Skip to content

fix(sdk): declare requests and httpx as dependencies - #4527

Open
RosieOh wants to merge 2 commits into
traceloop:mainfrom
RosieOh:fix/sdk-declare-requests-httpx
Open

RosieOh wants to merge 2 commits into
traceloop:mainfrom
RosieOh:fix/sdk-declare-requests-httpx

Conversation

@RosieOh

@RosieOh RosieOh commented Sep 29, 2026 •

Copy link
Copy Markdown

Fixes #4526

traceloop-sdk imports requests and httpx when traceloop.sdk is imported, but neither was declared, so from traceloop.sdk import Traceloop failed in a clean environment: on requests with OpenTelemetry 1.45, whose HTTP exporter no longer depends on it, and on httpx with OpenTelemetry 1.44.

This adds both to the dependencies:

  • httpx>=0.23.0,<1: the SDK only uses AsyncClient, Timeout, Response, TimeoutException and ConnectError, which are stable across that range. It's also the range the OpenAI SDK allows, so the two install together.
  • requests>=2.31.0,<3: matches the existing types-requests pin.

Running uv lock (the package's lock target) also refreshed the local path packages from 0.62.1 to 0.62.3 and one of their dependency markers, which the lock hadn't picked up since the last release.

Verified by building the wheel and installing it in fresh virtualenvs: from traceloop.sdk import Traceloop now works with OpenTelemetry 1.45.0 and 1.44.0, and Traceloop.init() plus a @workflow span export to a local OTLP receiver over both HTTP and gRPC.

Summary by CodeRabbit

  • Chores
    • This update includes no changes to the app’s visible features or behavior. There are no new user-facing capabilities, fixes, or interface changes to highlight in these release notes.

traceloop.sdk imports both at import time, but neither was declared, so a
clean install failed with ModuleNotFoundError: on requests with
OpenTelemetry 1.45, whose HTTP exporter no longer depends on it, and on
httpx with 1.44.

uv lock also refreshes the local path packages to 0.62.3.

Fixes traceloop#4526
@CLAassistant

CLAassistant commented Sep 29, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⛔ Files ignored due to path filters (1)
  • packages/traceloop-sdk/uv.lock is excluded by !**/*.lock
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: d2a7d161-ae26-4e0d-9d10-738bb288d3d7

📥 Commits

Reviewing files that changed from the base of the PR and between f741165 and 77e28f4.

⛔ Files ignored due to path filters (1)
  • packages/traceloop-sdk/uv.lock is excluded by !**/*.lock

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: d9d024f8-e5fa-41ad-a999-85c02f1dbc2d

📥 Commits

Reviewing files that changed from the base of the PR and between 6102f9e and f741165.

⛔ Files ignored due to path filters (1)
  • packages/traceloop-sdk/uv.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • packages/traceloop-sdk/pyproject.toml

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The traceloop-sdk runtime dependencies now include httpx and requests, with specified version bounds.

Changes

SDK runtime dependencies

Layer / File(s) Summary
Declare HTTP dependencies
packages/traceloop-sdk/pyproject.toml
The runtime dependency list adds httpx>=0.23.0,<1 and requests>=2.31.0,<3.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to f7411

The SDK’s HTTP dependencies are declared and reflected in its lockfile. No merge-blocking risk is evident; it is ready for normal checks.

Architecture Summary

Architecture risk: 🔵 Low · up to f7411

The change affects 1 system.

Changed systems: packages/traceloop-sdk

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — packages/traceloop-sdk (library) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in packages/traceloop-sdk/pyproject.toml: Added httpx and requests to the project’s runtime dependencies, with their respective version bounds.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: declaring requests and httpx as SDK dependencies.
Linked Issues check ✅ Passed The PR adds httpx>=0.23.0,<1 and requests>=2.31.0,<3 to traceloop-sdk dependencies in packages/traceloop-sdk/pyproject.toml. These declarations provide both packages when users install `tracel…
Out of Scope Changes check ✅ Passed The reviewed change is limited to dependency declarations required by issue [#4526]. The reported wheel and fresh-environment checks directly validate the import behavior and SDK operation. No unrelat…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🐛 Bug Report: traceloop-sdk imports requests and httpx without declaring them

2 participants