chore(deps): bump the project-python group with 2 updates - #97
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the project-python group with 2 updates: [logfire-api](https://github.com/pydantic/logfire) and [openai](https://github.com/openai/openai-python). Updates `logfire-api` from 5.0.0 to 5.1.0 - [Release notes](https://github.com/pydantic/logfire/releases) - [Changelog](https://github.com/pydantic/logfire/blob/main/CHANGELOG.md) - [Commits](pydantic/logfire@v5.0.0...v5.1.0) Updates `openai` from 3.8.0 to 3.13.0 - [Release notes](https://github.com/openai/openai-python/releases) - [Changelog](https://github.com/openai/openai-python/blob/main/CHANGELOG.md) - [Commits](openai/openai-python@v3.8.0...v3.13.0) --- updated-dependencies: - dependency-name: logfire-api dependency-version: 5.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: project-python - dependency-name: openai dependency-version: 3.13.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: project-python ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 02c84313a2
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| [[package]] | ||
| name = "logfire-api" | ||
| version = "5.0.0" | ||
| version = "5.1.0" |
There was a problem hiding this comment.
Regenerate the managed SDK dependency locks
When building any non-editable distribution, BuildSDK.run() verifies that ls/config/sdk-runtime.lock and sdk-dependency-receipt.json match uv.lock; this dependency bump leaves both generated files stale, so the build aborts with ValueError: Stale dependency locks. On this exact tree, python3 ls/tools/generate_sdk_dependency_locks.py --repo-root . --check reports both files as stale. Regenerate and commit the managed SDK lock and receipt alongside this update.
Useful? React with 👍 / 👎.
| [[package]] | ||
| name = "openai" | ||
| version = "3.8.0" | ||
| version = "3.13.0" |
There was a problem hiding this comment.
Re-audit the newly selected dependency versions
The newly locked openai==3.13.0 and logfire-api==5.1.0 artifacts were uploaded on September 10–11, but the repository's only combined dependency audit in ls/docs/SDK_FORK.md is dated September 5 and vendor/lscli/manifest.json still records the audited versions as 3.8.0 and 5.0.0. Thus there is no recorded advisory/yank or installed-compatibility evidence for the versions this change adopts. Audit these exact versions against the required primary sources and refresh the maintained evidence before accepting the bump.
AGENTS.md reference: AGENTS.md:L172-L178
Useful? React with 👍 / 👎.
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the project-python group with 2 updates: logfire-api and openai.
Updates
logfire-apifrom 5.0.0 to 5.1.0Release notes
Sourced from logfire-api's releases.
Changelog
Sourced from logfire-api's changelog.
Commits
17cc059Release v5.1.0 (#2406)acd485fHarden the OpenTelemetry flush regression test (#2405)e209cdaFix Logfire setup skill guidance (#2365)bb17649Prevent OpenTelemetry logging from deadlocking during flush (#2404)5905b8eRoute eval setup through the Logfire evals skill (#2402)6e08b41Make the Logfire evals skill executable for Python and Node.js (#2400)67dae06Document agent framework coverage across Logfire views (#2386)40f6cdfDocument OAuth apps for partner integrations (#2385)84ff5dfContinue setup after CLI authentication (#2384)49619abdocs: fix 'a a' duplication and the stale 'logfire login' reference (#2381)Updates
openaifrom 3.8.0 to 3.13.0Release notes
Sourced from openai's releases.
... (truncated)
Changelog
Sourced from openai's changelog.
... (truncated)
Commits
f0fa922release: 3.13.0 (#3848)1c4284afeat(agents): add beta API and one-turn streaming helpers (#3847)603b81frelease: 3.12.0 (#3832)0e4bfeffeat(api) Add Live API (#3846)802b334fix: add aclose() to AsyncStream for standard async cleanup (#2854)adb212efix: preserve finalized output on null response completion (#3345)c7e8c03fix: handle baredictandlistannotations without type arguments (#3760)397ea08ci: resolve fork PRs missing Castiron run associations (#3831)2d4b97ctest: restore CI test runtime after dependency-policy regression (#3830)41f0a23release: 3.11.0 (#3829)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions