Repository navigation
chore(deps): bump the minor-and-patch group across 1 directory with 17 updates - #975
dependabot[bot] wants to merge 1 commit into
Conversation
langwatch-agent
left a comment
There was a problem hiding this comment.
No actionable findings in this static review.
Reviewed the Python dependency/lockfile changes and existing CI without finding a sufficiently established code defect to report inline. This is NOT a green validation result: the PR's Python job exits 3 with an internal error in pytest_asyncio_concurrent's asyncio.get_event_loop(), after 1470 passes and seven errors. Main also has failures, but the latest main log I inspected showed live-example/budget errors rather than proving this internal error inherited. Isolate the async test-runner combination and obtain a completing run before treating the bump as validated.
Validation boundary: review skill used; external PR code, dependency installation, and package scripts were not executed. This is not an approval or a claim that untested dependency artifacts are safe.
LangWatch-Review: verdict=clean sha=0f23488747a502f3f38b8c446ce889d950285eba p0=0 p1=0 p2=0 p3=0
0f23488 to
2863590
Compare
langwatch-agent
left a comment
There was a problem hiding this comment.
No actionable findings established in this static review (P0=0, P1=0, P2=0, P3=0).
Reviewed Python lock package/version/source changes. No concrete security or compatibility defect was established statically. This is NOT ready-on-CI evidence: test (3.12) exits 3 after pytest_asyncio_concurrent calls asyncio.get_event_loop with no current loop (1470 passed, 7 errors in the log). I have not established which dependency change caused that failure or whether it also occurs on base. Resolve or isolate that red job before treating this update as validated.
External-contribution safety: reused the existing worktree; no PR code, dependency installation, package scripts, or live secret-bearing tests were executed. This is a COMMENT review, not approval or a claim that all CI passed.
LangWatch-Review: verdict=clean sha=286359076a0e0a495e4c6ed4e75d81f103074aab p0=0 p1=0 p2=0 p3=0
2863590 to
4bb2306
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
langwatch-agent
left a comment
There was a problem hiding this comment.
1 P2 dependency-migration finding; details inline. Static review of the current head, base consumers and CI logs. No PR code, installs or package scripts executed.
LangWatch-Review: verdict=findings sha=4bb23060f01aff0149690f419deabad56bccc69d p0=0 p1=0 p2=1 p3=0
| ] | ||
|
|
||
| [[package]] | ||
| name = "pytest-asyncio" | ||
| version = "1.3.0" | ||
| version = "1.4.0" |
There was a problem hiding this comment.
P2 · Reconcile the two asyncio test plugins before the bump
-
What you're looking at. This upgrades pytest-asyncio to 1.4.0 while pytest-asyncio-concurrent still relies on a current global event loop.
-
Why it's scary. The 1.4 runner lifecycle no longer restores the previous loop in _temporary_event_loop_policy. Current-head Python 3.12 CI job 104151864356 ends with an INTERNALERROR in pytest_asyncio_concurrent.plugin at asyncio.get_event_loop(), after seven event-structure setup errors. The latest main Python run passed. Keep compatible test-plugin versions or explicitly reconcile loop ownership, and require the complete Python 3.12 job including concurrent groups to finish normally. No local reproduction was executed, so isolate this version change when validating the fix.
4bb2306 to
ad585c2
Compare
langwatch-agent
left a comment
There was a problem hiding this comment.
One P2 remains on this head; see inline evidence from the current CI run. Static review only, with no contributor code or package scripts executed locally.
LangWatch-Review: verdict=findings sha=ad585c26e21f18dca2ac88ac8a445a66e62b85b8 p0=0 p1=0 p2=1 p3=0
| ] | ||
|
|
||
| [[package]] | ||
| name = "pytest-asyncio" | ||
| version = "1.3.0" | ||
| version = "1.4.0" |
There was a problem hiding this comment.
P2 · Reconcile asyncio test-plugin loop ownership
-
What you're looking at. The lock upgrades pytest-asyncio from 1.3.0 to 1.4.0 while retaining the concurrent test plugin.
-
Why it's scary. The current Python 3.12 job still terminates with INTERNALERROR in pytest_asyncio_concurrent.plugin at asyncio.get_event_loop(): there is no current event loop. This leaves concurrent coverage incomplete despite the many passing tests. Retain compatible plugin versions or reconcile loop ownership and rerun the complete job. The failure is confirmed in CI, but the exact version interaction was not isolated locally. CI evidence.
…7 updates Bumps the minor-and-patch group with 17 updates in the /python directory: | Package | From | To | | --- | --- | --- | | [pytest](https://github.com/pytest-dev/pytest) | `9.0.3` | `9.1.1` | | [pytest-rerunfailures](https://github.com/pytest-dev/pytest-rerunfailures) | `16.2` | `16.7` | | [litellm](https://github.com/BerriAI/litellm) | `1.85.0` | `1.102.1` | | [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` | | [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` | | [joblib](https://github.com/joblib/joblib) | `1.5.3` | `1.6.0` | | [pytest-asyncio](https://github.com/pytest-dev/pytest-asyncio) | `1.3.0` | `1.4.0` | | [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` | | [langwatch](https://github.com/langwatch/langwatch) | `1.0.0` | `1.4.0` | | [twilio](https://github.com/twilio/twilio-python) | `9.10.9` | `9.11.1` | | [fastapi](https://github.com/fastapi/fastapi) | `0.136.1` | `0.141.1` | | [uvicorn](https://github.com/Kludex/uvicorn) | `0.47.0` | `0.54.0` | | [google-genai](https://github.com/googleapis/python-genai) | `2.4.0` | `2.25.0` | | [elevenlabs](https://github.com/elevenlabs/elevenlabs-python) | `2.49.0` | `2.69.0` | | [pre-commit](https://github.com/pre-commit/pre-commit) | `4.6.0` | `4.6.2` | | [pyright](https://github.com/RobertCraigie/pyright-python) | `1.1.409` | `1.1.414` | | [streamlit](https://github.com/streamlit/streamlit) | `1.57.0` | `1.64.0` | Updates `pytest` from 9.0.3 to 9.1.1 - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst) - [Commits](pytest-dev/pytest@9.0.3...9.1.1) Updates `pytest-rerunfailures` from 16.2 to 16.7 - [Changelog](https://github.com/pytest-dev/pytest-rerunfailures/blob/master/CHANGES.rst) - [Commits](pytest-dev/pytest-rerunfailures@16.2...16.7) Updates `litellm` from 1.85.0 to 1.102.1 - [Release notes](https://github.com/BerriAI/litellm/releases) - [Commits](BerriAI/litellm@v1.85.0...v1.102.1) Updates `python-dotenv` from 1.2.2 to 1.2.3 - [Release notes](https://github.com/theskumar/python-dotenv/releases) - [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md) - [Commits](theskumar/python-dotenv@v1.2.2...v1.2.3) Updates `pydantic` from 2.13.4 to 2.13.5 - [Release notes](https://github.com/pydantic/pydantic/releases) - [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md) - [Commits](pydantic/pydantic@v2.13.4...v2.13.5) Updates `joblib` from 1.5.3 to 1.6.0 - [Release notes](https://github.com/joblib/joblib/releases) - [Changelog](https://github.com/joblib/joblib/blob/main/CHANGES.rst) - [Commits](joblib/joblib@1.5.3...1.6.0) Updates `pytest-asyncio` from 1.3.0 to 1.4.0 - [Release notes](https://github.com/pytest-dev/pytest-asyncio/releases) - [Commits](pytest-dev/pytest-asyncio@v1.3.0...v1.4.0) Updates `pydantic-settings` from 2.14.2 to 2.15.0 - [Release notes](https://github.com/pydantic/pydantic-settings/releases) - [Commits](pydantic/pydantic-settings@v2.14.2...v2.15.0) Updates `langwatch` from 1.0.0 to 1.4.0 - [Release notes](https://github.com/langwatch/langwatch/releases) - [Changelog](https://github.com/langwatch/langwatch/blob/main/CHANGELOG.md) - [Commits](https://github.com/langwatch/langwatch/compare/langwatch@v1.0.0...langwatch@v1.4.0) Updates `twilio` from 9.10.9 to 9.11.1 - [Release notes](https://github.com/twilio/twilio-python/releases) - [Changelog](https://github.com/twilio/twilio-python/blob/main/CHANGES.md) - [Commits](twilio/twilio-python@9.10.9...9.11.1) Updates `fastapi` from 0.136.1 to 0.141.1 - [Release notes](https://github.com/fastapi/fastapi/releases) - [Commits](fastapi/fastapi@0.136.1...0.141.1) Updates `uvicorn` from 0.47.0 to 0.54.0 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.47.0...0.54.0) Updates `google-genai` from 2.4.0 to 2.25.0 - [Release notes](https://github.com/googleapis/python-genai/releases) - [Changelog](https://github.com/googleapis/python-genai/blob/main/CHANGELOG.md) - [Commits](googleapis/python-genai@v2.4.0...v2.25.0) Updates `elevenlabs` from 2.49.0 to 2.69.0 - [Release notes](https://github.com/elevenlabs/elevenlabs-python/releases) - [Commits](elevenlabs/elevenlabs-python@v2.49.0...v2.69.0) Updates `pre-commit` from 4.6.0 to 4.6.2 - [Release notes](https://github.com/pre-commit/pre-commit/releases) - [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md) - [Commits](pre-commit/pre-commit@v4.6.0...v4.6.2) Updates `pyright` from 1.1.409 to 1.1.414 - [Release notes](https://github.com/RobertCraigie/pyright-python/releases) - [Commits](RobertCraigie/pyright-python@v1.1.409...v1.1.414) Updates `streamlit` from 1.57.0 to 1.64.0 - [Release notes](https://github.com/streamlit/streamlit/releases) - [Commits](streamlit/streamlit@1.57.0...1.64.0) --- updated-dependencies: - dependency-name: elevenlabs dependency-version: 2.66.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: fastapi dependency-version: 0.141.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: google-genai dependency-version: 2.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: joblib dependency-version: 1.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: langwatch dependency-version: 1.3.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: litellm dependency-version: 1.99.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: pre-commit dependency-version: 4.6.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: pydantic dependency-version: 2.13.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: pydantic-settings dependency-version: 2.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: pyright dependency-version: 1.1.411 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: pytest dependency-version: 9.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: pytest-asyncio dependency-version: 1.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: pytest-rerunfailures dependency-version: 16.6.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: python-dotenv dependency-version: 1.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: streamlit dependency-version: 1.63.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: twilio dependency-version: 9.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: uvicorn dependency-version: 0.52.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
ad585c2 to
9116ae8
Compare
|
Automated low-risk assessment This PR was evaluated against the repository's Low-Risk Pull Requests procedure and does not qualify as low risk.
This PR requires a manual review before merging. |
langwatch-agent
left a comment
There was a problem hiding this comment.
One P2 remains on this head; details and current CI evidence inline. Static review only; no contributor code, installs or package scripts executed locally.
LangWatch-Review: verdict=findings sha=9116ae839cbb7f54c260ee1ebb8235fbe533ed52 p0=0 p1=0 p2=1 p3=0
| ] | ||
|
|
||
| [[package]] | ||
| name = "pytest-asyncio" | ||
| version = "1.3.0" | ||
| version = "1.4.0" |
There was a problem hiding this comment.
P2 · Resolve the concurrent test-runner incompatibility before upgrading
-
What you're looking at. The lock continues to move pytest-asyncio from 1.3.0 to 1.4.0 alongside pytest and rerun-plugin changes, while retaining pytest_asyncio_concurrent.
-
Why it's scary. Current Python 3.12 CI still exits 3 with INTERNALERROR in pytest_asyncio_concurrent at asyncio.get_event_loop(): no current event loop. It reports 1535 passes but also seven errors and does not complete normally. The earlier finding remains: retain a working plugin combination or reconcile loop ownership, then obtain a completing run. The exact dependency interaction was not isolated locally. Current CI evidence.
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
Bumps the minor-and-patch group with 17 updates in the /python directory:
9.0.39.1.116.216.71.85.01.102.11.2.21.2.32.13.42.13.51.5.31.6.01.3.01.4.02.14.22.15.01.0.01.4.09.10.99.11.10.136.10.141.10.47.00.54.02.4.02.25.02.49.02.69.04.6.04.6.21.1.4091.1.4141.57.01.64.0Updates
pytestfrom 9.0.3 to 9.1.1Release notes
Sourced from pytest's releases.
... (truncated)
Commits
cf470ecPrepare release version 9.1.1e0c8ce6Merge pull request #14625 from pytest-dev/patchback/backports/9.1.x/a07c31a97...1b82d16Merge pull request #14624 from pytest-dev/patchback/backports/9.1.x/b375b79ec...501c4bcMerge pull request #14596 from bluetech/doc-classmethodb61f588Merge pull request #14622 from chrisburr/fix-14608-initial-conftest-test-subdir9a567e0[automated] Update plugin list (#14617) (#14618)ef8b299Merge pull request #14620 from pytest-dev/patchback/backports/9.1.x/680f9f3ed...66abd07Merge pull request #14220 from bysiber/fix-stale-iexp-raisesgroup79fbf93Merge pull request #14612 from pytest-dev/patchback/backports/9.1.x/974ed48b6...0d312ebMerge pull request #14611 from bluetech/parametrize-argvalues-typingUpdates
pytest-rerunfailuresfrom 16.2 to 16.7Changelog
Sourced from pytest-rerunfailures's changelog.
... (truncated)
Commits
fead4c6Preparing release 16.7ed62cfcShow each rerun attempt outcome in summary (#370)64687c9Add pytest.ini support for only_rerun (#369)1997015Preserve rerun status for teardown failures (#367)4220386Match only_rerun against wrapped exception causes (#364)87d81b2Keep nested pytester sessions isolated from pytest-randomly (#368)be14a6bAllow flaky conditions to inspect failure exceptions (#365)78561a5ci: test the free-threaded Python 3.14 build (#361)402afb4Fix bare exception class in only_rerun / rerun_except causing INTERNALERROR (...87a8b47Fix subtest reruns with structured NodeId keys (#363)Updates
litellmfrom 1.85.0 to 1.102.1Release notes
Sourced from litellm's releases.
... (truncated)
Commits
d09bbaeMerge pull request #42618 from BerriAI/litellm_backport_stable_1_102_x_realti...188c9d1Merge pull request #42595 from BerriAI/litellm_cherrypick_1_102_xd1cd2dcchore(backport): regenerate the openapi snapshot and dashboard api types for ...5aa45f1test(realtime): drop legacy InvalidStatusCode tests and pin websockets imports4bfac88fix(ui): adapt the jev dashboard pieces to stable/1.102.xda246e9chore(deps): bump anyio to 4.14.2 and soupsieve to 2.9.09a46f1fMerge pull request #41462 from BerriAI/litellm_otel_promote_nested_request_me...96e7739fix(realtime): surface an upstream handshake refusal as an error event and po...d068734feat(openrouter): price typesafe/jev-1.13 and add an openrouter decisions pas...e20cfbefeat(auto-router): add JEV classifier alongside LLM classifierUpdates
python-dotenvfrom 1.2.2 to 1.2.3Release notes
Sourced from python-dotenv's releases.
Changelog
Sourced from python-dotenv's changelog.
Commits
49515afBump version: 1.2.2 → 1.2.38ac846fchore: add release runbook (RELEASING.md) and make release targetbb31c94docs: add 1.2.3 release notes (#606, #638, #680)f7b18d9fix: round-trip backslashes through set_key (#680)751f8c1ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...f1937b6chore(deps): update mkdocs-include-markdown-plugin requirement from >=6.0.0 t...45b9372chore(deps): update pytest requirement from >=3.9 to >=9.0.3 (#653)72896e9docs: fix broken mkdocs link in CONTRIBUTING.md (#636)72754a1ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...078325eci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...Updates
pydanticfrom 2.13.4 to 2.13.5Release notes
Sourced from pydantic's releases.
Changelog
Sourced from pydantic's changelog.
Commits
001dea0Bumppypa/gh-action-pypi-publishaction to v1.14.2558379fBump twine to v7.0.02cfd5d3Do not check for docs builda735beeFix more Clippy lints7eed4a1Fix Clippy 0.1.95 warningsb353bbbPrepare release v2.13.563d2cccCount validated model fields once in smart unionsa53ec2eSpeed up PyPy CI testsd65e0f9Workaround circular import error in Mypy47a6dbfFix missing GC traversal inpydantic-coreforGeneralFieldsSerializerUpdates
joblibfrom 1.5.3 to 1.6.0Changelog
Sourced from joblib's changelog.
... (truncated)
Commits
cd9a6b0Release 1.6.0 (#1844)d873f97MNT vendor loky 3.6.0 (#1843)4ff61afBump the github-actions group with 4 updates (#1832)804f472FIX make func_code stable across processes when the source is unavailable (#1...65cc49dTST Restore RNG sequence in hash compatibility test (#1837)c1b6541CI Use pytest-run-parallel on free-threaded build (#1819)f6b80d3MNT Simplify isinstance check in hashing (#1835)fa4d5afMNT remove python 3.9 from CI (#1773)53cea7bDOC Update release docs to reflect usage of trusted publishing (#1826)26500e9Bump the github-actions group across 1 directory with 3 updates (#1790)Updates
pytest-asynciofrom 1.3.0 to 1.4.0Release notes
Sourced from pytest-asyncio's releases.
... (truncated)
Commits
6e14cd2chore: Prepare release of v1.4.0.4b900fbBuild(deps): Bump codecov/codecov-action from 6.0.0 to 6.0.1ab9f632Build(deps): Bump zipp from 3.23.1 to 4.1.0a56fc77Build(deps): Bump hypothesis from 6.152.6 to 6.152.8e8bae9bBuild(deps): Bump requests from 2.34.0 to 2.34.2fc43340Build(deps): Bump idna from 3.14 to 3.15762eaf5Build(deps): Bump jaraco-functools from 4.4.0 to 4.5.0b62e222Build(deps): Bump click from 8.3.3 to 8.4.09190447Build(deps): Bump pydantic from 2.13.3 to 2.13.482a393cci: Remove unnecessary debug output.Updates
pydantic-settingsfrom 2.14.2 to 2.15.0Release notes
Sourced from pydantic-settings's releases.
... (truncated)
Commits
f725ca1Prepare release 2.15.0 (#930)28f35c2Bump the python-packages group with 4 updates (#929)9056db0test: move function-local imports to the top of test modules (#927)f077e3afix: raise ValidationError for non-JSON env values on strict fields (#926)ae25d70fix: treat Secret subclasses as non-complex fields (#716) (#920)798dceaBump the python-packages group with 4 updates (#924)a190041Bump the github-actions group with 4 updates (#925)5d93332Bump the python-packages group with 4 updates (#921)d2fdedafix: read secret files as UTF-8 instead of the locale encoding (#917)2256a4eBump the python-packages group with 3 updates (#915)Updates
langwatchfrom 1.0.0 to 1.4.0Changelog
Sourced from langwatch's changelog.
... (truncated)
Commits
1108004chore: release main (#746)5bfabd3fix: azure ad extra required permission and env var names (#764)f13366efeat: delete dataset confirmation (#762)da736e0fix: dataset routes (#756)21376dcchore: temp disable e2e tests for typescript sdk (#758)bfd79bbfix: integration tests for typescript sdk (#757)5a003dftest: python ci tests93c9805ci: fix release please version python file update697792cchore: bump typescript sdk to v0.7.4 (#755)87c1f1ffix: register NodeTracerProvider globally when ProxyTracerProvider detected (...Updates
twiliofrom 9.10.9 to 9.11.1Release notes
Sourced from twilio's releases.