chore(deps): aggregate envs Dependabot updates - #1192
Conversation
Fold the remaining unpublished repl_env cryptography bump from #1015 (46.0.6 -> 50.0.1) without copying that lockfile, which would have downgraded pypdf below 6.16.1. uv lock --check passed. Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
…s-2026-09-17 Co-authored-by: burtenshaw <burtenshaw@users.noreply.github.com>
There was a problem hiding this comment.
Alignment Review Report
Scope: Dependabot-style, lockfile-only change. envs/repl_env/uv.lock bumps the transitive dependency cryptography 46.0.6 → 50.0.1. No Python/source files, public APIs, or configs are touched.
Automated Checks
- Lint: PASS (for this PR).
bash .claude/hooks/lint.shsurfaces pre-existing issues (usortflagstests/envs/test_grid_world.pyandtests/envs/test_julia_env.py;ruff formatflags 56 files acrossenvs/), but none are in this PR's diff — it changes zero.pyfiles, and no flagged file lives underrepl_env/orsrc/. No new lint issues introduced. - Debug code: CLEAN (for this PR).
check-debug.shreports only pre-existingprint/TODOoccurrences insrc/; none are introduced by this change. - Lockfile validation (extra):
uv lock --checkpasses — the lock is consistent withpyproject.toml(121 packages resolved). Every added artifact URL points to official PyPI (files.pythonhosted.org), each wheel/sdist carries asha256hash, andcryptographyis an unconstrained transitive dependency (pulled viaauthlib,pyjwt[crypto], andsecretstorage), so the bump violates no version pin.
Open RFCs Context
Active RFCs — In Review: 000 (Principles/Roadmap), 001 (Abstractions), 002 (Env Spec), 003 (MCP Support), 005 (Agentic Harnesses), 008 (Env Auto-Validation), 012 (Harbor Capture); Draft: 010 (ECHO token world model), 011 (ARD catalog discovery). None concern dependency management or the repl_env environment, so none are affected by this change.
Tier 1: Fixes Required
None. No mechanical issues (lint, debug code, type/import/syntax, or security) are attributable to this PR.
Tier 2: Alignment Discussion
Principle Conflicts: None identified. No API surface, client/server boundary, reward path, or Gym/MCP interface is affected (INVARIANTS unchanged).
RFC Conflicts: None identified.
Summary
- 0 mechanical issues to fix
- 0 alignment points for human review
- 0 RFC conflicts to discuss
Verdict: Clean, low-risk transitive security bump; consistent with OpenEnv principles and invariants.
Non-blocking awareness note: cryptography advances four major versions (46 → 50). It is a deep transitive dependency and uv resolved the graph cleanly (all dependents accept the new major), so there is no declared incompatibility — noted only for release-notes awareness.
Sent by Cursor Automation: Pre-review


Summary
Daily Dependabot triage for
envs/. No new individual Dependabot PRs were open. Yesterday's lockfile rollup (#1173) already landed onmain. This PR folds the one remaining unpublished security bump from superseded aggregate #1015:repl_envcryptography46.0.6 → 50.0.1, applied withuv lock --upgrade-package cryptographysopypdfstays at 6.16.1.Type of Change
envs/only)Alignment Checklist
Before submitting, verify:
.claude/docs/PRINCIPLES.mdand this PR aligns with our principles.claude/docs/INVARIANTS.mdand no invariants are violateduv lock --checkpassed inenvs/repl_env(envs lockfile-only; full core pytest not required)RFC Status
Test Plan
uv lock --checkinenvs/repl_envpypdfremains 6.16.1 andcryptographyis 50.0.1 inenvs/repl_env/uv.locksrc/or rootpyproject.tomlchangesClaude Code Review
N/A — daily Dependabot consolidation automation.
Triage notes
Open individual Dependabot PRs: none (
author:app/dependabot). No leftoverdependabot/*remote branches. Next weekly Dependabot window is 2026-09-22 (~02:54 UTC).Core aggregate: not opened.
mainalready pinshuggingface/doc-builder@cf20b09(matches latesthuggingface/doc-buildermain). #1109 would downgrade to@1b16dac.cursor/dependabot-core-2026-09-08would downgrade to@9978a413. FastMCP 4 (#1119, pin>=3.0.0,<5.0.0) stays out until HTTP/WebSocketinc_counterpersistence passes.Please close superseded aggregates (this token cannot close PRs):
Note
Medium Risk
Upgrades a security-sensitive transitive dependency (via
authlib) with a large version jump, though scope is limited to therepl_envlockfile.Overview
Bumps
cryptographyinenvs/repl_env/uv.lockfrom 46.0.6 to 50.0.1 as the remaining envs security rollup from superseded Dependabot aggregates. The lock was refreshed with a targeteduv lock --upgrade-package cryptographyso other pins (e.g.pypdf) are not pulled forward.There are no application or
pyproject.tomlchanges—only resolved wheel/sdist metadata for the newcryptographyrelease.Reviewed by Cursor Bugbot for commit 8d95562. Bugbot is set up for automated code reviews on this repo. Configure here.