chore(deps): bump the project-python group across 1 directory with 4 updates - #98
dependabot[bot] wants to merge 1 commit into
Conversation
…updates Bumps the project-python group with 4 updates in the / directory: [genai-prices](https://github.com/pydantic/genai-prices), [httpx2](https://github.com/pydantic/httpx2), [logfire-api](https://github.com/pydantic/logfire) and [openai](https://github.com/openai/openai-python). Updates `genai-prices` from 0.1.6 to 0.1.7 - [Release notes](https://github.com/pydantic/genai-prices/releases) - [Changelog](https://github.com/pydantic/genai-prices/blob/main/RELEASE.md) - [Commits](pydantic/genai-prices@v0.1.6...v0.1.7) Updates `httpx2` from 2.12.0 to 2.13.0 - [Release notes](https://github.com/pydantic/httpx2/releases) - [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md) - [Commits](pydantic/httpx2@v2.12.0...v2.13.0) Updates `logfire-api` from 5.0.0 to 5.1.0 - [Release notes](https://github.com/pydantic/logfire/releases) - [Changelog](https://github.com/pydantic/logfire/blob/main/CHANGELOG.md) - [Commits](pydantic/logfire@v5.0.0...v5.1.0) Updates `openai` from 3.8.0 to 3.15.0 - [Release notes](https://github.com/openai/openai-python/releases) - [Changelog](https://github.com/openai/openai-python/blob/main/CHANGELOG.md) - [Commits](openai/openai-python@v3.8.0...v3.15.0) --- updated-dependencies: - dependency-name: genai-prices dependency-version: 0.1.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: project-python - dependency-name: httpx2 dependency-version: 2.13.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: project-python - dependency-name: logfire-api dependency-version: 5.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: project-python - dependency-name: openai dependency-version: 3.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: project-python ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 86d26bb508
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| [[package]] | ||
| name = "genai-prices" | ||
| version = "0.1.6" | ||
| version = "0.1.7" |
There was a problem hiding this comment.
Regenerate the managed SDK dependency locks
Changing these external resolutions changes the digest bound into ls/config/sdk-dependency-receipt.json, but this commit leaves that receipt and sdk-runtime.lock at the previous versions. Consequently every non-editable wheel build reaches dependency_integrity.verify() and aborts with Stale dependency locks; running python ls/tools/generate_sdk_dependency_locks.py --repo-root . --check reports both files as stale. Regenerate and commit the managed lock export and receipt with this dependency update.
Useful? React with 👍 / 👎.
| [[package]] | ||
| name = "genai-prices" | ||
| version = "0.1.6" | ||
| version = "0.1.7" |
There was a problem hiding this comment.
Audit the newly resolved dependency versions
These new resolutions are not covered by the checked-in supply-chain evidence: vendor/lscli/manifest.json still records genai-prices 0.1.6, httpcore2/httpx2 2.12.0, logfire-api 5.0.0, and openai 3.8.0, and SDK_FORK.md explicitly limits its no-advisory/no-yank result to those exact audited versions. After the generated locks are fixed, this candidate would therefore install unaudited versions while lacking the required release provenance; audit the new exact versions against the documented advisory and registry sources and record dated sources and limitations as new evidence rather than relying on the historical audit.
AGENTS.md reference: AGENTS.md:L172-L176
Useful? React with 👍 / 👎.
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the project-python group with 4 updates in the / directory: genai-prices, httpx2, logfire-api and openai.
Updates
genai-pricesfrom 0.1.6 to 0.1.7Commits
eb37e5eSplit AWS GPT-5.6 (Luna, Sol, Terra) prices into global and regional (#676)120c48eFix triage pilot Pydantic harness helper pin (#688)cec07bfAdd GitHub Copilot pricing (#683)0abc683Add OpenAI GPT-6 Astra pricing (#680)887ca85Add Google Gemini 3.8 Flash pricing (#678)Updates
httpx2from 2.12.0 to 2.13.0Release notes
Sourced from httpx2's releases.
Changelog
Sourced from httpx2's changelog.
Commits
f295185Prepare version 2.13.0 (#1208)8f215b5Use portable links in API docstrings (#1202)36d636aGrouphttpx2.__all__exports by source module (#1188)f1064aaBump the python-packages group across 1 directory with 11 updates (#1179)bc27137Update uv-dynamic-versioning requirement from >=0.14.0 to >=0.14.1 (#1180)62e0827Restore--no-verifyCLI flag (#1186)c9b1d33Replace--no-verifyflag with--verify(#1140)e3a87b1ConvertTimeoutandLimitsto dataclasses (#1167)4c02c4bFixed a grammatical mistake. (#1154)Updates
logfire-apifrom 5.0.0 to 5.1.0Release notes
Sourced from logfire-api's releases.
Changelog
Sourced from logfire-api's changelog.
Commits
17cc059Release v5.1.0 (#2406)acd485fHarden the OpenTelemetry flush regression test (#2405)e209cdaFix Logfire setup skill guidance (#2365)bb17649Prevent OpenTelemetry logging from deadlocking during flush (#2404)5905b8eRoute eval setup through the Logfire evals skill (#2402)6e08b41Make the Logfire evals skill executable for Python and Node.js (#2400)67dae06Document agent framework coverage across Logfire views (#2386)40f6cdfDocument OAuth apps for partner integrations (#2385)84ff5dfContinue setup after CLI authentication (#2384)49619abdocs: fix 'a a' duplication and the stale 'logfire login' reference (#2381)Updates
openaifrom 3.8.0 to 3.15.0Release notes
Sourced from openai's releases.
... (truncated)
Changelog
Sourced from openai's changelog.
... (truncated)
Commits
fcfb37crelease: 3.15.0 (#3870)b7116e6test: synchronize replacement WebSocket handshake (#3891)3b865affeat(api): add managed Responses WebSocket sessions (#3887)bb79676chore(api): update image request examples (#3889)8f7cdb8feat(api): add prompt-cache prewarming (#3888)a6eeb3ffeat(api): add audio-mini model choices (#3886)f0457abchore(api): clarify incoming SIP call ID usage (#3885)4b15817feat(api): add agent session model settings (#3882)b77076dfix: preserve chat stream moderation results (#3864)98e1d24feat(api): add compaction progress events (#3866)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions