mirror of
https://github.com/ComposioHQ/composio.git
synced 2026-09-22 11:46:35 +08:00
0421f1fb52
## Summary Closes #4197 as not-actionable and stops Dependabot from re-raising it. `ag2` 1.0 removed the top-level `autogen` package. The 1.x wheel ships only `ag2`: ``` $ python -c "import zipfile; print(sorted({n.split('/')[0] for n in zipfile.ZipFile('ag2-1.0.2-py3-none-any.whl').namelist()}))" ['ag2', 'ag2-1.0.2.dist-info'] ``` `composio_autogen/provider.py` imports `autogen`, `autogen.agentchat.register_function`, and `autogen.agentchat.conversable_agent.ConversableAgent` — none of which exist in 1.x. #4197 widened the requirement to `<2.0` and CI resolved `ag2==1.0.2`, which failed the fresh-install import guard on all three Python versions: ``` File ".../composio_autogen/provider.py", line 6, in <module> import autogen ModuleNotFoundError: No module named 'autogen' ``` This is the same failure mode as #3728 (pyautogen 0.10 shipping no `autogen`), one framework rename later. Adopting ag2 1.x is a provider rewrite against the new `ag2.tools` / middleware API, not a requirement widening — so it needs its own PR, not an automated bump. ## Changes - `.github/dependabot.yml`: ignore `version-update:semver-major` for `ag2` in the pip ecosystem, matching the existing convention for compatibility-boundary majors. Security updates are unaffected. - Record why the `<1.0` cap exists in both `pyproject.toml` and `setup.py`, so the next reader doesn't widen it by hand. ## Follow-up Migrating `composio-autogen` to ag2 1.x remains open and unscheduled. Remove the ignore entry when that lands.
94 lines
3.2 KiB
YAML
94 lines
3.2 KiB
YAML
# Dependabot configuration.
|
|
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
|
|
#
|
|
# Grouping keeps the update/security-alert volume manageable (one PR per group
|
|
# instead of one per advisory). Routine minor/patch bumps are batched; major
|
|
# bumps still arrive individually so they get review.
|
|
# Schedule: every Friday at 06:30 UTC / 12:00 IST.
|
|
|
|
version: 2
|
|
updates:
|
|
# TypeScript / npm workspace
|
|
- package-ecosystem: "npm"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "weekly"
|
|
day: "friday"
|
|
time: "06:30"
|
|
open-pull-requests-limit: 10
|
|
# These majors are compatibility boundaries exercised by explicit test
|
|
# lanes. Upgrade them manually with parallel old/new coverage. Dependabot
|
|
# security updates are not affected by update-type ignores.
|
|
ignore:
|
|
- dependency-name: "ai"
|
|
update-types: ["version-update:semver-major"]
|
|
- dependency-name: "openai"
|
|
update-types: ["version-update:semver-major"]
|
|
# Node 22/24/25 built-in fetch uses the legacy dispatcher handler API.
|
|
- dependency-name: "undici"
|
|
update-types: ["version-update:semver-major"]
|
|
- dependency-name: "zod"
|
|
update-types: ["version-update:semver-major"]
|
|
# Version 1.0.0 is not compatible with the Effect package family in use.
|
|
- dependency-name: "@effect/printer-ansi"
|
|
versions: ["1.0.0"]
|
|
groups:
|
|
npm-production:
|
|
applies-to: version-updates
|
|
dependency-type: "production"
|
|
patterns: ["*"]
|
|
update-types: ["minor", "patch"]
|
|
npm-development:
|
|
applies-to: version-updates
|
|
dependency-type: "development"
|
|
patterns: ["*"]
|
|
update-types: ["minor", "patch"]
|
|
npm-security:
|
|
applies-to: security-updates
|
|
patterns: ["*"]
|
|
|
|
# Python SDK and provider packages
|
|
- package-ecosystem: "pip"
|
|
directories:
|
|
- "/python"
|
|
- "/python/providers/*"
|
|
schedule:
|
|
interval: "weekly"
|
|
day: "friday"
|
|
time: "06:30"
|
|
open-pull-requests-limit: 10
|
|
ignore:
|
|
# CrewAI 1.15.x requires Tomli 2.0.x. Keep patch and security updates,
|
|
# then remove this when CrewAI accepts a newer Tomli line.
|
|
- dependency-name: "tomli"
|
|
update-types:
|
|
- "version-update:semver-minor"
|
|
- "version-update:semver-major"
|
|
# ag2 1.0 dropped the top-level `autogen` package that
|
|
# composio-autogen imports (`autogen.agentchat.register_function`,
|
|
# `ConversableAgent`); the 1.x wheel ships only `ag2`. Adopting it is a
|
|
# provider rewrite, not a requirement widening. Remove this once
|
|
# composio-autogen targets the `ag2` namespace.
|
|
- dependency-name: "ag2"
|
|
update-types:
|
|
- "version-update:semver-major"
|
|
groups:
|
|
pip-version:
|
|
applies-to: version-updates
|
|
patterns: ["*"]
|
|
update-types: ["minor", "patch"]
|
|
pip-security:
|
|
applies-to: security-updates
|
|
patterns: ["*"]
|
|
|
|
# GitHub Actions workflow pins
|
|
- package-ecosystem: "github-actions"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "weekly"
|
|
day: "friday"
|
|
time: "06:30"
|
|
groups:
|
|
github-actions:
|
|
patterns: ["*"]
|