Skip to content

chore(deps): aggregate envs Dependabot updates - #1160

Closed
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/dependabot-envs-2026-09-15
Closed

cursor[bot] wants to merge 1 commit into
mainfrom
cursor/dependabot-envs-2026-09-15

Conversation

@cursor

@cursor cursor Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Summary

Rebases the 2026-09-11 envs Dependabot rollup (#1152) onto current main so remaining lockfile security bumps stay easy to merge after #1017 (typed-client envelope fix).

No new individual Dependabot PRs opened overnight (weekly dependabot.yml covers root uv excluding envs/**, plus GitHub Actions). This PR only carries unpublished envs/**/uv.lock updates from #1152 / #1146 / #1015.

Included (still not on main):

  • cryptography → 50.0.0 in calendar, carla, chat, opencode, pelican_svg, pi, qed_math, sophistry_bench_sprint, sumo_rl, terminus, websearch, agent_world_model, wildfire
  • aiohttp → 3.14.3 in agent_world_model, finrl, openapp, qed_math, sophistry_bench_sprint
  • h2 4.4.1 / hpack 4.2.0 in coding_tools_env
  • nltk 3.10.0 in openapp_env
  • pyjwt 2.13.0 in tbench2_env
  • pillow 12.3.0 in websearch_env

Left untouched so we do not regress main:

  • envs/coding_env (tornado 6.5.8 + Hugging Face registry already on main)
  • envs/textarena_env (nltk>=3.10.3 already on main)
  • envs/repl_env (pypdf>=6.16.1 already on main)

This supersedes #1152, #1146, and #1015.

Core Dependabot status (no second mergeable PR today):

  • No open Dependabot singles outside envs/.
  • Doc-builder pins on main (cf20b09) already match latest huggingface/doc-builder main. chore(deps): aggregate non-env dependabot updates #1109 would downgrade to 1b16dac.
  • FastMCP 4 (#1119, pin >=3.0.0,<5.0.0) remains blocked: HTTP and WebSocket inc_counter persistence still fail. Do not re-open until those tests pass.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation
  • New environment
  • Refactoring
  • Dependency updates (envs only)

Alignment Checklist

Before submitting, verify:

  • I have read .claude/docs/PRINCIPLES.md and this PR aligns with our principles
  • I have checked .claude/docs/INVARIANTS.md and no invariants are violated (envs lockfiles only; no agent-facing reset/API changes)
  • uv lock --check passed in every updated env

RFC Status

  • Not required (bug fix, docs, minor refactoring)
  • RFC exists: #___
  • RFC needed (will create before merge)

Test Plan

  • git diff --check origin/main...HEAD
  • Scope is envs/**/uv.lock only (17 files)
  • uv lock --check in each updated environment: pass
  • No src/ or root pyproject.toml changes
  • Branch is 0 behind / 1 ahead of origin/main

Claude Code Review

N/A — Dependabot lockfile rollup.

This automation cannot close PRs (GitHub token returns 403). Please close these superseded aggregates:

There were no open individual Dependabot PRs to close today.

Open in Web View Automation 

Rebase the 2026-09-11 envs lockfile rollup onto current main so remaining
security bumps stay easy to merge after #1017.

Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Release-manager intake for draft head d1c88ca8 (envs Dependabot rollup rebasing #1152 onto post-#1017 main).

Keep this draft and out of the 0.4.3 candidate. Same blockers as #1152:

  1. cryptography → 50.0.0 across many envs is a multi-major jump. Exact-head generic CI / validate-env-locks is not enough; needs multi-environment Docker/runtime smoke plus an explicit compatibility decision before merge.
  2. openapp_env NLTK 3.10.0 is not a safe routine bump: GHSA-6ww7-3frv-cqxh marks NLTK ≤3.10.2 vulnerable (patch is ≥3.10.3). Prefer keep 3.9.4, or take 3.10.3 with a NO_PROXY-only startup assessment (upstream #3748). Do not land 3.10.0.
  3. Please split routine patch/minor bumps (aiohttp/h2/hpack/pyjwt/pillow, etc.) from cryptography 50 and from any NLTK move, then re-request review on the routine-only slice.

Supersedes #1152 / #1146 / #1015 for tracking, but those drafts should stay closed or clearly marked superseded once a human confirms. Automation will not mark this ready or merge it.

Open in Web View Automation 

Sent by Cursor Automation: Release

cursor Bot added a commit that referenced this pull request Sep 17, 2026
Refreshed onto main 34825a7. Only envs/**/uv.lock changes: cryptography 50.0.0, aiohttp 3.14.3, h2 4.4.1/hpack 4.2.0, nltk 3.10.0, pyjwt 2.13.0, pillow 12.3.0. All 17 lockfiles re-validated with uv lock --check. Supersedes #1160, #1152, #1146, #1015.
@cursor

cursor Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

Closing: superseded by the merged envs Dependabot rollup #1173 (main 4a1fa2a) and the open #1192. All 24 bumps here are already on main at an equal or newer version.

@burtenshaw burtenshaw closed this Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants