Is pants able to handle "something else" updating ...
# general
f
Is pants able to handle "something else" updating a (python) lockfile? I'm trying to configure Renovate to keep my
uv.lock
up to date. Presumably this would end up using
uv
directly, updating my
pyproject.toml
and my
uv.lock
, but it seems like it would not update pants' generated
uv.lock.metadata
file. Going to be digging deeper today, but just wanted to start a thread to see if anyone has done this already?
c
I think you could do this with
[python].invalid_lockfile_behavior=ignore
, and then have Renovate do whatever it is going to do to the lockfile) (The way I've approached this previously is using dependabot for security alerts, but doing the updates myself.)
f
This does seem sensible. Even if we let Renovate do whatever it does, the worst case is "checkout PR branch,
pants generate-lockfiles
, commit, push, merge".
d
When I used renovate with pants before, we used post-upgrade tasks to regenerate the lockfile - this is a brief example guidebook.devops.uis.cam.ac.uk/howtos/renovatebot/post-upgrade-tasks the gotcha is that you have to self-host renovate (or run it as a github action, ref: github.com/renovatebot/github-action