Skip to content

chore(deps): aggregate envs Dependabot updates - #1146

Draft
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/dependabot-envs-2026-09-10
Draft

chore(deps): aggregate envs Dependabot updates#1146
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/dependabot-envs-2026-09-10

Conversation

@cursor

@cursor cursor Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Aggregates the remaining open envs/ Dependabot updates into one PR, and carries unpublished lockfile security bumps from #1015 / #1131 so they are not dropped.

New open Dependabot PRs included:

Already on main (from fda3603e); close the singles, nothing left to land:

Also included from #1015 / #1131 (still not on main):

  • cryptography → 50.0.0 in calendar, carla, chat, opencode, pelican_svg, pi, qed_math, sophistry_bench_sprint, sumo_rl, terminus, websearch, agent_world_model, wildfire
  • aiohttp → 3.14.3 in agent_world_model, finrl, openapp, qed_math, sophistry_bench_sprint
  • h2/hpack in coding_tools_env, nltk in openapp_env, pyjwt in tbench2_env, pillow in websearch_env

repl_env files are left untouched so we do not regress the pypdf>=6.16.1 lower bound already on main.

This supersedes #1015 and #1131.

Core Dependabot status (no second mergeable PR today):

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation
  • New environment
  • Refactoring
  • Dependency updates (envs only)

Alignment Checklist

Before submitting, verify:

  • I have read .claude/docs/PRINCIPLES.md and this PR aligns with our principles
  • I have checked .claude/docs/INVARIANTS.md and no invariants are violated (envs lockfiles only; no agent-facing reset/API changes)
  • uv lock --check passed in every updated env

RFC Status

  • Not required (bug fix, docs, minor refactoring)
  • RFC exists: #___
  • RFC needed (will create before merge)

Test Plan

  • git diff --check origin/main...HEAD
  • Scope is envs/**/uv.lock plus envs/textarena_env/pyproject.toml
  • uv lock --check in each updated environment: pass
  • No src/ or root pyproject.toml changes

Claude Code Review

N/A — Dependabot lockfile rollup.

This automation cannot close PRs (GitHub token returns 403). Please close these superseded PRs:

Open in Web View Automation 

Roll up the remaining open envs Dependabot bumps and unpublished
lockfile security updates from the prior aggregate so maintainers
can land one PR instead of several overlapping ones.

Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant