ci(dependabot): stop proposing a litellm cap-raise that CI must reject - #3007
Conversation
pyproject pins litellm to the exact minor its inlined proxy subset mirrors (>=1.94.2,<1.95). litellm[proxy] pulls litellm-enterprise, so the subset is inlined rather than installed via the extra, and any wider ceiling lets a fresh resolve outrun it -- which is precisely what test_install_licences.py::test_proxy_extra_pins_litellm_to_the_minor_it_mirrors asserts, with a companion test proving a decoy "<2" ceiling is rejected too. Dependabot has no ignore for litellm, so the weekly python-deps group keeps widening the specifier (#2810 proposed <1.100) and keeps failing that gate. The bump is unmergeable by construction, not flaky: every future run burns a CI cycle on a PR that cannot land. Mirror the existing fastapi precedent and ignore litellm >=1.95. Re-mirroring the inlined subset onto a newer minor stays a deliberate change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DiKJuYikvUFHQv1YCrDcUY
|
ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughDependabot now ignores ChangesDependency version guard
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Merge Risk: ⚪ Minimal · up to This configuration prevents incompatible LiteLLM upgrades while preserving the currently supported mirrored range. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Files Reviewed (1 files)
Reviewed by step-3.7-flash:free · Input: 0 · Output: 0 · Cached: 0 |
Why
pyproject.tomlpins litellm to the exact minor that the inlined proxy subset mirrors (>=1.94.2,<1.95).litellm[proxy]pullslitellm-enterprise, so the proxy subset is inlined instead of installed via the extra, and any ceiling wider than the mirrored minor lets a fresh resolve outrun that subset.tests/test_install_licences.py::test_proxy_extra_pins_litellm_to_the_minor_it_mirrorsenforces this, and a companion test (test_litellm_cap_helper_rejects_a_ceiling_wider_than_the_mirrored_minor) proves the check rejects a decoy<2ceiling rather than merely looking for some upper bound. The gate is doing its job..github/dependabot.ymlhas anignoreentry for fastapi but none for litellm, so the weeklypython-depsgroup keeps widening the specifier. #2810 proposedlitellm>=1.94.2,<1.100and failed exactly there:That PR is unmergeable by construction, not flaky. Without this, every weekly run re-opens the same doomed bump and burns a CI cycle on it.
Change
One
ignoreentry mirroring the existing fastapi precedent, with the reasoning inline so the next person does not simply delete it:Re-mirroring the inlined proxy subset onto a newer litellm minor stays a deliberate, human change — which is the intent the gate already encodes.
Scope
.github/dependabot.ymlonly. Not under.github/workflows/, so nogate-integrity-allowis needed. No change undertinyagentos/ordesktop/src/, so no changelog fragment is required.🤖 Generated with Claude Code
https://claude.ai/code/session_01DiKJuYikvUFHQv1YCrDcUY
Summary by CodeRabbit