Skip to content

Python: Bump locked OpenAI SDK to 3.22.1 - #8882

Merged
Eduard van Valkenburg (eavanvalkenburg) merged 1 commit into
microsoft:mainfrom
eavanvalkenburg:openai-lock-bump
Sep 30, 2026
Merged

Eduard van Valkenburg (eavanvalkenburg) merged 1 commit into
microsoft:mainfrom
eavanvalkenburg:openai-lock-bump

Conversation

@eavanvalkenburg

Copy link
Copy Markdown
Member

Motivation & Context

python/uv.lock resolves openai==3.15.0. That version still has the SDK import-time regression tracked in openai/openai-python#2819. The fix, openai/openai-python#3898, shipped in OpenAI 3.16.1 and stops loading unused resources and Assistants types at startup. Every local and CI test process that imports the OpenAI-based clients pays the extra cost. This PR moves the development lock to the latest OpenAI release. It speeds up test runs and doesn't change what we ship.

Description & Review Guide

  • What are the major changes?
    • python/uv.lock: openai goes from 3.15.0 to 3.22.1, the latest on PyPI. I generated it with uv lock --upgrade-package openai==3.22.1. The lock has one openai entry with no resolution forks, and that entry moved.
    • This is a lock-only change. No pyproject.toml changed, and package ranges and floors stay the same: openai>=2.25.0,<4 in agent-framework-openai, openai>=2.45.0,<4 in DevUI, and openai>=1.99.0,<4 in Hosting Responses. The existing SDK-floor CI lanes keep testing those minimums. Lab's separate lock is untouched.
    • When uv re-resolved, it also tightened five dependency-edge markers. No package version, addition, or removal changed:
      • aiologic → sniffio/wrapt and culsans → aiologic now use python_full_version < '3.13'. That matches culsans, which is only required below Python 3.13.
      • powerfx → cffi/pythonnet and pythonnet → clr-loader now use python_full_version < '3.14'. That matches powerfx, which declarative only requires below Python 3.14.
      • I compared uv export --all-packages --all-extras --all-groups output for Python 3.11–3.14 before and after. The only difference is the openai line.
      • uv 0.10.x and 0.11.x produce this same diff. uv 0.12.16 would reformat the whole lock, so I didn't use it.
  • What is the impact of these changes?
    • The change affects only development and CI environments. Published package metadata doesn't change.
    • Local and CI test processes import the OpenAI SDK faster. These are local client-startup measurements, not service latency. They compare OpenAI 3.15.0 with 3.20.0 on macOS arm64 with Python 3.13.1 and Azure AI Projects 2.7.0. All other locked dependencies were the same. Each workload ran in 25 fresh python -I processes, interleaved, with mocked HTTP, inert credentials, and no network:
      • FoundryChatClient import through the first mocked non-streaming response: median 1,767 ms → 1,137 ms.
      • import openai alone, 20 processes each: median 826 ms → 530 ms.
      • OpenAI modules loaded by the first response: 1,517 → 550.
    • I also spot-checked the locked 3.22.1. import openai alone, with the same pinned dependencies and 20 interleaved python -I processes, gave a median of 931 ms on 3.15.0, 576 ms on 3.20.0, and 570 ms on 3.22.1. So 3.22.1 keeps the improvement.
    • Unit tests (uv run poe test -P <package>) and type checks (uv run poe typing -P <package>) pass locally with the new lock for openai, foundry, devui, hosting-responses, and foundry_hosting. The type checks are strict Pyright on source plus mypy, pyrefly, ty, zuban, and relaxed Pyright on tests. The OpenAI and Foundry import tests pass. Unit tests for core, foundry_local, ollama, and chatkit, and typing for core and foundry_local, pass too.
  • What do you want reviewers to focus on?
    • Are the five marker-only transitive edits acceptable?
    • Are we comfortable locking 3.22.1? It was released on 2026-09-30, so 3.20.0 is the more conservative choice.

Related Issue

No Agent Framework issue tracks this development-lock update, and no other open PR changes the locked OpenAI version. For the upstream fix, see openai/openai-python#2819, which openai/openai-python#3898 fixed in OpenAI 3.16.1.

Contribution Checklist

  • The code builds clean without any errors or warnings
  • All unit tests pass, and I have added new tests where possible
  • The PR follows the Contribution Guidelines
  • This PR is linked to an issue and there is no other open PR for this issue (see Related Issue above).
  • This is not a breaking change. If it is a breaking change, add the breaking change label (or add "[BREAKING]" to the title prefix, before or after any language prefix) — a workflow keeps the label and title prefix in sync automatically.

Development lock only: update openai 3.15.0 -> 3.22.1 in python/uv.lock.
No package dependency ranges changed. uv also tightened five transitive
dependency-edge markers without changing any resolved package version.
Copilot AI balanced review requested due to automatic review settings September 30, 2026 07:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MAF Automated Review — Iteration 1

Result: No findings
Scope: full PR (1 commit(s)): c30a17b10f17
Model: gpt-5.6-sol

Overview

This PR updates only the shared Python development/CI lock from OpenAI 3.15.0 to 3.22.1 while preserving published dependency ranges. The new artifacts are hash-pinned, the lock validates, and the transitive marker changes follow their parent Python-version gates. Existing cross-version workflows and OpenAI-facing tests provide concrete compatibility coverage, and no publishable Critical, High, or Medium issue was established.

Reviewed the supplied pull-request change set across correctness, security/reliability, architecture, and failure behavior.
No publishable findings remained after source verification for this scope.

Merged via the queue into microsoft:main with commit 2d99504 Sep 30, 2026
50 of 51 checks passed

This branch was successfully deployed

1 active deployment
github-app-auth — c30a17b1 Deployed Sep 30, 2026 by eavanvalkenburg via team_check #5603
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

python Usage: [Issues, PRs], Target: Python

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants