Skip to content

feat(deps): allow ignoring known-broken upstream releases - #6665

Merged
perrin4869 merged 4 commits into
masterfrom
deps/ignore-broken-versions
Sep 23, 2026
Merged

perrin4869 merged 4 commits into
masterfrom
deps/ignore-broken-versions

Conversation

@perrin4869

@perrin4869 perrin4869 commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • #6642 (bump coursier to v2.1.25) failed CI: the v2.1.25 standalone launcher jar is broken upstream, throwing NoSuchMethodError: cats.Align cats.implicits$.catsStdInstancesForList() on every command (bundles a mismatched cats). See coursier/coursier#3865 — fixed upstream but not yet in a tagged release. Closed with the wontfix label.
  • check_upstream_version now checks GitHub's own PR history before proposing a version: it queries GET /repos/{owner}/{repo}/pulls?head=update/<dep>/<version>&state=closed and skips the version if a matching closed PR is labeled wontfix. GitHub keeps a PR's head branch name even after the branch is deleted, so this needs no file or state committed to the repo — closing a bad-version PR with that label is the whole mechanism.
  • update_deps.yml's "Check for update" step now passes GITHUB_TOKEN so the query is authenticated against our own repo.

Test plan

  • ./utils/check_upstream_version coursier returns nothing (finds closed+wontfix-labeled Update coursier to v2.1.25 #6642 for update/coursier/v2.1.25)
  • Manually confirmed the PR-list query matches Update coursier to v2.1.25 #6642 by branch even though its branch was deleted
  • Confirmed no false positive: an older closed-but-unlabeled coursier PR (update/coursier/v2.1.24, unrelated close) isn't treated as rejected
  • ./utils/check_upstream_version metals unaffected

check_upstream_version now skips a dep's latest release if it's
listed in .external_versions/<dep>.ignore, so the update workflow
stops re-proposing a version known to be broken until upstream ships
a newer one.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
perrin4869 and others added 3 commits September 24, 2026 03:27
…versions

Replace the .external_versions/<dep>.ignore file approach with a
lookup against GitHub's own PR history: closing a rejected version's
update PR with the "wontfix" label is enough for check_upstream_version
to recognize it later, since the closed PR's head branch name (which
GitHub keeps even after the branch is deleted) encodes dep + version.
No repo state to commit or keep in sync.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
gh already does head-branch + label filtering server-side, and reads
GITHUB_TOKEN for auth automatically - no need to derive owner/repo
from the git remote URL by hand or build the API request manually.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Same rationale as the PR-history check: gh already handles auth and
request building. Drops the last curl+jq usage, so the separate
"Install jq" step in the workflow is dead weight - removed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@perrin4869
perrin4869 merged commit bf25d59 into master Sep 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant