chore(deps): lock file maintenance - #1851
Conversation
Performance BenchmarksCompared
|
cc6b7bd to
f0650d5
Compare
f0650d5 to
bff418c
Compare
Port the supported Mypy and Ruff bounds and standalone Mypy validation from PR #1858 (d324555 and 966a5fa). Restore their known-compatible locked versions so standalone Ruff remains aligned with the root tool. Keep Renovate's runtime dependency refresh, including its audited AnyIO and GitPython updates. Remove the now-unused ast-serialize lock entry from the Mypy 2.x dependency graph.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
|
Codex Review: Didn't find any major issues. Keep them coming! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1851 +/- ##
==========================================
- Coverage 76.54% 76.54% -0.01%
==========================================
Files 218 218
Lines 119909 119909
Branches 28392 28392
==========================================
- Hits 91789 91785 -4
- Misses 20430 20432 +2
- Partials 7690 7692 +2 🚀 New features to boost your workflow:
|
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5071b9ef2d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| { name = "filelock" }, | ||
| { name = "fsspec" }, | ||
| { name = "hf-xet", marker = "platform_machine == 'AMD64' or platform_machine == 'aarch64' or platform_machine == 'amd64' or platform_machine == 'arm64' or platform_machine == 'x86_64'" }, | ||
| { name = "httpx" }, | ||
| { name = "httpx2" }, |
There was a problem hiding this comment.
Suppress the renamed HTTP client loggers
When this lock is used for a non-verbose Hugging Face scan, huggingface-hub 2.0 delegates metadata requests to httpx2/httpcore2, but _configure_scan_logging() in modelaudit/cli.py still raises only the httpx and httpcore loggers to WARNING. Because the CLI configures the root logger at INFO, these request records leak to stderr during otherwise quiet scans, including JSON-output invocations; add the renamed logger names to the suppression list or retain the previous client until they are handled.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Confirmed by the independent native verifier on this head: the renamed HTTP client emits INFO request records to stderr during a non-verbose Hugging Face scan. The tested CLI reproduction exited 0 with valid JSON on stdout; no concrete credential disclosure was established on the tested paths. This remains an accepted nonblocking P3 advisory for this dependency upgrade and is not fixed here. Leaving this thread open so the logger cleanup remains visible.
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
mldangelo-oai
left a comment
There was a problem hiding this comment.
Reviewed the dependency lock maintenance and compatibility repairs at 5071b9e, including additive integration of current main e635b8a. All eight current-head workflows passed: 59 successful checks and one expected skip. Three native reviews plus independent verification completed; current-head Codex code and security reviews also completed. The confirmed P3 httpx2 logger issue remains explicitly accepted as a nonblocking advisory, unfixed and visible in its open thread: tested output retained valid JSON and exit status, with no concrete credential disclosure established. No blocking finding remains for this dependency upgrade.
This PR contains the following updates:
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.
CI repair and current-main integration
Retain the compatible tooling repair from #1858: Mypy below 2.0 and Ruff below 0.16, locked at Mypy 1.20.0 / Ruff 0.15.10, with the matching standalone Mypy bound and pytest. Preserve the Renovate dependency refresh, including AnyIO 4.15.1 and GitPython 3.1.62.
Integrate main
e635b8acadditively, carrying its GitPython regression floor of 3.1.60 and security changelog entry. The lock file is byte-identical to the previously reviewed PR headfa5c8189.Validation:
--cache-diroption with a unique temporary directory. This is a local host limitation, not a completed green broad run.fa5c8189. Fresh CI and repository Codex review are requested for the integrated head. Complete optional-dependency validation runs in CI because the refreshed Torch/CUDA environment exceeds local free space.Native review advisory: three independent reviews and a fresh verifier retained one P3 issue: non-verbose Hugging Face scans can emit httpx2 metadata-request INFO logs to stderr because suppression still names httpx/httpcore. The verified reproduction retained exit status 0 and valid JSON stdout, with no concrete credential or signed-URL disclosure established. This remains a visible nonblocking advisory; this integration does not change logging.