chore(deps): aggregate envs Dependabot updates - #1160
Closed
cursor[bot] wants to merge 1 commit into
Closed
cursor[bot] wants to merge 1 commit into
cursor[bot] wants to merge 1 commit into
Conversation
Rebase the 2026-09-11 envs lockfile rollup onto current main so remaining security bumps stay easy to merge after #1017. Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
Contributor
Author
There was a problem hiding this comment.
Release-manager intake for draft head d1c88ca8 (envs Dependabot rollup rebasing #1152 onto post-#1017 main).
Keep this draft and out of the 0.4.3 candidate. Same blockers as #1152:
- cryptography → 50.0.0 across many envs is a multi-major jump. Exact-head generic CI /
validate-env-locksis not enough; needs multi-environment Docker/runtime smoke plus an explicit compatibility decision before merge. - openapp_env NLTK 3.10.0 is not a safe routine bump: GHSA-6ww7-3frv-cqxh marks NLTK ≤3.10.2 vulnerable (patch is ≥3.10.3). Prefer keep 3.9.4, or take 3.10.3 with a
NO_PROXY-only startup assessment (upstream #3748). Do not land 3.10.0. - Please split routine patch/minor bumps (aiohttp/h2/hpack/pyjwt/pillow, etc.) from cryptography 50 and from any NLTK move, then re-request review on the routine-only slice.
Supersedes #1152 / #1146 / #1015 for tracking, but those drafts should stay closed or clearly marked superseded once a human confirms. Automation will not mark this ready or merge it.
Sent by Cursor Automation: Release
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
Rebases the 2026-09-11 envs Dependabot rollup (#1152) onto current
mainso remaining lockfile security bumps stay easy to merge after#1017(typed-client envelope fix).No new individual Dependabot PRs opened overnight (weekly
dependabot.ymlcovers root uv excludingenvs/**, plus GitHub Actions). This PR only carries unpublishedenvs/**/uv.lockupdates from #1152 / #1146 / #1015.Included (still not on main):
Left untouched so we do not regress main:
envs/coding_env(tornado 6.5.8 + Hugging Face registry already on main)envs/textarena_env(nltk>=3.10.3already on main)envs/repl_env(pypdf>=6.16.1already on main)This supersedes #1152, #1146, and #1015.
Core Dependabot status (no second mergeable PR today):
envs/.cf20b09) already match latesthuggingface/doc-buildermain. chore(deps): aggregate non-env dependabot updates #1109 would downgrade to1b16dac.#1119, pin>=3.0.0,<5.0.0) remains blocked: HTTP and WebSocketinc_counterpersistence still fail. Do not re-open until those tests pass.Type of Change
Alignment Checklist
Before submitting, verify:
.claude/docs/PRINCIPLES.mdand this PR aligns with our principles.claude/docs/INVARIANTS.mdand no invariants are violated (envs lockfiles only; no agent-facing reset/API changes)uv lock --checkpassed in every updated envRFC Status
Test Plan
git diff --check origin/main...HEADenvs/**/uv.lockonly (17 files)uv lock --checkin each updated environment: passsrc/or rootpyproject.tomlchangesorigin/mainClaude Code Review
N/A — Dependabot lockfile rollup.
This automation cannot close PRs (GitHub token returns 403). Please close these superseded aggregates:
There were no open individual Dependabot PRs to close today.