Skip to content

chore(ci): skip generated python-tools lock, hold better-auth at 1.6 - #74

Merged
arodiss merged 1 commit into
mainfrom
chore/dependabot-python-tools-better-auth
Sep 28, 2026
Merged

arodiss merged 1 commit into
mainfrom
chore/dependabot-python-tools-better-auth

Conversation

@arodiss

@arodiss arodiss commented Sep 28, 2026 •

Copy link
Copy Markdown

Two Dependabot config fixes. Each one makes a weekly group PR fail every week.

Python group: stop updating packages/sandbox-images/locks/python-tools.
sandbox_images/locks.py (npm run sandbox:images lock) generates that project's pyproject.toml from the image tool manifest. The python-minor-patch group (#61) edited it, which failed the freshness check (Generated image input is stale … run sandbox:images lock) in both sandbox image contract jobs and in modal-infra's test_deploy.py. Bump those tools in the manifest and regenerate instead. The single-level /packages/* glob does not match that directory.

npm group: ignore better-auth >= 1.7.0.
1.7 changes the socialProviders types, which fails the control-plane typecheck, and breaks the sign-in integration tests (GitHub PKCE, Google ID-token rejection, Slack email claim). That failed the npm-minor-patch group (#56 / #66). Only 1.7 and above is ignored, so 1.6.x patches still arrive, following the existing cloudflare/cloudflare hold. Drop the entry once the 1.7 migration lands.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Automated update checks now continue to consider eligible versions of the authentication package while excluding versions 1.7.0 and later.
    • Python tooling update checks now cover package directories, with the sandbox image lockfile directory no longer included. These changes affect automated maintenance coverage and do not change app behavior.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Team

Run ID: f6456c00-6e2c-4898-84d5-b121e70f639b

📥 Commits

Reviewing files that changed from the base of the PR and between b3fa6f1 and 7cd7d37.

📒 Files selected for processing (1)
  • .github/dependabot.yml

Comment @coderabbitai help to get the list of available commands.

@codos-reviewer codos-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking: 0 · Non-blocking: 0

The uv configuration no longer targets the generated python-tools project, and the better-auth ignore bounds the incompatible 1.7+ releases while leaving 1.6.x updates eligible. No actionable findings in the PR diff.

@arodiss
arodiss merged commit 7d4ac60 into main Sep 28, 2026
2 of 3 checks passed
@arodiss
arodiss deleted the chore/dependabot-python-tools-better-auth branch September 28, 2026 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant