chore(deps): aggregate envs Dependabot updates - #1173
Conversation
Rebase the 2026-09-15 envs lockfile rollup onto current main so remaining security bumps stay easy to merge after the 9 commits that landed overnight. Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
This reverts commit 4a1fa2a.
This reverts commit 4a1fa2a.
There was a problem hiding this comment.
Alignment Review Report
Scope: uv.lock files only across 17 environments — no .py, pyproject.toml, .md, or other source changes. Base commit == current origin/main (34825a77), so the three-dot diff is the exact net change (no already-on-main no-ops). This is the aggregate roll-up channel, the intended path for env dependency bumps.
Automated Checks
- Lint: PASS. The repo's CI
lintjob is green. The local.claude/hooks/lint.shexits 1, but only on pre-existing formatting drift in ~56 unrelated.py/README files (the hook'sruff format --check … envs/is stricter than CI, which scopes tosrc/ tests/) plus the two AGENTS.md-documentedusortfiles (tests/envs/test_grid_world.py,test_julia_env.py). Zero overlap with this PR's diff, and lockfiles aren't linted at all. - Debug code: CLEAN (for this PR).
check-debug.shscanssrc/only; this PR changes no.py, so its findings are all pre-existing and unrelated. - Lock validity: PASS. CI
validate-env-locksis green (all 17 locks resolve--frozenagainst theirpyproject.toml);test (3.11/3.12)and package smoke-test also pass. - Supply-chain integrity: CLEAN. Every added
source =resolves tohttps://pypi.org/simple; every added artifact URL tofiles.pythonhosted.orgwith asha256. No git/local/alt-registry sources, no downgrades, no removed packages. All new hashes match values verified against live PyPI in prior reviews.
What changed (all transitive, all security-positive maintenance bumps)
- cryptography → 50.0.0 (13 envs; from 46/47/48/49) — via fastmcp→authlib. 50.0.0 is the minimum release clearing CVE-2026-69247 (fixed_in 50.0.0 only), so the major jump is justified.
- aiohttp → 3.14.3 (5 envs) — clears the 3.14.x CVE cluster (zip-bomb DoS, etc.; + CookieJar RCE for the qed_math 3.13.3 start).
- pillow → 12.3.0 (websearch_env) — clears the 12.3.0 advisory cluster (incl. CVE-2026-55798).
- nltk → 3.10.0 (openapp_env) + new transitive defusedxml 0.7.1 (nltk 3.10 runtime dep; hardened XML parser).
- pyjwt → 2.13.0 (tbench2_env) — security release; no direct pyjwt usage in the repo.
- h2 → 4.4.1 + hpack → 4.2.0 (coding_tools_env) — clears CVE-2026-71554 (HTTP/2 request smuggling).
Open RFCs Context
Present RFCs: 000/001/002/003/005/008/012 (In Review), 010/011 (Draft), 004 (no status header). None governs dependency pinning / package indexes → no RFC surface is touched by a lockfile bump.
Tier 1: Fixes Required
- None. No issues attributable to this PR (CI fully green incl. lint + lock validation + tests; hashes verified; sources all PyPI). The local lint/debug hook findings are pre-existing and live in files this PR does not touch.
Tier 2: Alignment Discussion
Principle Conflicts
- None identified. No interfaces, imports, reward logic, MCP/WebSocket boundaries, or abstractions change — pure lockfile bump.
RFC Conflicts
- None identified.
Non-blocking reproducibility note (recurring)
ALIGNMENT FLAG: 7 envs' locks flip declared index HF-mirror → public PyPI, plus revision 2→3
- Principle at stake: "Container isolation for reproducibility" (PRINCIPLES.md) — declared dependency provenance
- The concern: In
chat_env,coding_tools_env,opencode_env,pelican_svg_env,pi_env,sophistry_bench_sprint_env,websearch_env, this re-lock rewritessource = registry pypi.registries.huggingface.tech→pypi.org/simple(129–184 refs each) and bumpsrevision 2→3. Artifact URLs/hashes are unchanged apart from the intended bumps, so it's functionally benign, but it changes declared provenance and reverses deliberate prior choices (e.g. coding_tools_env was pointed at the HF mirror in #882). Registry choice is a team decision — flagging, not fixing. The other 10 envs are "born clean" (already on PyPI + rev 3). (finrl_env additionally shows benigngreenlets390x-wheel/marker churn from the re-lock — no artifact/hash change.) - Suggested reviewer: @Darktex (reproducibility principle) + @burtenshaw (
.github/dependabot.yml/ aggregate roll-up owner); @sergiopaniego for coding_tools_env's mirror decision (#882)
Process note (not a flag): because this is the aggregate roll-up (native per-env dependabot/uv/envs/* PRs bypass the exclude-paths: [envs/**] config), there's no exclude-paths concern here.
Summary
- 0 mechanical issues to fix (CI fully green; lint/debug findings are pre-existing & unrelated)
- 1 non-blocking alignment note for human awareness (index-flip + revision on 7 envs — provenance/reproducibility)
- 0 RFC conflicts
Net: a clean, security-positive dependency roll-up. No code changes made (review-only); the dependabot-generated locks should not be hand-edited.
Sent by Cursor Automation: Pre-review
| @@ -1,5 +1,5 @@ | |||
| version = 1 | |||
| revision = 2 | |||
| revision = 3 | |||
There was a problem hiding this comment.
Index-flip + revision bump (non-blocking, provenance). This env — and 6 others (coding_tools_env, opencode_env, pelican_svg_env, pi_env, sophistry_bench_sprint_env, websearch_env) — has its declared index rewritten from the HF mirror (pypi.registries.huggingface.tech) to public PyPI (pypi.org/simple, ~132 refs here; first at line 20) and revision bumped 2→3. Artifact URLs/hashes are otherwise unchanged, so it's functionally benign, but it changes declared provenance and reverses deliberate prior choices (e.g. coding_tools_env was set to the HF mirror in #882). Registry choice is a team decision — flagging, not fixing. cc @Darktex (reproducibility) / @burtenshaw (dependabot config).
| @@ -587,68 +587,65 @@ toml = [ | |||
|
|
|||
| [[package]] | |||
| name = "cryptography" | |||
| version = "46.0.7" | |||
| source = { registry = "https://pypi.registries.huggingface.tech/" } | |||
| version = "50.0.0" | |||
There was a problem hiding this comment.
cryptography → 50.0.0 (13 envs in this roll-up). Transitive (openenv→fastmcp→authlib→cryptography), so lock-only is correct. The 46/47/48/49→50 major jump is security-justified: 50.0.0 is the minimum release clearing CVE-2026-69247 (GHSA-g6cj-pr64-35w5), which is fixed_in 50.0.0 only. requires-python is satisfied by every env (≥3.10) and the hash matches PyPI. No concern.
| name = "h2" | ||
| version = "4.3.0" | ||
| source = { registry = "https://pypi.registries.huggingface.tech/" } | ||
| version = "4.4.1" |
There was a problem hiding this comment.
h2 → 4.4.1 (with transitive hpack → 4.2.0). Fixes CVE-2026-71554 (HTTP/2 request smuggling via multiple Host headers on an H2→1.1 downgrade; fixed in 4.4.1). Transitive (via httpx[http2]/fastmcp), so lock-only is correct; both hashes match PyPI.
|
|
||
| [[package]] | ||
| name = "defusedxml" | ||
| version = "0.7.1" |
There was a problem hiding this comment.
New transitive dep defusedxml 0.7.1 — pulled in because nltk 3.10.0 added it to its runtime requires (a hardened XML parser: XXE / billion-laughs). Zero deps, security-positive, hash matches PyPI. This is an expected side effect of the nltk 3.9.4→3.10.0 bump, not a concern.
| { url = "https://files.pythonhosted.org/packages/c3/28/ec0fc38107fc32536908034e990c47914c57cd7c5a3ece4d8d8f7ffd7e27/pillow-12.2.0-pp311-pypy311_pp73-manylinux_2_27_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:4a6c9fa44005fa37a91ebfc95d081e8079757d2e904b27103f4f5fa6f0bf78c0", size = 5355404, upload-time = "2026-04-01T14:46:06.33Z" }, | ||
| { url = "https://files.pythonhosted.org/packages/5e/8b/51b0eddcfa2180d60e41f06bd6d0a62202b20b59c68f5a132e615b75aecf/pillow-12.2.0-pp311-pypy311_pp73-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:25373b66e0dd5905ed63fa3cae13c82fbddf3079f2c8bf15c6fb6a35586324c1", size = 6002215, upload-time = "2026-04-01T14:46:08.83Z" }, | ||
| { url = "https://files.pythonhosted.org/packages/bc/60/5382c03e1970de634027cee8e1b7d39776b778b81812aaf45b694dfe9e28/pillow-12.2.0-pp311-pypy311_pp73-win_amd64.whl", hash = "sha256:bfa9c230d2fe991bed5318a5f119bd6780cda2915cca595393649fc118ab895e", size = 7080946, upload-time = "2026-04-01T14:46:11.734Z" }, | ||
| version = "12.3.0" |
There was a problem hiding this comment.
pillow → 12.3.0 (transitive via gradio). Clears the growing 12.2.0 advisory cluster (all fixed_in 12.3.0), including CVE-2026-55798. requires-python ≥3.10 is satisfied and the hash matches PyPI. Note this env is also one of the 7 carrying the index-flip + rev-3 side effect flagged above.
This reverts commit de6e1d0.
This reverts commit 9abb06c.


Summary
Rebases the 2026-09-15 envs Dependabot rollup (#1160) onto current
mainso remaining lockfile security bumps stay easy to merge after the 9 commits that landed overnight (#1138,#1161–#1167,#1171).No new individual Dependabot PRs opened overnight (weekly
dependabot.ymlcovers root uv excludingenvs/**, plus GitHub Actions). This PR only carries unpublishedenvs/**/uv.lockupdates from #1160 / #1152 / #1146 / #1015.Included (still not on main):
Left untouched so we do not regress main:
envs/coding_env(tornado 6.5.8 + Hugging Face registry already on main)envs/textarena_env(nltk>=3.10.3already on main)envs/repl_env(pypdf>=6.16.1already on main)This supersedes #1160, #1152, #1146, and #1015.
Core Dependabot status (no second mergeable PR today):
envs/.cf20b09) already match latesthuggingface/doc-buildermain. chore(deps): aggregate non-env dependabot updates #1109 would downgrade to1b16dac.#1119, pin>=3.0.0,<5.0.0) remains blocked: HTTP and WebSocketinc_counterpersistence still fail. Do not re-open until those tests pass.Type of Change
Alignment Checklist
Before submitting, verify:
.claude/docs/PRINCIPLES.mdand this PR aligns with our principles.claude/docs/INVARIANTS.mdand no invariants are violated (envs lockfiles only; no agent-facing reset/API changes)uv lock --checkpassed in every updated envRFC Status
Test Plan
git diff --check origin/main...HEADenvs/**/uv.lockonly (17 files)uv lock --checkin each updated environment: passsrc/or rootpyproject.tomlchangesorigin/mainClaude Code Review
N/A — Dependabot lockfile rollup.
This automation cannot close PRs (GitHub token returns 403). Please close these superseded aggregates:
There were no open individual Dependabot PRs to close today.
Note
Medium Risk
Lockfile-only, but cryptography 50 is a large jump on a security-sensitive transitive dependency across many envs; validate installs and env smoke tests after merge.
Overview
This PR rebases and lands pending
uv.locksecurity bumps across multipleenvs/**environments—nopyproject.tomlor application code changes.The largest shared update is
cryptography→ 50.0.0 in many env lockfiles (replacing various 46.x/48.x pins). Several envs also pick upaiohttp→ 3.14.3, plus smaller bumps called out in the branch (e.g. h2/hpack, nltk, PyJWT, Pillow) where those envs depend on them.Alongside version pins, the diff includes uv resolver metadata churn (simpler dependency markers on packages like pandas, scikit-learn, scipy, and secretstorage) from re-running the lock, not intentional API changes.
Reviewed by Cursor Bugbot for commit 359dd07. Bugbot is set up for automated code reviews on this repo. Configure here.