Skip to content

chore(deps): aggregate envs Dependabot updates - #1152

Closed
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/dependabot-envs-2026-09-11
Closed

cursor[bot] wants to merge 1 commit into
mainfrom
cursor/dependabot-envs-2026-09-11

Conversation

@cursor

@cursor cursor Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Summary

Rebases yesterday's envs Dependabot rollup (#1146) onto current main so remaining lockfile security bumps can merge cleanly after #1114 (coding_env tornado) and #1116 (textarena nltk) landed.

No new individual Dependabot PRs opened overnight. This PR only carries unpublished envs/**/uv.lock updates from #1146 / #1015.

Included (still not on main):

  • cryptography → 50.0.0 in calendar, carla, chat, opencode, pelican_svg, pi, qed_math, sophistry_bench_sprint, sumo_rl, terminus, websearch, agent_world_model, wildfire
  • aiohttp → 3.14.3 in agent_world_model, finrl, openapp, qed_math, sophistry_bench_sprint
  • h2 4.4.1 / hpack 4.2.0 in coding_tools_env
  • nltk 3.10.0 in openapp_env
  • pyjwt 2.13.0 in tbench2_env
  • pillow 12.3.0 in websearch_env

Left untouched so we do not regress main:

This supersedes #1146 and #1015.

Core Dependabot status (no second mergeable PR today):

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation
  • New environment
  • Refactoring
  • Dependency updates (envs only)

Alignment Checklist

Before submitting, verify:

  • I have read .claude/docs/PRINCIPLES.md and this PR aligns with our principles
  • I have checked .claude/docs/INVARIANTS.md and no invariants are violated (envs lockfiles only; no agent-facing reset/API changes)
  • uv lock --check passed in every updated env

RFC Status

  • Not required (bug fix, docs, minor refactoring)
  • RFC exists: #___
  • RFC needed (will create before merge)

Test Plan

  • git diff --check origin/main...HEAD
  • Scope is envs/**/uv.lock only (17 files)
  • uv lock --check in each updated environment: pass
  • No src/ or root pyproject.toml changes

Claude Code Review

N/A — Dependabot lockfile rollup.

This automation cannot close PRs (GitHub token returns 403). Please close these superseded aggregates:

Open in Web View Automation 

Rebase yesterday's envs rollup onto current main so remaining
lockfile security bumps can land without conflicting with the
already-merged coding_env tornado and textarena nltk updates.

Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Keep this draft out of release candidates in its current form. Exact head fe8b9466 is clean and the generic repository checks pass, but this is not one routine dependency update:

  • cryptography jumps from versions 46–49 to 50.0.0 in 13 environment lockfiles. Lock consistency and core tests do not exercise those environments' TLS/crypto/runtime paths.
  • The diff also rewrites 924 existing package source entries from https://pypi.registries.huggingface.tech/ to https://pypi.org/simple across large lockfiles. That package-provenance migration is not disclosed in the PR summary and needs an explicit infrastructure decision; it is not incidental wheel churn.
  • The safe aiohttp/h2/hpack/NLTK/PyJWT/Pillow bumps are bundled with both higher-risk groups, preventing routine fast-track review.

Please split this into: (1) routine patch/minor lock updates, (2) the cryptography 50 update with affected multi-environment Docker/runtime smoke coverage, and (3) the registry-source migration with explicit infrastructure/operations approval and a clear provenance rationale. The split heads must each be refreshed and validated independently. The routine subset can then proceed under normal dependency-merge policy; the cryptography and registry subsets require human compatibility/security/infrastructure review.

Open in Web View Automation 

Sent by Cursor Automation: Release

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One additional compatibility gate from the exact-head audit: openapp_env moves NLTK 3.9.4 → 3.10.0. NLTK 3.10.x has the same NO_PROXY-only downloader regression that required the TextArena compatibility work; the upstream fix is not in 3.10.0. Please isolate this update and establish whether the OpenApps dependency ever downloads corpora at build/start/reset time. If it does, hold it for a fixed NLTK release or add equivalent tested compatibility handling; if resources are fully bundled and no downloader path is reachable, document that and add a NO_PROXY runtime smoke.

Within the requested routine split, finrl_env's aiohttp update and tbench2_env's PyJWT update are the clean fast-track subset. Other routine-looking updates overlap the registry, cryptography, or NLTK gates and should remain separated.

Open in Web View Automation 

Sent by Cursor Automation: Release

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correction to my prior NLTK note at exact head fe8b9466: the NO_PROXY-only downloader false positive was introduced in NLTK 3.10.3, not 3.10.0 (upstream nltk/nltk#3748). However, the proposed OpenApp 3.9.4 → 3.10.0 move still must not be fast-tracked: the official high-severity advisory GHSA-6ww7-3frv-cqxh classifies versions <=3.10.2 as affected by proxied-fetch SSRF and >=3.10.3 as patched; it specifically identifies 3.9.4 as a negative control.

So the safe dependency decision is: retain 3.9.4 for now, or isolate a move to 3.10.3 with affected OpenApp runtime coverage and the NO_PROXY compatibility assessment already required for TextArena. The existing three-way split request and the clean FinRL aiohttp / TBench2 PyJWT fast-track recommendation otherwise stand.

Open in Web View Automation 

Sent by Cursor Automation: Release

cursor Bot added a commit that referenced this pull request Sep 17, 2026
Refreshed onto main 34825a7. Only envs/**/uv.lock changes: cryptography 50.0.0, aiohttp 3.14.3, h2 4.4.1/hpack 4.2.0, nltk 3.10.0, pyjwt 2.13.0, pillow 12.3.0. All 17 lockfiles re-validated with uv lock --check. Supersedes #1160, #1152, #1146, #1015.
@cursor

cursor Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

Closing: superseded by the merged envs Dependabot rollup #1173 (main 4a1fa2a) and the open #1192. All 24 bumps here are already on main at an equal or newer version.

@burtenshaw burtenshaw closed this Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants