chore(deps): bump httpx2 from 2.7.0 to 2.12.0 in the python-security group across 1 directory - #3823
Conversation
Castiron custom code✅ No new custom-code files detected. 47 mixed files remain; 0 existing customizations changed. Compared 47 existing customizations unchanged
7 more in the full report. A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 35650852099 --repo openai/openai-python \
--name castiron-custom-code-35650852099-1 --dir /tmp/castiron-custom-code-35650852099-1
git apply --stat /tmp/castiron-custom-code-35650852099-1/custom-code.patch
cat /tmp/castiron-custom-code-35650852099-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin febbcdfe39f6887caeb4c3c18e5aabb4404ef59b 899727a4939f2c87b613578a1933442e6882dbe1
python3 scripts/castiron/custom_code_report.py report \
--base febbcdfe39f6887caeb4c3c18e5aabb4404ef59b \
--head 899727a4939f2c87b613578a1933442e6882dbe1 --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-899727a4939f
cat /tmp/castiron-custom-code-899727a4939f/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 34b090b7ee
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
34b090b to
5963ac9
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5963ac9105
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
5963ac9 to
ea57da5
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ea57da525c
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
47b2400 to
b442724
Compare
d65635e to
8190202
Compare
Bumps the python-security group with 1 update in the / directory: [httpx2](https://github.com/pydantic/httpx2). Updates `httpx2` from 2.7.0 to 2.12.0 - [Release notes](https://github.com/pydantic/httpx2/releases) - [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md) - [Commits](pydantic/httpx2@v2.7.0...v2.12.0) --- updated-dependencies: - dependency-name: httpx2 dependency-version: 2.12.0 dependency-type: direct:production dependency-group: python-security ... Signed-off-by: dependabot[bot] <support@github.com>
8190202 to
a8d0d73
Compare
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4acb30c5c9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
marcuswood-oai
left a comment
There was a problem hiding this comment.
Reviewed the final diff at 899727a. The trimmed tests retain focused sync/async coverage for bounded, lossless decompression and immediate cleanup on malformed responses. All 17 applicable CI checks pass. Python 3.10 passed on rerun after an existing WebSocket fixture timing failure; that test also passed locally.
Automated Release PR --- ## [3.17.0](v3.16.2...v3.17.0) (2026-09-22) ### Features * **api:** add external storage configuration management ([#3909](#3909)) ([6332577](6332577)) * **api:** add safety case retrieval ([#3911](#3911)) ([a87b938](a87b938)) * **api:** add safety warning and deactivation webhook events ([#3908](#3908)) ([19f1f37](19f1f37)) * **api:** add session environment reset events ([#3913](#3913)) ([69a2c1d](69a2c1d)) * **api:** add SIP media security to incoming call events ([#3907](#3907)) ([c377eb2](c377eb2)) * **api:** support environment variable vault credentials ([#3905](#3905)) ([eeebc53](eeebc53)) ### Bug Fixes * **api:** correct model types and network policy docs ([618bb31](618bb31)) * **api:** preserve model choices and defer error response docs ([#3931](#3931)) ([6e7a90f](6e7a90f)) * **lib:** treat null message content as empty in parse_response ([#3851](#3851)) ([fab5283](fab5283)) * **lib:** use log.warning instead of the deprecated log.warn ([#3878](#3878)) ([56b1708](56b1708)) ### Chores * **api:** document API error response contracts ([#3917](#3917)) ([fededc9](fededc9)) * **api:** document response management resources ([#3912](#3912)) ([eaa5b77](eaa5b77)) * **deps:** bump actions/github-script from 7.1.0 to 9.0.0 ([#3769](#3769)) ([32e07e1](32e07e1)) * **deps:** bump actions/upload-artifact from 5.0.0 to 7.0.1 ([#3767](#3767)) ([b413abe](b413abe)) * **deps:** bump CodeQL init and analyze to 4.37.8 ([#3765](#3765)) ([f95237f](f95237f)) * **deps:** bump CodeQL init and analyze to 4.37.8 ([#3766](#3766)) ([690a8b5](690a8b5)) * **deps:** bump httpx2 from 2.7.0 to 2.12.0 in the python-security group across 1 directory ([#3823](#3823)) ([9b8e399](9b8e399)) * **deps:** bump openai/codex-action from 1.11 to 1.12 ([#3768](#3768)) ([9c1579b](9c1579b)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: openai-sdks[bot] <284451331+openai-sdks[bot]@users.noreply.github.com>
|
@marcuswood-oai Acknowledging your final-head review: its local regressions and CI apply to |
Raise the published HTTPX2 minimum to 2.12.0 so SDK installations receive incremental response decompression and stream cleanup on decoding errors. Keep the matching HTTPcore2 constraint and update both the project and runnable realtime-example locks.
Keep focused synchronous and asynchronous regressions for bounded, lossless decoding of a large gzip response and immediate stream closure on malformed gzip/deflate data. Existing large JSON/SSE parser coverage remains intact, with all large cases in one collected test to keep xdist execution sequential. Preserve the release-please lock marker and align policy, wheel-metadata validation, and retry-header assertions with the new dependency.
Validation: five focused tests, Ruff, Pyright, and mypy passed locally after trimming redundant parser and dependency-floor tests. Earlier regression reversal confirmed the bounded-decoding and stream-cleanup probes fail against HTTPX2 2.10.0. Changed dependency artifact URLs and hashes were verified against PyPI, and build metadata was reviewed. Hosted CI validates the final head, including the Python 3.10/3.14 and HTTPX2 test jobs, wheel installation, lint, and custom-code budgets.
Bumps the python-security group with 1 update in the / directory: httpx2.
Updates
httpx2from 2.7.0 to 2.12.0Release notes
Sourced from httpx2's releases.
... (truncated)
Changelog
Sourced from httpx2's changelog.
... (truncated)
Commits
71ae23bVersion 2.12.0 (#1147)4fd0c70Decode compressed response bodies incrementally (#1126)d588e52Usebackports.zstdon Python 3.13 and earlier (#1146)344589dVersion 2.11.0 (#1143)de96d81Validate multipart part headers (#1142)51c3269Require brotli 1.2.0 in the brotli extra (#1141)829b93aRespect explicit Transfer-Encoding headers (#1137)4fa6c8eFix changelog extraction regex for H2 release headings (#1136)8a6f370Restore deprecated status code aliases (#1135)d03f1ecAdd public Origin API (#1134)