Skip to content

chore(deps): aggregate envs Dependabot updates - #1146

Closed
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/dependabot-envs-2026-09-10
Closed

cursor[bot] wants to merge 1 commit into
mainfrom
cursor/dependabot-envs-2026-09-10

Conversation

@cursor

@cursor cursor Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Aggregates the remaining open envs/ Dependabot updates into one PR, and carries unpublished lockfile security bumps from #1015 / #1131 so they are not dropped.

New open Dependabot PRs included:

Already on main (from fda3603e); close the singles, nothing left to land:

Also included from #1015 / #1131 (still not on main):

  • cryptography → 50.0.0 in calendar, carla, chat, opencode, pelican_svg, pi, qed_math, sophistry_bench_sprint, sumo_rl, terminus, websearch, agent_world_model, wildfire
  • aiohttp → 3.14.3 in agent_world_model, finrl, openapp, qed_math, sophistry_bench_sprint
  • h2/hpack in coding_tools_env, nltk in openapp_env, pyjwt in tbench2_env, pillow in websearch_env

repl_env files are left untouched so we do not regress the pypdf>=6.16.1 lower bound already on main.

This supersedes #1015 and #1131.

Core Dependabot status (no second mergeable PR today):

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation
  • New environment
  • Refactoring
  • Dependency updates (envs only)

Alignment Checklist

Before submitting, verify:

  • I have read .claude/docs/PRINCIPLES.md and this PR aligns with our principles
  • I have checked .claude/docs/INVARIANTS.md and no invariants are violated (envs lockfiles only; no agent-facing reset/API changes)
  • uv lock --check passed in every updated env

RFC Status

  • Not required (bug fix, docs, minor refactoring)
  • RFC exists: #___
  • RFC needed (will create before merge)

Test Plan

  • git diff --check origin/main...HEAD
  • Scope is envs/**/uv.lock plus envs/textarena_env/pyproject.toml
  • uv lock --check in each updated environment: pass
  • No src/ or root pyproject.toml changes

Claude Code Review

N/A — Dependabot lockfile rollup.

This automation cannot close PRs (GitHub token returns 403). Please close these superseded PRs:

Open in Web View Automation 

Roll up the remaining open envs Dependabot bumps and unpublished
lockfile security updates from the prior aggregate so maintainers
can land one PR instead of several overlapping ones.

Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
cursor Bot added a commit that referenced this pull request Sep 17, 2026
Refreshed onto main 34825a7. Only envs/**/uv.lock changes: cryptography 50.0.0, aiohttp 3.14.3, h2 4.4.1/hpack 4.2.0, nltk 3.10.0, pyjwt 2.13.0, pillow 12.3.0. All 17 lockfiles re-validated with uv lock --check. Supersedes #1160, #1152, #1146, #1015.
@cursor

cursor Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

Closing: superseded by the merged envs Dependabot rollup #1173 (main 4a1fa2a) and the open #1192. All 28 bumps here are already on main at an equal or newer version.

@burtenshaw burtenshaw closed this Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants