Skip to content

Conversation

@stefanvanburen
Copy link
Member

We're failing to run Dependabot for uv dependencies:

https://github.com/bufbuild/protovalidate-python/actions/runs/16629514901/job/47054963334

I found a fix for this issue, here:

dependabot/dependabot-core#12340 (comment)

Makes me nervous that a stray release could end up with a 0.0.0 version, but we could just yank it - hopefully the upstream bug is fixed soon.

Ref: https://setuptools-scm.readthedocs.io/en/latest/config/#configuration-parameters

I'm making a similar fix for connect-python.

We're failing to run Dependabot for uv dependencies:

https://github.com/bufbuild/protovalidate-python/actions/runs/16629514901/job/47054963334

I found a fix for this issue, here:

dependabot/dependabot-core#12340 (comment)

Makes me nervous that a stray release could end up with a 0.0.0 version,
but we could just yank it - hopefully the upstream bug is fixed soon.

Ref: https://setuptools-scm.readthedocs.io/en/latest/config/#configuration-parameters

I'm making a [similar fix for connect-python][1].

[1]: connectrpc/connect-python#30
@stefanvanburen stefanvanburen merged commit 0925b76 into main Aug 1, 2025
13 checks passed
@stefanvanburen stefanvanburen deleted the svanburen/attempt-fix-dependabot-python branch August 1, 2025 18:35
@stefanvanburen
Copy link
Member Author

Ugh, no dice: https://github.com/bufbuild/protovalidate-python/actions/runs/16682738619/job/47225023976#step:3:522. Now we're hitting dependabot/dependabot-core#12042, which doesn't seem to have an obvious fix. :(

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants