chore(deps): weekly dependency update - #21
github-actions[bot] wants to merge 1 commit into
Conversation
Reviewer's GuideAutomated weekly dependency refresh updates the matrix’s latest pins across provider SDKs, agent integrations, and test tooling, then regenerates the lockfile; reviewers should verify lockfile resolution and require cassette re-recording before merge. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 1 issue
Fixed security issues:
- anyio (link)
- cryptography (link)
- gitpython (link)
- mcp (link)
- pyjwt (link)
- python-multipart (link)
- starlette (link)
- urllib3 (link)
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="py/pyproject.toml" line_range="287" />
<code_context>
[tool.braintrust.matrix.openai]
-latest = "openai==2.33.0"
+latest = "openai==3.16.2"
"1.92.0" = "openai==1.92.0"
"1.77.0" = "openai==1.77.0"
</code_context>
<issue_to_address>
**issue (broader_impact):** The provider matrix now installs new SDK versions for the `latest` nox sessions, but this PR does not update the corresponding cassette recordings. CI configures VCR with `record_mode = "none"` under CI/GitHub Actions, so the latest-version integration tests fail when the new SDK requests do not match the existing recordings.
**Triggers:** When CI runs any provider integration session against the updated `latest` pin.
**Suggested fix:** Re-record and commit the `cassettes/latest` fixtures for each changed provider, or keep the old pins until the recordings are updated.
</issue_to_address>|
|
||
| [tool.braintrust.matrix.openai] | ||
| latest = "openai==2.33.0" | ||
| latest = "openai==3.16.2" |
There was a problem hiding this comment.
issue (broader_impact): The provider matrix now installs new SDK versions for the latest nox sessions, but this PR does not update the corresponding cassette recordings. CI configures VCR with record_mode = "none" under CI/GitHub Actions, so the latest-version integration tests fail when the new SDK requests do not match the existing recordings.
Triggers: When CI runs any provider integration session against the updated latest pin.
Suggested fix: Re-record and commit the cassettes/latest fixtures for each changed provider, or keep the old pins until the recordings are updated.
|
Superseded by a newer automated dependency update. |
Automated weekly dependency update via
python scripts/update-matrix-latest.py && uv lock --upgrade.Summary by Sourcery
Refresh the Python dependency matrix and lockfile to the latest supported package versions.
Enhancements:
Build:
Tests: