Skip to content

chore(deps): aggregate envs Dependabot updates - #1152

Draft
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/dependabot-envs-2026-09-11
Draft

chore(deps): aggregate envs Dependabot updates#1152
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/dependabot-envs-2026-09-11

Conversation

@cursor

@cursor cursor Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Summary

Rebases yesterday's envs Dependabot rollup (#1146) onto current main so remaining lockfile security bumps can merge cleanly after #1114 (coding_env tornado) and #1116 (textarena nltk) landed.

No new individual Dependabot PRs opened overnight. This PR only carries unpublished envs/**/uv.lock updates from #1146 / #1015.

Included (still not on main):

  • cryptography → 50.0.0 in calendar, carla, chat, opencode, pelican_svg, pi, qed_math, sophistry_bench_sprint, sumo_rl, terminus, websearch, agent_world_model, wildfire
  • aiohttp → 3.14.3 in agent_world_model, finrl, openapp, qed_math, sophistry_bench_sprint
  • h2 4.4.1 / hpack 4.2.0 in coding_tools_env
  • nltk 3.10.0 in openapp_env
  • pyjwt 2.13.0 in tbench2_env
  • pillow 12.3.0 in websearch_env

Left untouched so we do not regress main:

This supersedes #1146 and #1015.

Core Dependabot status (no second mergeable PR today):

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation
  • New environment
  • Refactoring
  • Dependency updates (envs only)

Alignment Checklist

Before submitting, verify:

  • I have read .claude/docs/PRINCIPLES.md and this PR aligns with our principles
  • I have checked .claude/docs/INVARIANTS.md and no invariants are violated (envs lockfiles only; no agent-facing reset/API changes)
  • uv lock --check passed in every updated env

RFC Status

  • Not required (bug fix, docs, minor refactoring)
  • RFC exists: #___
  • RFC needed (will create before merge)

Test Plan

  • git diff --check origin/main...HEAD
  • Scope is envs/**/uv.lock only (17 files)
  • uv lock --check in each updated environment: pass
  • No src/ or root pyproject.toml changes

Claude Code Review

N/A — Dependabot lockfile rollup.

This automation cannot close PRs (GitHub token returns 403). Please close these superseded aggregates:

Open in Web View Automation 

Rebase yesterday's envs rollup onto current main so remaining
lockfile security bumps can land without conflicting with the
already-merged coding_env tornado and textarena nltk updates.

Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant