Skip to content

test(deps): guard patched AnyIO lock versions - #1858

Merged
mldangelo merged 6 commits into
mainfrom
fix/tooling-version-bounds
Oct 3, 2026
Merged

mldangelo merged 6 commits into
mainfrom
fix/tooling-version-bounds

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Add AnyIO to the dependency lock regression test so future lock updates cannot select a release below the patched 4.14.2 floor.

Make the inherited cache interruption test deterministic across Windows identity retries and explicitly cover both initial and retried captures, preserving monitor-cleanup assertions.

Current main now supplies newer compatible Mypy/Ruff bounds and the matching standalone workflow, documentation, and regression updates. This branch integrates those changes and preserves main's AnyIO 4.15.1 and GitPython 3.1.62 lock entries; the remaining dependency change is the AnyIO guard.

Validation: 235 dependency/workflow tests and both cache interruption scenarios, repository-wide Ruff and Mypy (491 files), and lock consistency pass. An interrupted broad local run reported 2,913 passes and an unchanged one-second timing assertion failure under heavy shared-host load. The exact timing test subsequently passed on this branch and current main. Runtime sources are identical to current main.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T19:05:10.770411Z 1869454 New commits
🔒 Security Review ✅ Completed 2026-10-03T19:05:26.002757Z 1869454 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d324555009

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread pyproject.toml Outdated
@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Workflow run and artifacts

Performance Benchmarks

Compared 13 shared benchmarks with a regression threshold of 15%.
Status: 0 regressions, 0 improved, 13 stable, 0 new, 0 missing.
Aggregate shared-benchmark median: 4.289s -> 4.312s (+0.5%).

Workload Benchmark Target Size Files Baseline Current Change Status
direct-malicious-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_direct_malicious_upload malicious_reduce 52 B 1 230.0us 222.3us -3.4% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_raw] nested_raw 78 B 1 283.2us 275.3us -2.8% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_hex] nested_hex 130 B 1 306.9us 315.4us +2.8% stable
suspicious-pickle-intake tests/benchmarks/test_scan_benchmarks.py::test_scan_suspicious_pickle_intake suspicious-intake 183.8 KiB 4 125.30ms 123.13ms -1.7% stable
rejected-basic-auth-candidates tests/benchmarks/test_scan_benchmarks.py::test_rejected_basic_auth_candidates_scan_linearly - 371.1 KiB 1 2.439s 2.478s +1.6% stable
warm-cache-rescan tests/benchmarks/test_scan_benchmarks.py::test_scan_warm_cached_repository_rescan release-candidate 547.3 KiB 32 157.25ms 155.58ms -1.1% stable
mixed-model-repository tests/benchmarks/test_scan_benchmarks.py::test_scan_release_candidate_repository release-candidate 547.3 KiB 32 660.47ms 653.76ms -1.0% stable
duplicate-heavy-registry tests/benchmarks/test_scan_benchmarks.py::test_scan_duplicate_registry_snapshot registry-snapshot 915.2 KiB 13 577.29ms 572.48ms -0.8% stable
padded-multi-stream-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_padded_multi_stream_upload multi_stream_padded 4.1 KiB 1 344.3us 346.8us +0.7% stable
single-checkpoint-preflight tests/benchmarks/test_scan_benchmarks.py::test_scan_single_checkpoint_before_load single_checkpoint.pkl 183.0 KiB 1 104.88ms 104.23ms -0.6% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_base64] nested_base64 98 B 1 293.0us 291.4us -0.6% stable
clean-training-checkpoint tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_clean_training_checkpoint safe_large 278.2 KiB 1 109.46ms 109.90ms +0.4% stable
chunked-upload-stream tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_chunked_upload_stream chunked_stream 278.2 KiB 1 113.18ms 113.06ms -0.1% stable

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

Reviewed commit: 966a5fad61

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 966a5fad61

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@codecov-commenter

codecov-commenter commented Sep 28, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 76.54%. Comparing base (fafb9fb) to head (274694f).

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##             main    #1858   +/-   ##
=======================================
  Coverage   76.54%   76.54%           
=======================================
  Files         218      218           
  Lines      119909   119909           
  Branches    28392    28392           
=======================================
+ Hits        91788    91789    +1     
  Misses      20430    20430           
+ Partials     7691     7690    -1     

see 1 file with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Reuse the AnyIO 4.14.2 and GitPython 3.1.60 lock updates and regression guards from PR #1857 so this branch passes the dependency audit independently.
mldangelo-oai added a commit that referenced this pull request Sep 29, 2026
Port the supported Mypy and Ruff bounds and standalone Mypy validation
from PR #1858 (d324555 and 966a5fa). Restore their known-compatible
locked versions so standalone Ruff remains aligned with the root tool.

Keep Renovate's runtime dependency refresh, including its audited
AnyIO and GitPython updates. Remove the now-unused ast-serialize lock
entry from the Mypy 2.x dependency graph.
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep it up!

Reviewed commit: cb270b2812

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: cb270b2812

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Another round soon, please!

Reviewed commit: 274694fd70

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 274694fd70

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

mldangelo-oai added a commit that referenced this pull request Sep 29, 2026
* chore(deps): lock file maintenance

* fix(ci): preserve compatible tools during lock maintenance

Port the supported Mypy and Ruff bounds and standalone Mypy validation
from PR #1858 (d324555 and 966a5fa). Restore their known-compatible
locked versions so standalone Ruff remains aligned with the root tool.

Keep Renovate's runtime dependency refresh, including its audited
AnyIO and GitPython updates. Remove the now-unused ast-serialize lock
entry from the Mypy 2.x dependency graph.

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Michael D'Angelo <mdangelo@openai.com>
@mldangelo-oai mldangelo-oai changed the title fix(ci): bound compatible lint and type checker versions test(deps): guard patched AnyIO lock versions Oct 3, 2026
@mldangelo
mldangelo merged commit b857a32 into main Oct 3, 2026
26 checks passed
@mldangelo
mldangelo deleted the fix/tooling-version-bounds branch October 3, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants