4 ms·
Fossabot: AI code review for Dependabot/Renovate on breaking changes and impacts
- johnnyyw 1y agoWhy didn't GitHub come up with this? This seems like such an obvious use case.
- chadfurman 1y agoIt's a niche for AI, which creates some great opportunities for context engineering :)
- robszumski 1y agoIt requires you to go deep in both the code analysis and the research, which is expensive at their scale And, as someone who's start up (EdgeBit was acquired by FOSSA recently) wrote a new JS/TS static analysis engine, it's just hard to get correct.
- zingababba 1y agoGitHub hasn't done anything interesting with dependabot or code scanning for awhile.
- timrogers 1y agoGitHub PM here. We have tried this, but we weren't able to get results that we were satisfied with. Of course, you have to revisit these things regularly, as the models and wider state of the art are evolving so quickly!
- SkyPuncher 1y agoBecause this won't work. Dependency updates are actually incredibly hard.
- rohitpaulk 1y agoAlways felt dependency updates are a perfect fit for AI agents: (a) they’re broadly similar across companies, (b) they aren’t time-sensitive, so the agent can take hours without anyone noticing, and (c) customers are already accustomed to using bots here, just bad ones
- XiZhao 1y agoOne would imagine they are broadly similar; but that's off the assumption that codebases are similar as well. Migrations between versions can have big variance largely as a function of the parent codebase and not the dependency change. A simple example of this would be a supported node version bump. It's common to lose support for older node runtimes with new dependency versions, but migrating the parent codebase may require large custom efforts like changing module systems.
- jamietanna 1y agoRelated: https://news.ycombinator.com/item?id=45436251 https://news.ycombinator.com/item?id=45436251
- jamietanna 1y agoThis is very interesting, looking forward to seeing more about it! (I'm one of the maintainers on Renovate)
- stevepike 1y agoThis is cool, it looks to me like you're integrating static analysis on the user's codebase and the underlying dependency. Very curious to see where it goes. We've found dependency upgrades to be deceptively complex to evaluate safety for. Often you need context that's difficult or impossible to determine statically in a dynamically typed language. An example I use for Ruby is the kwarg migration from ruby 2.7->3 (https://www.ruby-lang.org/en/news/2019/12/12/separation-of-positional-and-keyword-arguments-in-ruby-3-0/ https://www.ruby-lang.org/en/news/2019/12/12/separation-of-p...). It's trivial to profile for impacted sites at runtime but basically impossible to do it statically without adopting something like sorbet. Do you have any benchmarks on how reliable your evaluations are on plain JS vs. typescript codebases? We ended up embracing runtime profiling for deprecation warnings / breaking changes as part of upgrading dependencies for our customers and have found that context to unlock more reliable code transformations. But you're stuck building an SDK for every language you want to support, and it's more friction than installing a github app.
- poetril 1y agoFossabot[0] is also the name of an established Twitch/YouTube chat bot. 0: https://fossabot.com/ https://fossabot.com/
- ai-christianson 1y agoCool to see this coming out of FOSSA (ex FOSSA here :))
- cchance 1y agoThis seems great, i see you offer it as a service, but also its opensource (FOSS) ... how does the FOSS version differ from the commercial service?
- jamietanna 1y ago> also its opensource (FOSS) Where did you see that? I must've missed it in the announcement
- gregjw 1y agoDid they not Google the name before deciding upon it? Fossabot is a dominant player in online streaming chat moderation.