858 ">#858</a>)</li>
<li><a
href="080c31e04c "><code>080c31e</code></a>
Add action-types.yml to instructions (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/857 ">#857</a>)</li>
<li><a
href="b3e97d2ba1 "><code>b3e97d2</code></a>
Add input no-project in combination with activate-environment (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/856 ">#856</a>)</li>
<li><a
href="7dd591db95 "><code>7dd591d</code></a>
chore(deps): bump release-drafter/release-drafter from 7.1.1 to 7.2.0
(<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/855 ">#855</a>)</li>
<li><a
href="1541b77626 "><code>1541b77</code></a>
chore: update known checksums for 0.11.7 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/853 ">#853</a>)</li>
<li><a
href="cdfb2ee6dd "><code>cdfb2ee</code></a>
Refactor version resolving (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/852 ">#852</a>)</li>
<li><a
href="cb84d12dc6 "><code>cb84d12</code></a>
chore: update known checksums for 0.11.6 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/850 ">#850</a>)</li>
<li><a
href="1912cc65f2 "><code>1912cc6</code></a>
chore: update known checksums for 0.11.5 (<a
href="https://redirect.github.com/astral-sh/setup-uv/issues/845 ">#845</a>)</li>
<li>Additional commits viewable in <a
href="eac588ad8d...08807647e7 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-24 16:23:59 -07:00
saurabh dave
3bdfcaa8ee
Add Dependabot config for uv dependencies and GitHub Actions ( #167 )
...
## Summary
Adds a Dependabot configuration to automate weekly update PRs for:
- `uv`-managed Python dependencies
- GitHub Actions used in CI workflows
## Why
This repository already relies on pinned dependency state via `uv.lock`
and pinned GitHub Action revisions in CI. Adding Dependabot helps keep
both current with small, reviewable update PRs instead of larger manual
catch-up updates.
## What this changes
- Adds `.github/dependabot.yml`
- Configures weekly version update checks for the repo root
- Groups minor and patch dependency updates to reduce PR noise
- Enables automatic update PRs for GitHub Actions references in
workflows
## Used `uv` instead of `pip`
This project uses `uv` directly (`uv.lock`, `uv run`, and repo
instructions based on `uv`), so configuring Dependabot with the `uv`
ecosystem matches the repository’s actual package management workflow
more closely than a generic `pip` entry.
## Risk
Low. This is a configuration only change and does not affect application
runtime behavior .
2026-04-24 14:04:36 -07:00
Alishahryar1
f1f6080224
Updated agent instructions and renamed lint check to format check
2026-02-28 07:20:00 -08:00
Alishahryar1
d21ed84171
updated uv version
2026-02-19 20:23:37 -08:00
Alishahryar1
416664ed41
Renamed a check in workflow
2026-02-16 15:59:25 -08:00
Alishahryar1
47e5d4f969
Updated workflow
2026-02-15 22:05:47 -08:00
Alishahryar1
539854fe7b
Refactor done using GLM-5
2026-02-15 21:58:03 -08:00
Alishahryar1
c36c07a8ce
Removed formatter workflow
2026-02-15 19:20:39 -08:00
Alishahryar1
ae0145f933
Fixed formatter workflow
2026-02-15 19:17:25 -08:00
Alishahryar1
6093939151
Enhance GitHub Actions workflow by adding concurrency and separating jobs for checks and formatting. Updated actions/checkout and setup-uv versions, adjusted permissions, and set timeouts for improved CI performance.
2026-02-15 19:04:27 -08:00
Alishahryar1
626766c857
Updated actions/checkout to v6
2026-02-15 18:57:43 -08:00
Cursor Agent
eec5771ea1
ci: fix checkout for PRs from forks
...
Use head repo and SHA when checking out pull_request events so the
workflow can fetch the branch from the fork instead of the base repo.
Fixes CI failure when patch-1 (or other fork branches) don't exist
in the base repository.
Co-authored-by: Ali Khokhar <alishahryar2@gmail.com>
2026-02-16 02:51:34 +00:00
Ali Khokhar
de970deb5d
Update tests.yml
2026-02-15 09:24:33 -08:00
Alishahryar1
8ed1658e4e
Reordered workflow
2026-02-15 02:03:07 -08:00
Alishahryar1
830840f98f
updated workflow
2026-02-15 01:18:51 -08:00
Alishahryar1
96e6765315
Removed python setup and tests from workflow
2026-02-15 01:16:54 -08:00
Alishahryar1
3950c39ae8
Updated workflow
2026-02-14 23:04:27 -08:00
Alishahryar1
8fb5ee698b
fixed yml typo
2026-02-14 23:02:19 -08:00
Alishahryar1
0d292cd578
ci: enhance type checking in workflow and improve test coverage
...
- Added a step to fail the CI if any '# type: ignore' comments are found in Python files.
- Refactored tests to use mocking for better isolation and reliability.
- Updated type hints and casting in several files to improve type safety.
2026-02-14 23:01:11 -08:00
Cursor Agent
be78008429
ci: checkout branch to fix detached HEAD on PR
...
Co-authored-by: Ali Khokhar <alishahryar2@gmail.com>
2026-02-15 06:43:11 +00:00
Cursor Agent
ebdfdbb6c9
ci: run ruff format and auto-commit instead of format check
...
Co-authored-by: Ali Khokhar <alishahryar2@gmail.com>
2026-02-15 06:42:00 +00:00
Cursor Agent
37f2e2871e
ci: remove hardcoded feature branch from workflow triggers
...
Co-authored-by: Ali Khokhar <alishahryar2@gmail.com>
2026-02-15 06:39:34 +00:00
Cursor Agent
6d1197fb9b
ci: add type check and format check, block merge on failure
...
- Run ty check; fail CI if type errors
- Run ruff format --check; fail CI if not formatted
- Rename workflow to CI
Co-authored-by: Ali Khokhar <alishahryar2@gmail.com>
2026-02-15 06:38:41 +00:00
Cursor Agent
d68fd6013c
fix: align README badges with best practices
...
- License: use standard MIT yellow badge, link to opensource.org
- Python: update to 3.14 to match pyproject.toml
- uv: use official dynamic endpoint badge from astral-sh/uv
- Tests: replace static pytest 95% with GitHub Actions badge
- Ty: fix link to PyPI (pypi.org/project/ty/)
- Add .github/workflows/tests.yml for CI
Co-authored-by: Ali Khokhar <alishahryar2@gmail.com>
2026-02-15 06:32:25 +00:00