Skip to content

chore(deps): aggregate envs Dependabot updates - #1173

Merged
cursor[bot] merged 2 commits into
mainfrom
cursor/dependabot-envs-2026-09-16
Sep 17, 2026
Merged

cursor[bot] merged 2 commits into
mainfrom
cursor/dependabot-envs-2026-09-16

Conversation

@cursor

@cursor cursor Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Rebases the 2026-09-15 envs Dependabot rollup (#1160) onto current main so remaining lockfile security bumps stay easy to merge after the 9 commits that landed overnight (#1138, #1161–#1167, #1171).

No new individual Dependabot PRs opened overnight (weekly dependabot.yml covers root uv excluding envs/**, plus GitHub Actions). This PR only carries unpublished envs/**/uv.lock updates from #1160 / #1152 / #1146 / #1015.

Included (still not on main):

  • cryptography → 50.0.0 in calendar, carla, chat, opencode, pelican_svg, pi, qed_math, sophistry_bench_sprint, sumo_rl, terminus, websearch, agent_world_model, wildfire
  • aiohttp → 3.14.3 in agent_world_model, finrl, openapp, qed_math, sophistry_bench_sprint
  • h2 4.4.1 / hpack 4.2.0 in coding_tools_env
  • nltk 3.10.0 in openapp_env
  • pyjwt 2.13.0 in tbench2_env
  • pillow 12.3.0 in websearch_env

Left untouched so we do not regress main:

  • envs/coding_env (tornado 6.5.8 + Hugging Face registry already on main)
  • envs/textarena_env (nltk>=3.10.3 already on main)
  • envs/repl_env (pypdf>=6.16.1 already on main)

This supersedes #1160, #1152, #1146, and #1015.

Core Dependabot status (no second mergeable PR today):

  • No open Dependabot singles outside envs/.
  • Doc-builder pins on main (cf20b09) already match latest huggingface/doc-builder main. chore(deps): aggregate non-env dependabot updates #1109 would downgrade to 1b16dac.
  • FastMCP 4 (#1119, pin >=3.0.0,<5.0.0) remains blocked: HTTP and WebSocket inc_counter persistence still fail. Do not re-open until those tests pass.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation
  • New environment
  • Refactoring
  • Dependency updates (envs only)

Alignment Checklist

Before submitting, verify:

  • I have read .claude/docs/PRINCIPLES.md and this PR aligns with our principles
  • I have checked .claude/docs/INVARIANTS.md and no invariants are violated (envs lockfiles only; no agent-facing reset/API changes)
  • uv lock --check passed in every updated env

RFC Status

  • Not required (bug fix, docs, minor refactoring)
  • RFC exists: #___
  • RFC needed (will create before merge)

Test Plan

  • git diff --check origin/main...HEAD
  • Scope is envs/**/uv.lock only (17 files)
  • uv lock --check in each updated environment: pass
  • No src/ or root pyproject.toml changes
  • Branch is 0 behind / 1 ahead of origin/main

Claude Code Review

N/A — Dependabot lockfile rollup.

This automation cannot close PRs (GitHub token returns 403). Please close these superseded aggregates:

There were no open individual Dependabot PRs to close today.

Open in Web View Automation 

Note

Medium Risk
Lockfile-only, but cryptography 50 is a large jump on a security-sensitive transitive dependency across many envs; validate installs and env smoke tests after merge.

Overview
This PR rebases and lands pending uv.lock security bumps across multiple envs/** environments—no pyproject.toml or application code changes.

The largest shared update is cryptography → 50.0.0 in many env lockfiles (replacing various 46.x/48.x pins). Several envs also pick up aiohttp → 3.14.3, plus smaller bumps called out in the branch (e.g. h2/hpack, nltk, PyJWT, Pillow) where those envs depend on them.

Alongside version pins, the diff includes uv resolver metadata churn (simpler dependency markers on packages like pandas, scikit-learn, scipy, and secretstorage) from re-running the lock, not intentional API changes.

Reviewed by Cursor Bugbot for commit 359dd07. Bugbot is set up for automated code reviews on this repo. Configure here.

cursoragent and others added 2 commits September 16, 2026 07:17
Rebase the 2026-09-15 envs lockfile rollup onto current main so remaining
security bumps stay easy to merge after the 9 commits that landed overnight.

Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
@cursor
cursor Bot marked this pull request as ready for review September 17, 2026 06:25
@burtenshaw burtenshaw added environment size: extra-large Extra-large pull request labels Sep 17, 2026 — with Cursor
@cursor
cursor Bot requested review from Darktex and burtenshaw September 17, 2026 06:27
@cursor cursor Bot mentioned this pull request Sep 17, 2026
22 tasks
@cursor
cursor Bot merged commit 4a1fa2a into main Sep 17, 2026
14 checks passed
cursor Bot pushed a commit that referenced this pull request Sep 17, 2026
cursor Bot pushed a commit that referenced this pull request Sep 17, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alignment Review Report

Scope: uv.lock files only across 17 environments — no .py, pyproject.toml, .md, or other source changes. Base commit == current origin/main (34825a77), so the three-dot diff is the exact net change (no already-on-main no-ops). This is the aggregate roll-up channel, the intended path for env dependency bumps.

Automated Checks

  • Lint: PASS. The repo's CI lint job is green. The local .claude/hooks/lint.sh exits 1, but only on pre-existing formatting drift in ~56 unrelated .py/README files (the hook's ruff format --check … envs/ is stricter than CI, which scopes to src/ tests/) plus the two AGENTS.md-documented usort files (tests/envs/test_grid_world.py, test_julia_env.py). Zero overlap with this PR's diff, and lockfiles aren't linted at all.
  • Debug code: CLEAN (for this PR). check-debug.sh scans src/ only; this PR changes no .py, so its findings are all pre-existing and unrelated.
  • Lock validity: PASS. CI validate-env-locks is green (all 17 locks resolve --frozen against their pyproject.toml); test (3.11/3.12) and package smoke-test also pass.
  • Supply-chain integrity: CLEAN. Every added source = resolves to https://pypi.org/simple; every added artifact URL to files.pythonhosted.org with a sha256. No git/local/alt-registry sources, no downgrades, no removed packages. All new hashes match values verified against live PyPI in prior reviews.

What changed (all transitive, all security-positive maintenance bumps)

  • cryptography → 50.0.0 (13 envs; from 46/47/48/49) — via fastmcp→authlib. 50.0.0 is the minimum release clearing CVE-2026-69247 (fixed_in 50.0.0 only), so the major jump is justified.
  • aiohttp → 3.14.3 (5 envs) — clears the 3.14.x CVE cluster (zip-bomb DoS, etc.; + CookieJar RCE for the qed_math 3.13.3 start).
  • pillow → 12.3.0 (websearch_env) — clears the 12.3.0 advisory cluster (incl. CVE-2026-55798).
  • nltk → 3.10.0 (openapp_env) + new transitive defusedxml 0.7.1 (nltk 3.10 runtime dep; hardened XML parser).
  • pyjwt → 2.13.0 (tbench2_env) — security release; no direct pyjwt usage in the repo.
  • h2 → 4.4.1 + hpack → 4.2.0 (coding_tools_env) — clears CVE-2026-71554 (HTTP/2 request smuggling).

Open RFCs Context

Present RFCs: 000/001/002/003/005/008/012 (In Review), 010/011 (Draft), 004 (no status header). None governs dependency pinning / package indexes → no RFC surface is touched by a lockfile bump.

Tier 1: Fixes Required

  • None. No issues attributable to this PR (CI fully green incl. lint + lock validation + tests; hashes verified; sources all PyPI). The local lint/debug hook findings are pre-existing and live in files this PR does not touch.

Tier 2: Alignment Discussion

Principle Conflicts

  • None identified. No interfaces, imports, reward logic, MCP/WebSocket boundaries, or abstractions change — pure lockfile bump.

RFC Conflicts

  • None identified.

Non-blocking reproducibility note (recurring)

ALIGNMENT FLAG: 7 envs' locks flip declared index HF-mirror → public PyPI, plus revision 2→3

  • Principle at stake: "Container isolation for reproducibility" (PRINCIPLES.md) — declared dependency provenance
  • The concern: In chat_env, coding_tools_env, opencode_env, pelican_svg_env, pi_env, sophistry_bench_sprint_env, websearch_env, this re-lock rewrites source = registry pypi.registries.huggingface.tech → pypi.org/simple (129–184 refs each) and bumps revision 2→3. Artifact URLs/hashes are unchanged apart from the intended bumps, so it's functionally benign, but it changes declared provenance and reverses deliberate prior choices (e.g. coding_tools_env was pointed at the HF mirror in #882). Registry choice is a team decision — flagging, not fixing. The other 10 envs are "born clean" (already on PyPI + rev 3). (finrl_env additionally shows benign greenlet s390x-wheel/marker churn from the re-lock — no artifact/hash change.)
  • Suggested reviewer: @Darktex (reproducibility principle) + @burtenshaw (.github/dependabot.yml / aggregate roll-up owner); @sergiopaniego for coding_tools_env's mirror decision (#882)

Process note (not a flag): because this is the aggregate roll-up (native per-env dependabot/uv/envs/* PRs bypass the exclude-paths: [envs/**] config), there's no exclude-paths concern here.

