Skip to content

chore(deps): aggregate envs Dependabot updates - #1192

Merged
cursor[bot] merged 2 commits into
mainfrom
cursor/dependabot-envs-2026-09-17
Sep 17, 2026
Merged

cursor[bot] merged 2 commits into
mainfrom
cursor/dependabot-envs-2026-09-17

Conversation

@cursor

@cursor cursor Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Daily Dependabot triage for envs/. No new individual Dependabot PRs were open. Yesterday's lockfile rollup (#1173) already landed on main. This PR folds the one remaining unpublished security bump from superseded aggregate #1015: repl_env cryptography 46.0.6 → 50.0.1, applied with uv lock --upgrade-package cryptography so pypdf stays at 6.16.1.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation
  • New environment
  • Refactoring
  • Dependency / security lockfile update (envs/ only)

Alignment Checklist

Before submitting, verify:

  • I have read .claude/docs/PRINCIPLES.md and this PR aligns with our principles
  • I have checked .claude/docs/INVARIANTS.md and no invariants are violated
  • uv lock --check passed in envs/repl_env (envs lockfile-only; full core pytest not required)

RFC Status

  • Not required (bug fix, docs, minor refactoring)
  • RFC exists: #___
  • RFC needed (will create before merge)

Test Plan

  • uv lock --check in envs/repl_env
  • Confirm pypdf remains 6.16.1 and cryptography is 50.0.1 in envs/repl_env/uv.lock
  • No src/ or root pyproject.toml changes

Claude Code Review

N/A — daily Dependabot consolidation automation.

Triage notes

Open individual Dependabot PRs: none (author:app/dependabot). No leftover dependabot/* remote branches. Next weekly Dependabot window is 2026-09-22 (~02:54 UTC).

Core aggregate: not opened. main already pins huggingface/doc-builder @cf20b09 (matches latest huggingface/doc-builder main). #1109 would downgrade to @1b16dac. cursor/dependabot-core-2026-09-08 would downgrade to @9978a413. FastMCP 4 (#1119, pin >=3.0.0,<5.0.0) stays out until HTTP/WebSocket inc_counter persistence passes.

Please close superseded aggregates (this token cannot close PRs):

Open in Web View Automation 

Note

Medium Risk
Upgrades a security-sensitive transitive dependency (via authlib) with a large version jump, though scope is limited to the repl_env lockfile.

Overview
Bumps cryptography in envs/repl_env/uv.lock from 46.0.6 to 50.0.1 as the remaining envs security rollup from superseded Dependabot aggregates. The lock was refreshed with a targeted uv lock --upgrade-package cryptography so other pins (e.g. pypdf) are not pulled forward.

There are no application or pyproject.toml changes—only resolved wheel/sdist metadata for the new cryptography release.

Reviewed by Cursor Bugbot for commit 8d95562. Bugbot is set up for automated code reviews on this repo. Configure here.

cursoragent and others added 2 commits September 17, 2026 07:18
Fold the remaining unpublished repl_env cryptography bump from #1015
(46.0.6 -> 50.0.1) without copying that lockfile, which would have
downgraded pypdf below 6.16.1. uv lock --check passed.

Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
…s-2026-09-17

Co-authored-by: burtenshaw <burtenshaw@users.noreply.github.com>
@cursor
cursor Bot marked this pull request as ready for review September 17, 2026 09:10
@cursor
cursor Bot merged commit a4a2779 into main Sep 17, 2026
12 checks passed
@cursor
cursor Bot deleted the cursor/dependabot-envs-2026-09-17 branch September 17, 2026 09:10

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alignment Review Report

Scope: Dependabot-style, lockfile-only change. envs/repl_env/uv.lock bumps the transitive dependency cryptography 46.0.6 → 50.0.1. No Python/source files, public APIs, or configs are touched.

Automated Checks

  • Lint: PASS (for this PR). bash .claude/hooks/lint.sh surfaces pre-existing issues (usort flags tests/envs/test_grid_world.py and tests/envs/test_julia_env.py; ruff format flags 56 files across envs/), but none are in this PR's diff — it changes zero .py files, and no flagged file lives under repl_env/ or src/. No new lint issues introduced.
  • Debug code: CLEAN (for this PR). check-debug.sh reports only pre-existing print/TODO occurrences in src/; none are introduced by this change.
  • Lockfile validation (extra): uv lock --check passes — the lock is consistent with pyproject.toml (121 packages resolved). Every added artifact URL points to official PyPI (files.pythonhosted.org), each wheel/sdist carries a sha256 hash, and cryptography is an unconstrained transitive dependency (pulled via authlib, pyjwt[crypto], and secretstorage), so the bump violates no version pin.

Open RFCs Context

Active RFCs — In Review: 000 (Principles/Roadmap), 001 (Abstractions), 002 (Env Spec), 003 (MCP Support), 005 (Agentic Harnesses), 008 (Env Auto-Validation), 012 (Harbor Capture); Draft: 010 (ECHO token world model), 011 (ARD catalog discovery). None concern dependency management or the repl_env environment, so none are affected by this change.

Tier 1: Fixes Required

None. No mechanical issues (lint, debug code, type/import/syntax, or security) are attributable to this PR.

Tier 2: Alignment Discussion

Principle Conflicts: None identified. No API surface, client/server boundary, reward path, or Gym/MCP interface is affected (INVARIANTS unchanged).

RFC Conflicts: None identified.

Summary

  • 0 mechanical issues to fix
  • 0 alignment points for human review
  • 0 RFC conflicts to discuss

Verdict: Clean, low-risk transitive security bump; consistent with OpenEnv principles and invariants.

Non-blocking awareness note: cryptography advances four major versions (46 → 50). It is a deep transitive dependency and uv resolved the graph cleanly (all dependents accept the new major), so there is no declared incompatibility — noted only for release-notes awareness.

Open in Web View Automation 

Sent by Cursor Automation: Pre-review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant