Skip to content

ci(dependabot): stop proposing a litellm cap-raise that CI must reject - #3007

Merged
jaylfc merged 1 commit into
devfrom
fix/dependabot-ignore-litellm-cap
Sep 12, 2026
Merged

jaylfc merged 1 commit into
devfrom
fix/dependabot-ignore-litellm-cap

Conversation

@jaylfc

@jaylfc jaylfc commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

Why

pyproject.toml pins litellm to the exact minor that the inlined proxy subset mirrors (>=1.94.2,<1.95). litellm[proxy] pulls litellm-enterprise, so the proxy subset is inlined instead of installed via the extra, and any ceiling wider than the mirrored minor lets a fresh resolve outrun that subset.

tests/test_install_licences.py::test_proxy_extra_pins_litellm_to_the_minor_it_mirrors enforces this, and a companion test (test_litellm_cap_helper_rejects_a_ceiling_wider_than_the_mirrored_minor) proves the check rejects a decoy <2 ceiling rather than merely looking for some upper bound. The gate is doing its job.

.github/dependabot.yml has an ignore entry for fastapi but none for litellm, so the weekly python-deps group keeps widening the specifier. #2810 proposed litellm>=1.94.2,<1.100 and failed exactly there:

FAILED tests/test_install_licences.py::test_proxy_extra_pins_litellm_to_the_minor_it_mirrors - AssertionError: litellm's specifier must pin exactly the mirrored minor (>=1.94.2,<1.95), not merely carry *some* upper bound (got 'litellm>=1.94.2,<1.100')

That PR is unmergeable by construction, not flaky. Without this, every weekly run re-opens the same doomed bump and burns a CI cycle on it.

Change

One ignore entry mirroring the existing fastapi precedent, with the reasoning inline so the next person does not simply delete it:

- dependency-name: "litellm"
  versions: [">=1.95"]

Re-mirroring the inlined proxy subset onto a newer litellm minor stays a deliberate, human change — which is the intent the gate already encodes.

Scope

.github/dependabot.yml only. Not under .github/workflows/, so no gate-integrity-allow is needed. No change under tinyagentos/ or desktop/src/, so no changelog fragment is required.

🤖 Generated with Claude Code

https://claude.ai/code/session_01DiKJuYikvUFHQv1YCrDcUY

Summary by CodeRabbit

  • Chores
    • Updated automated dependency update settings to ignore LiteLLM versions 1.95 and later, preserving compatibility with the supported proxy subset.

pyproject pins litellm to the exact minor its inlined proxy subset mirrors
(>=1.94.2,<1.95). litellm[proxy] pulls litellm-enterprise, so the subset is
inlined rather than installed via the extra, and any wider ceiling lets a fresh
resolve outrun it -- which is precisely what
test_install_licences.py::test_proxy_extra_pins_litellm_to_the_minor_it_mirrors
asserts, with a companion test proving a decoy "<2" ceiling is rejected too.

Dependabot has no ignore for litellm, so the weekly python-deps group keeps
widening the specifier (#2810 proposed <1.100) and keeps failing that gate. The
bump is unmergeable by construction, not flaky: every future run burns a CI
cycle on a PR that cannot land.

Mirror the existing fastapi precedent and ignore litellm >=1.95. Re-mirroring
the inlined subset onto a newer minor stays a deliberate change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DiKJuYikvUFHQv1YCrDcUY
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@coderabbitai

coderabbitai Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 80aac17a-ce41-4b67-9dfc-7d358772141d

📥 Commits

Reviewing files that changed from the base of the PR and between 71ff78a and 32db00d.

📒 Files selected for processing (1)
  • .github/dependabot.yml

Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

Dependabot now ignores litellm versions >=1.95. The configuration documents the supported mirrored range >=1.94.2,<1.95.

Changes

Dependency version guard

Layer / File(s) Summary
LiteLLM version constraint
.github/dependabot.yml
Dependabot ignores litellm versions >=1.95 and documents the required proxy subset range.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 32db0

This configuration prevents incompatible LiteLLM upgrades while preserving the currently supported mirrored range.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: preventing Dependabot from proposing an incompatible litellm version cap increase. It is concise and specific.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/dependabot-ignore-litellm-cap

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gitar-bot

gitar-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown

Important

You are using the Gitar free plan. Upgrade to unlock code review, CI analysis, auto-apply, custom automations, and more.

Gitar

@kilo-code-bot

kilo-code-bot Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (1 files)
  • .github/dependabot.yml

Reviewed by step-3.7-flash:free · Input: 0 · Output: 0 · Cached: 0

@jaylfc jaylfc added the gate-integrity-allow Reviewed exception: allows a PR past the gate-integrity check label Sep 12, 2026
@jaylfc
jaylfc merged commit f001f35 into dev Sep 12, 2026
42 of 44 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gate-integrity-allow Reviewed exception: allows a PR past the gate-integrity check

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant