Fossabot: AI code review for Dependabot/Renovate on breaking changes and impacts
1–10 of 19 posts
Re: Fossabot: AI code review for Dependabot/Renovate on breaking changes and impacts
#2Re: Fossabot: AI code review for Dependabot/Renovate on breaking changes and impacts
#3(a) they’re broadly similar across companies,
(b) they aren’t time-sensitive, so the agent can take hours without anyone noticing, and
(c) customers are already accustomed to using bots here, just bad ones
Re: Fossabot: AI code review for Dependabot/Renovate on breaking changes and impacts
#4Always felt dependency updates are a perfect fit for AI agents: (a) they’re broadly similar across companies, (b) they aren’t time-sensitive, so the agent can take hours without anyone noticing, and (c) customers are already accustomed to using bots here, just bad ones
Migrations between versions can have big variance largely as a function of the parent codebase and not the dependency change. A simple example of this would be a supported node version bump. It's common to lose support for older node runtimes with new dependency versions, but migrating the parent codebase may require large custom efforts like changing module systems.
Re: Fossabot: AI code review for Dependabot/Renovate on breaking changes and impacts
#5Why didn't GitHub come up with this? This seems like such an obvious use case.
Re: Fossabot: AI code review for Dependabot/Renovate on breaking changes and impacts
#6Why didn't GitHub come up with this? This seems like such an obvious use case.
And, as someone who's start up (EdgeBit was acquired by FOSSA recently) wrote a new JS/TS static analysis engine, it's just hard to get correct.
Re: Fossabot: AI code review for Dependabot/Renovate on breaking changes and impacts
#7Re: Fossabot: AI code review for Dependabot/Renovate on breaking changes and impacts
#8(I'm one of the maintainers on Renovate)
Re: Fossabot: AI code review for Dependabot/Renovate on breaking changes and impacts
#9Why didn't GitHub come up with this? This seems like such an obvious use case.
Re: Fossabot: AI code review for Dependabot/Renovate on breaking changes and impacts
#10We've found dependency upgrades to be deceptively complex to evaluate safety for. Often you need context that's difficult or impossible to determine statically in a dynamically typed language. An example I use for Ruby is the kwarg migration from ruby 2.7->3 (https://www.ruby-lang.org/en/news/2019/12/12/separation-of-p...). It's trivial to profile for impacted sites at runtime but basically impossible to do it statically without adopting something like sorbet. Do you have any benchmarks on how reliable your evaluations are on plain JS vs. typescript codebases?
We ended up embracing runtime profiling for deprecation warnings / breaking changes as part of upgrading dependencies for our customers and have found that context to unlock more reliable code transformations. But you're stuck building an SDK for every language you want to support, and it's more friction than installing a github app.