Add `uv lock --upgrade` CI workflow
envgap__vega__altair-3796
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
bd2543881aea9f4be3688798ab592aa5980ec5cf- Manifest
pyproject.toml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
vega/altair #3796 · read the original issue
_Originally posted by @dangotbanned in https://github.com/vega/altair/issues/3723#issuecomment-2598167273_
> All in all, I'm not really a big fan of a lock file. We can synchronize to a single unified developer experience, but it won't change the issues users face.
I prefer that we as maintainers experience these issues in environments and during review.
@mattijn I've thought some more about this and think I have an idea that gives us the **benefits of both**
- GitHub Action scheduled at some interval (e.g. weekly, monthly) that adds a PR upgrading our lock file and running the test suite
- If our CI is green, it could merge to `main` without review
- Otherwise, it should block subsequent runs and require a maintainer to address the issues in that PR to merge
So we get the failures **isolated** to a single branch (one less concern for new contributors).
But we also continue to know *well-ahead* of release that we may have a dependency issue (preserving the current feedback loop).
---
I would split this into another issue to plan out how we'd achieve this.
However, after reading these I feel convinced we have options:
- [dependabot](https://docs.github.com/en/code-security/dependabot/ecosystems-supported-by-dependabot/supported-ecosystems-and-repositories)
- [dependabot w/ `uv`](https://github.com/dependabot/dependabot-core/pull/10040)
- [renovate](https://github.com/apps/renovate)
- [renovatebot w/ `uv`](https://docs.renovatebot.com/modules/manager/pep621/#additional-information)
- [setup-uv](https://docs.astral.sh/uv/guides/integration/github/)
- [`uv lock --upgrade`](https://docs.astral.sh/uv/concepts/projects/sync/#upgrading-locked-package-versions)
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]