Files
composiohq__composio/.github/dependabot.yml
T
Alberto Schiabel 0421f1fb52 chore(deps): stop Dependabot proposing ag2 majors for composio-autogen (#4236)
## Summary

Closes #4197 as not-actionable and stops Dependabot from re-raising it.

`ag2` 1.0 removed the top-level `autogen` package. The 1.x wheel ships
only `ag2`:

```
$ python -c "import zipfile; print(sorted({n.split('/')[0] for n in zipfile.ZipFile('ag2-1.0.2-py3-none-any.whl').namelist()}))"
['ag2', 'ag2-1.0.2.dist-info']
```

`composio_autogen/provider.py` imports `autogen`,
`autogen.agentchat.register_function`, and
`autogen.agentchat.conversable_agent.ConversableAgent` — none of which
exist in 1.x. #4197 widened the requirement to `<2.0` and CI resolved
`ag2==1.0.2`, which failed the fresh-install import guard on all three
Python versions:

```
File ".../composio_autogen/provider.py", line 6, in <module>
    import autogen
ModuleNotFoundError: No module named 'autogen'
```

This is the same failure mode as #3728 (pyautogen 0.10 shipping no
`autogen`), one framework rename later. Adopting ag2 1.x is a provider
rewrite against the new `ag2.tools` / middleware API, not a requirement
widening — so it needs its own PR, not an automated bump.

## Changes

- `.github/dependabot.yml`: ignore `version-update:semver-major` for
`ag2` in the pip ecosystem, matching the existing convention for
compatibility-boundary majors. Security updates are unaffected.
- Record why the `<1.0` cap exists in both `pyproject.toml` and
`setup.py`, so the next reader doesn't widen it by hand.

## Follow-up

Migrating `composio-autogen` to ag2 1.x remains open and unscheduled.
Remove the ignore entry when that lands.
2026-08-25 01:20:54 +02:00

94 lines
3.2 KiB
YAML

# Dependabot configuration.
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
#
# Grouping keeps the update/security-alert volume manageable (one PR per group
# instead of one per advisory). Routine minor/patch bumps are batched; major
# bumps still arrive individually so they get review.
# Schedule: every Friday at 06:30 UTC / 12:00 IST.
version: 2
updates:
# TypeScript / npm workspace
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
day: "friday"
time: "06:30"
open-pull-requests-limit: 10
# These majors are compatibility boundaries exercised by explicit test
# lanes. Upgrade them manually with parallel old/new coverage. Dependabot
# security updates are not affected by update-type ignores.
ignore:
- dependency-name: "ai"
update-types: ["version-update:semver-major"]
- dependency-name: "openai"
update-types: ["version-update:semver-major"]
# Node 22/24/25 built-in fetch uses the legacy dispatcher handler API.
- dependency-name: "undici"
update-types: ["version-update:semver-major"]
- dependency-name: "zod"
update-types: ["version-update:semver-major"]
# Version 1.0.0 is not compatible with the Effect package family in use.
- dependency-name: "@effect/printer-ansi"
versions: ["1.0.0"]
groups:
npm-production:
applies-to: version-updates
dependency-type: "production"
patterns: ["*"]
update-types: ["minor", "patch"]
npm-development:
applies-to: version-updates
dependency-type: "development"
patterns: ["*"]
update-types: ["minor", "patch"]
npm-security:
applies-to: security-updates
patterns: ["*"]
# Python SDK and provider packages
- package-ecosystem: "pip"
directories:
- "/python"
- "/python/providers/*"
schedule:
interval: "weekly"
day: "friday"
time: "06:30"
open-pull-requests-limit: 10
ignore:
# CrewAI 1.15.x requires Tomli 2.0.x. Keep patch and security updates,
# then remove this when CrewAI accepts a newer Tomli line.
- dependency-name: "tomli"
update-types:
- "version-update:semver-minor"
- "version-update:semver-major"
# ag2 1.0 dropped the top-level `autogen` package that
# composio-autogen imports (`autogen.agentchat.register_function`,
# `ConversableAgent`); the 1.x wheel ships only `ag2`. Adopting it is a
# provider rewrite, not a requirement widening. Remove this once
# composio-autogen targets the `ag2` namespace.
- dependency-name: "ag2"
update-types:
- "version-update:semver-major"
groups:
pip-version:
applies-to: version-updates
patterns: ["*"]
update-types: ["minor", "patch"]
pip-security:
applies-to: security-updates
patterns: ["*"]
# GitHub Actions workflow pins
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
day: "friday"
time: "06:30"
groups:
github-actions:
patterns: ["*"]