← All tasks
pythonvega/altair #3796Not a task: already works

Add `uv lock --upgrade` CI workflow

envgap__vega__altair-3796

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
bd2543881aea9f4be3688798ab592aa5980ec5cf
Manifest
pyproject.toml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

vega/altair #3796 · read the original issue
_Originally posted by @dangotbanned in https://github.com/vega/altair/issues/3723#issuecomment-2598167273_



> All in all, I'm not really a big fan of a lock file. We can synchronize to a single unified developer experience, but it won't change the issues users face.

I prefer that we as maintainers experience these issues in environments and during review.



@mattijn I've thought some more about this and think I have an idea that gives us the **benefits of both**



- GitHub Action scheduled at some interval (e.g. weekly, monthly) that adds a PR upgrading our lock file and running the test suite

- If our CI is green, it could merge to `main` without review

- Otherwise, it should block subsequent runs and require a maintainer to address the issues in that PR to merge





So we get the failures **isolated** to a single branch (one less concern for new contributors).

But we also continue to know *well-ahead* of release that we may have a dependency issue (preserving the current feedback loop).



---



I would split this into another issue to plan out how we'd achieve this.

However, after reading these I feel convinced we have options:

- [dependabot](https://docs.github.com/en/code-security/dependabot/ecosystems-supported-by-dependabot/supported-ecosystems-and-repositories)

  - [dependabot w/ `uv`](https://github.com/dependabot/dependabot-core/pull/10040)

- [renovate](https://github.com/apps/renovate)

  - [renovatebot w/ `uv`](https://docs.renovatebot.com/modules/manager/pep621/#additional-information)

- [setup-uv](https://docs.astral.sh/uv/guides/integration/github/)

- [`uv lock --upgrade`](https://docs.astral.sh/uv/concepts/projects/sync/#upgrading-locked-package-versions)





            
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]