chore: pin the Ruff rule set and point Dependabot at dev - #36
Merged
Conversation
Two config gaps that both showed up while triaging the open Dependabot PRs. Ruff: [tool.ruff] set only line-length and target-version, so the project inherited whatever Ruff's defaults were. 0.16.0 widened them and turned 84 findings up in code nobody had touched (PR #33 is red on exactly this). Pinning select to Ruff's classic defaults makes "lint clean" a decision made here rather than one made by whichever Ruff version resolved. Verified as a no-op: `ruff check src tests` passes on both 0.15.19 and 0.16.0 with the pin, matching what CI enforced before it. Widening the set is separate work. Dependabot: it opens against the repository's default branch, which is main, while CONTRIBUTING requires PRs to be based on dev. Merging those bumps put them on main only, leaving dev's CI to keep testing the old versions. target-branch fixes that for future runs. Note: Dependabot reads this file from the default branch, so the change takes effect once it reaches main. The five PRs already open stay pointed at main. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This was referenced Jul 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two config gaps found while triaging the five open Dependabot PRs. Both are config-only; no source or test files change.
Pin the Ruff rule set
[tool.ruff]set onlyline-lengthandtarget-version, with noselect. The project therefore inherited whatever Ruff's defaults happened to be, so "lint clean" changed meaning on a Ruff upgrade rather than on a decision made here. Ruff 0.16.0 widened those defaults and surfaced 84 findings across 16 rules in code nobody had touched — which is exactly why #33 is red while its guard and smoke jobs pass. Paired with the open-endedruff>=0.5dev pin, every Ruff release was a coin flip.Pinning
selectto Ruff's classic defaults is a verified no-op today:All checks passedAll checks passedAll checks passedSame command CI runs (
ruff check src tests), same config. So #33 should go green on a rebase.This deliberately does not adopt the new rules. 57 of the 84 are auto-fixable across 49 files and 27 need hand edits, several of them worth doing on their own merits (
B023loop-variable capture intui/setup_screen.py,PLW0127self-assignments incore/errors.py,RUF012mutable class default intui/shell_app.py). That belongs in its own reviewable PR, not bundled into a dependency bump.Point Dependabot at
devDependabot opens PRs against the repository's default branch, which is
main, while CONTRIBUTING requires PRs to be based ondev. All five open bumps targetmain; merging them there would land the updates onmainonly and leavedev's CI testing the old versions until someone back-merges.Two caveats worth knowing:
.github/dependabot.ymlfrom the default branch, so this takes effect once it reachesmain— i.e. at the nextdev→maincut.main.🤖 Generated with Claude Code