chore(deps): aggregate envs Dependabot updates - #1152
cursor[bot] wants to merge 1 commit into
Conversation
Rebase yesterday's envs rollup onto current main so remaining lockfile security bumps can land without conflicting with the already-merged coding_env tornado and textarena nltk updates. Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
There was a problem hiding this comment.
Keep this draft out of release candidates in its current form. Exact head fe8b9466 is clean and the generic repository checks pass, but this is not one routine dependency update:
cryptographyjumps from versions 46–49 to 50.0.0 in 13 environment lockfiles. Lock consistency and core tests do not exercise those environments' TLS/crypto/runtime paths.- The diff also rewrites 924 existing package source entries from
https://pypi.registries.huggingface.tech/tohttps://pypi.org/simpleacross large lockfiles. That package-provenance migration is not disclosed in the PR summary and needs an explicit infrastructure decision; it is not incidental wheel churn. - The safe aiohttp/h2/hpack/NLTK/PyJWT/Pillow bumps are bundled with both higher-risk groups, preventing routine fast-track review.
Please split this into: (1) routine patch/minor lock updates, (2) the cryptography 50 update with affected multi-environment Docker/runtime smoke coverage, and (3) the registry-source migration with explicit infrastructure/operations approval and a clear provenance rationale. The split heads must each be refreshed and validated independently. The routine subset can then proceed under normal dependency-merge policy; the cryptography and registry subsets require human compatibility/security/infrastructure review.
Sent by Cursor Automation: Release
There was a problem hiding this comment.
One additional compatibility gate from the exact-head audit: openapp_env moves NLTK 3.9.4 → 3.10.0. NLTK 3.10.x has the same NO_PROXY-only downloader regression that required the TextArena compatibility work; the upstream fix is not in 3.10.0. Please isolate this update and establish whether the OpenApps dependency ever downloads corpora at build/start/reset time. If it does, hold it for a fixed NLTK release or add equivalent tested compatibility handling; if resources are fully bundled and no downloader path is reachable, document that and add a NO_PROXY runtime smoke.
Within the requested routine split, finrl_env's aiohttp update and tbench2_env's PyJWT update are the clean fast-track subset. Other routine-looking updates overlap the registry, cryptography, or NLTK gates and should remain separated.
Sent by Cursor Automation: Release
There was a problem hiding this comment.
Correction to my prior NLTK note at exact head fe8b9466: the NO_PROXY-only downloader false positive was introduced in NLTK 3.10.3, not 3.10.0 (upstream nltk/nltk#3748). However, the proposed OpenApp 3.9.4 → 3.10.0 move still must not be fast-tracked: the official high-severity advisory GHSA-6ww7-3frv-cqxh classifies versions <=3.10.2 as affected by proxied-fetch SSRF and >=3.10.3 as patched; it specifically identifies 3.9.4 as a negative control.
So the safe dependency decision is: retain 3.9.4 for now, or isolate a move to 3.10.3 with affected OpenApp runtime coverage and the NO_PROXY compatibility assessment already required for TextArena. The existing three-way split request and the clean FinRL aiohttp / TBench2 PyJWT fast-track recommendation otherwise stand.
Sent by Cursor Automation: Release


Summary
Rebases yesterday's envs Dependabot rollup (#1146) onto current
mainso remaining lockfile security bumps can merge cleanly after#1114(coding_env tornado) and#1116(textarena nltk) landed.No new individual Dependabot PRs opened overnight. This PR only carries unpublished
envs/**/uv.lockupdates from #1146 / #1015.Included (still not on main):
Left untouched so we do not regress main:
envs/coding_env(tornado 6.5.8 + Hugging Face registry already on main)envs/textarena_env(nltk>=3.10.3already on main; chore(deps): aggregate envs Dependabot updates #1146 still had>=3.10.0)envs/repl_env(pypdf>=6.16.1already on main)This supersedes #1146 and #1015.
Core Dependabot status (no second mergeable PR today):
envs/.cf20b09) are already newer than chore(deps): aggregate non-env dependabot updates #1109 (1b16dac). Opening a core PR from chore(deps): aggregate non-env dependabot updates #1109 would downgrade workflows.#1119, pin>=3.0.0,<5.0.0) remains blocked: HTTP and WebSocketinc_counterpersistence still fail.#1119was closed 2026-09-10; do not re-open until those tests pass.Type of Change
Alignment Checklist
Before submitting, verify:
.claude/docs/PRINCIPLES.mdand this PR aligns with our principles.claude/docs/INVARIANTS.mdand no invariants are violated (envs lockfiles only; no agent-facing reset/API changes)uv lock --checkpassed in every updated envRFC Status
Test Plan
git diff --check origin/main...HEADenvs/**/uv.lockonly (17 files)uv lock --checkin each updated environment: passsrc/or rootpyproject.tomlchangesClaude Code Review
N/A — Dependabot lockfile rollup.
This automation cannot close PRs (GitHub token returns 403). Please close these superseded aggregates: