Skip to content

chore(deps): lock file maintenance - #1851

Merged
mldangelo-oai merged 3 commits into
mainfrom
renovate/lock-file-maintenance
Sep 29, 2026
Merged

mldangelo-oai merged 3 commits into
mainfrom
renovate/lock-file-maintenance

Conversation

@renovate

@renovate renovate Bot commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 6am on Sunday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

CI repair and current-main integration

Retain the compatible tooling repair from #1858: Mypy below 2.0 and Ruff below 0.16, locked at Mypy 1.20.0 / Ruff 0.15.10, with the matching standalone Mypy bound and pytest. Preserve the Renovate dependency refresh, including AnyIO 4.15.1 and GitPython 3.1.62.

Integrate main e635b8ac additively, carrying its GitPython regression floor of 3.1.60 and security changelog entry. The lock file is byte-identical to the previously reviewed PR head fa5c8189.

Validation:

  • Formatting, Ruff, Mypy (480 files), and 177 dependency/workflow guards pass. The prior tooling repair has three regression cases that failed before the repair and passed afterward.
  • The required local fast suite reached 15,450 passed / 927 skipped before an unchanged CLI test attempted to stage under the sandbox's read-only shared cache (errno 30), before its mocked download. The exact node also fails on isolated current main; all original assertions pass on both snapshots using the supported --cache-dir option with a unique temporary directory. This is a local host limitation, not a completed green broad run.
  • The unchanged lock previously passed Python 3.12/3.13 dependency audits and the full optional-dependency CI matrix at fa5c8189. Fresh CI and repository Codex review are requested for the integrated head. Complete optional-dependency validation runs in CI because the refreshed Torch/CUDA environment exceeds local free space.
  • Local lock checking has the previously recorded internal-registry mismatch. The committed registry remains unchanged; the exact-head GitHub Lock File Consistency check is required before merge.

Native review advisory: three independent reviews and a fresh verifier retained one P3 issue: non-verbose Hugging Face scans can emit httpx2 metadata-request INFO logs to stderr because suppression still names httpx/httpcore. The verified reproduction retained exit status 0 and valid JSON stdout, with no concrete credential or signed-URL disclosure established. This remains a visible nonblocking advisory; this integration does not change logging.

@github-actions

github-actions Bot commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

Workflow run and artifacts

Performance Benchmarks

Compared 13 shared benchmarks with a regression threshold of 15%.
Status: 0 regressions, 0 improved, 13 stable, 0 new, 0 missing.
Aggregate shared-benchmark median: 4.314s -> 4.339s (+0.6%).

Workload Benchmark Target Size Files Baseline Current Change Status
mixed-model-repository tests/benchmarks/test_scan_benchmarks.py::test_scan_release_candidate_repository release-candidate 547.3 KiB 32 686.23ms 664.26ms -3.2% stable
direct-malicious-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_direct_malicious_upload malicious_reduce 52 B 1 229.3us 224.1us -2.3% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_base64] nested_base64 98 B 1 302.9us 296.1us -2.2% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_raw] nested_raw 78 B 1 281.9us 276.6us -1.9% stable
warm-cache-rescan tests/benchmarks/test_scan_benchmarks.py::test_scan_warm_cached_repository_rescan release-candidate 547.3 KiB 32 155.87ms 158.64ms +1.8% stable
rejected-basic-auth-candidates tests/benchmarks/test_scan_benchmarks.py::test_rejected_basic_auth_candidates_scan_linearly - 371.1 KiB 1 2.435s 2.472s +1.5% stable
duplicate-heavy-registry tests/benchmarks/test_scan_benchmarks.py::test_scan_duplicate_registry_snapshot registry-snapshot 915.2 KiB 13 580.00ms 586.73ms +1.2% stable
padded-multi-stream-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_padded_multi_stream_upload multi_stream_padded 4.1 KiB 1 340.9us 343.7us +0.8% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_hex] nested_hex 130 B 1 311.6us 309.2us -0.8% stable
clean-training-checkpoint tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_clean_training_checkpoint safe_large 278.2 KiB 1 109.57ms 109.99ms +0.4% stable
chunked-upload-stream tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_chunked_upload_stream chunked_stream 278.2 KiB 1 113.52ms 113.22ms -0.3% stable
single-checkpoint-preflight tests/benchmarks/test_scan_benchmarks.py::test_scan_single_checkpoint_before_load single_checkpoint.pkl 183.0 KiB 1 105.92ms 106.15ms +0.2% stable
suspicious-pickle-intake tests/benchmarks/test_scan_benchmarks.py::test_scan_suspicious_pickle_intake suspicious-intake 183.8 KiB 4 126.11ms 126.37ms +0.2% stable

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from cc6b7bd to f0650d5 Compare September 16, 2026 09:59
Port the supported Mypy and Ruff bounds and standalone Mypy validation
from PR #1858 (d324555 and 966a5fa). Restore their known-compatible
locked versions so standalone Ruff remains aligned with the root tool.

Keep Renovate's runtime dependency refresh, including its audited
AnyIO and GitPython updates. Remove the now-unused ast-serialize lock
entry from the Mypy 2.x dependency graph.
@mldangelo-oai

Copy link
Copy Markdown
Contributor

@codex review

Please review the current head fa5c8189c5cdbadd5d3a60be29ad0d88156cac87, including the CI tooling compatibility repair carried over from #1858.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T18:10:28.818172Z 5071b9e Manual request
🔒 Security Review ✅ Completed 2026-09-29T18:10:58.743636Z 5071b9e Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@renovate

renovate Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep them coming!

Reviewed commit: fa5c8189c5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: fa5c8189c5

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@codecov-commenter

codecov-commenter commented Sep 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 76.54%. Comparing base (e635b8a) to head (5071b9e).

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #1851      +/-   ##
==========================================
- Coverage   76.54%   76.54%   -0.01%     
==========================================
  Files         218      218              
  Lines      119909   119909              
  Branches    28392    28392              
==========================================
- Hits        91789    91785       -4     
- Misses      20430    20432       +2     
- Partials     7690     7692       +2     

see 3 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@mldangelo-oai

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5071b9ef2d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread uv.lock
{ name = "filelock" },
{ name = "fsspec" },
{ name = "hf-xet", marker = "platform_machine == 'AMD64' or platform_machine == 'aarch64' or platform_machine == 'amd64' or platform_machine == 'arm64' or platform_machine == 'x86_64'" },
{ name = "httpx" },
{ name = "httpx2" },

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3 Badge Suppress the renamed HTTP client loggers

When this lock is used for a non-verbose Hugging Face scan, huggingface-hub 2.0 delegates metadata requests to httpx2/httpcore2, but _configure_scan_logging() in modelaudit/cli.py still raises only the httpx and httpcore loggers to WARNING. Because the CLI configures the root logger at INFO, these request records leak to stderr during otherwise quiet scans, including JSON-output invocations; add the renamed logger names to the suppression list or retain the previous client until they are handled.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed by the independent native verifier on this head: the renamed HTTP client emits INFO request records to stderr during a non-verbose Hugging Face scan. The tested CLI reproduction exited 0 with valid JSON on stdout; no concrete credential disclosure was established on the tested paths. This remains an accepted nonblocking P3 advisory for this dependency upgrade and is not fixed here. Leaving this thread open so the logger cleanup remains visible.

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 5071b9ef2d

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@mldangelo-oai mldangelo-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the dependency lock maintenance and compatibility repairs at 5071b9e, including additive integration of current main e635b8a. All eight current-head workflows passed: 59 successful checks and one expected skip. Three native reviews plus independent verification completed; current-head Codex code and security reviews also completed. The confirmed P3 httpx2 logger issue remains explicitly accepted as a nonblocking advisory, unfixed and visible in its open thread: tested output retained valid JSON and exit status, with no concrete credential disclosure established. No blocking finding remains for this dependency upgrade.

@mldangelo-oai
mldangelo-oai merged commit ac5240a into main Sep 29, 2026
60 checks passed
@mldangelo-oai
mldangelo-oai deleted the renovate/lock-file-maintenance branch September 29, 2026 18:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants