Skip to content

chore: add Dependabot updates and code ownership - #99

Open
Sonike wants to merge 1 commit into
CodewithJha:mainfrom
Sonike:chore/dependabot-and-codeowners
Open

Sonike wants to merge 1 commit into
CodewithJha:mainfrom
Sonike:chore/dependabot-and-codeowners

Conversation

@Sonike

@Sonike Sonike commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Summary

Fixes #20.

Add weekly Dependabot updates for the root uv workspace, npm in apps/web, and GitHub Actions, so Python/web dependencies and the action SHAs pinned in #95 can receive update PRs. Add CODEOWNERS entries routing Python packages, the API/demo/UI apps, shared Python manifests, and .github configuration to @CodewithJha.

Only two configuration files are added; application code, dependency versions, lockfiles, and workflow commands are unchanged.

Type of change

  • Docs / community / DX only

uv support and limitations

Use the native uv ecosystem at /, following Astral's Dependabot integration guide, to update the workspace manifests and their shared uv.lock. The five workspace members do not need separate pip jobs. The original upstream workspace-support issue, dependabot/dependabot-core#12072, is closed as completed; no pip workaround is needed for this layout.

The hosted Dependabot updater has not been run for this change. The first update after merge still needs its resolution result checked in GitHub; local validation verifies configuration and paths, not successful dependency upgrades. This PR does not change repository security-update settings.

Checklist

  • Read CONTRIBUTING.md and repository contribution/security guidance.
  • Linked the related issue; one concern per PR.
  • Configuration-only scope; no application behavior or dependency upgrades.
  • Validation follows oss: add Dependabot (pip + npm) and CODEOWNERS #20's configuration-only expectations (no pytest required).

Test plan

  • Parsed .github/dependabot.yml with PyYAML and validated it against the current SchemaStore Dependabot v2 schema.
  • Verified all three ecosystem directories and manifests, all five uv workspace members, and the shared root lockfile exist.
  • Checked every CODEOWNERS pattern against tracked paths and verified coverage of all areas requested in oss: add Dependabot (pip + npm) and CODEOWNERS #20, including the new configuration files.
  • git diff --cached --check passed.

Created with Codex assistance.

@vercel

vercel Bot commented Oct 8, 2026

Copy link
Copy Markdown

@Sonike is attempting to deploy a commit to the priyanshu's projects Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

oss: add Dependabot (pip + npm) and CODEOWNERS

1 participant