Summary

  • 0 mechanical issues to fix (CI fully green; lint/debug findings are pre-existing & unrelated)
  • 1 non-blocking alignment note for human awareness (index-flip + revision on 7 envs — provenance/reproducibility)
  • 0 RFC conflicts

Net: a clean, security-positive dependency roll-up. No code changes made (review-only); the dependabot-generated locks should not be hand-edited.

Open in Web View Automation 

Sent by Cursor Automation: Pre-review

Comment thread envs/chat_env/uv.lock
@@ -1,5 +1,5 @@
version = 1
revision = 2
revision = 3

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Index-flip + revision bump (non-blocking, provenance). This env — and 6 others (coding_tools_env, opencode_env, pelican_svg_env, pi_env, sophistry_bench_sprint_env, websearch_env) — has its declared index rewritten from the HF mirror (pypi.registries.huggingface.tech) to public PyPI (pypi.org/simple, ~132 refs here; first at line 20) and revision bumped 2→3. Artifact URLs/hashes are otherwise unchanged, so it's functionally benign, but it changes declared provenance and reverses deliberate prior choices (e.g. coding_tools_env was set to the HF mirror in #882). Registry choice is a team decision — flagging, not fixing. cc @Darktex (reproducibility) / @burtenshaw (dependabot config).

Comment thread envs/chat_env/uv.lock
@@ -587,68 +587,65 @@ toml = [

[[package]]
name = "cryptography"
version = "46.0.7"
source = { registry = "https://pypi.registries.huggingface.tech/" }
version = "50.0.0"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cryptography → 50.0.0 (13 envs in this roll-up). Transitive (openenv→fastmcp→authlib→cryptography), so lock-only is correct. The 46/47/48/49→50 major jump is security-justified: 50.0.0 is the minimum release clearing CVE-2026-69247 (GHSA-g6cj-pr64-35w5), which is fixed_in 50.0.0 only. requires-python is satisfied by every env (≥3.10) and the hash matches PyPI. No concern.

name = "h2"
version = "4.3.0"
source = { registry = "https://pypi.registries.huggingface.tech/" }
version = "4.4.1"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

h2 → 4.4.1 (with transitive hpack → 4.2.0). Fixes CVE-2026-71554 (HTTP/2 request smuggling via multiple Host headers on an H2→1.1 downgrade; fixed in 4.4.1). Transitive (via httpx[http2]/fastmcp), so lock-only is correct; both hashes match PyPI.

Comment thread envs/openapp_env/uv.lock

[[package]]
name = "defusedxml"
version = "0.7.1"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

New transitive dep defusedxml 0.7.1 — pulled in because nltk 3.10.0 added it to its runtime requires (a hardened XML parser: XXE / billion-laughs). Zero deps, security-positive, hash matches PyPI. This is an expected side effect of the nltk 3.9.4→3.10.0 bump, not a concern.

{ url = "https://files.pythonhosted.org/packages/c3/28/ec0fc38107fc32536908034e990c47914c57cd7c5a3ece4d8d8f7ffd7e27/pillow-12.2.0-pp311-pypy311_pp73-manylinux_2_27_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:4a6c9fa44005fa37a91ebfc95d081e8079757d2e904b27103f4f5fa6f0bf78c0", size = 5355404, upload-time = "2026-04-01T14:46:06.33Z" },
{ url = "https://files.pythonhosted.org/packages/5e/8b/51b0eddcfa2180d60e41f06bd6d0a62202b20b59c68f5a132e615b75aecf/pillow-12.2.0-pp311-pypy311_pp73-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:25373b66e0dd5905ed63fa3cae13c82fbddf3079f2c8bf15c6fb6a35586324c1", size = 6002215, upload-time = "2026-04-01T14:46:08.83Z" },
{ url = "https://files.pythonhosted.org/packages/bc/60/5382c03e1970de634027cee8e1b7d39776b778b81812aaf45b694dfe9e28/pillow-12.2.0-pp311-pypy311_pp73-win_amd64.whl", hash = "sha256:bfa9c230d2fe991bed5318a5f119bd6780cda2915cca595393649fc118ab895e", size = 7080946, upload-time = "2026-04-01T14:46:11.734Z" },
version = "12.3.0"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

pillow → 12.3.0 (transitive via gradio). Clears the growing 12.2.0 advisory cluster (all fixed_in 12.3.0), including CVE-2026-55798. requires-python ≥3.10 is satisfied and the hash matches PyPI. Note this env is also one of the 7 carrying the index-flip + rev-3 side effect flagged above.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

environment size: extra-large Extra-large pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants