Skip to content

Conversation

@rebkwok
Copy link
Contributor

@rebkwok rebkwok commented Jan 20, 2026

Add uv dependabot config for security updates only

Add a GHA workflow to ensure uvmirror file is consistent with uv.lock

Ensures that the uvmirror requirements file has not been updated independently of the pyproject.toml and uv.lock files. This will fail any dependabot security update PRs that modify only the mirror file, and will prompt us to fix the PRs with the correct uv updates.

Add uv dependabot config for security updates only

Add a GHA workflow to ensure uvmirror file is consistent with uv.lock

Ensures that the uvmirror requirements file has not been updated
independently of the pyproject.toml and uv.lock files. This will fail
any dependabot security update PRs that modify only the mirror file,
and will prompt us to fix the PRs with the correct uv updates.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants