chore(deps): aggregate envs Dependabot updates - #1152
Draft
cursor[bot] wants to merge 1 commit into
Draft
Conversation
Rebase yesterday's envs rollup onto current main so remaining lockfile security bumps can land without conflicting with the already-merged coding_env tornado and textarena nltk updates. Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Rebases yesterday's envs Dependabot rollup (#1146) onto current
mainso remaining lockfile security bumps can merge cleanly after#1114(coding_env tornado) and#1116(textarena nltk) landed.No new individual Dependabot PRs opened overnight. This PR only carries unpublished
envs/**/uv.lockupdates from #1146 / #1015.Included (still not on main):
Left untouched so we do not regress main:
envs/coding_env(tornado 6.5.8 + Hugging Face registry already on main)envs/textarena_env(nltk>=3.10.3already on main; chore(deps): aggregate envs Dependabot updates #1146 still had>=3.10.0)envs/repl_env(pypdf>=6.16.1already on main)This supersedes #1146 and #1015.
Core Dependabot status (no second mergeable PR today):
envs/.cf20b09) are already newer than chore(deps): aggregate non-env dependabot updates #1109 (1b16dac). Opening a core PR from chore(deps): aggregate non-env dependabot updates #1109 would downgrade workflows.#1119, pin>=3.0.0,<5.0.0) remains blocked: HTTP and WebSocketinc_counterpersistence still fail.#1119was closed 2026-09-10; do not re-open until those tests pass.Type of Change
Alignment Checklist
Before submitting, verify:
.claude/docs/PRINCIPLES.mdand this PR aligns with our principles.claude/docs/INVARIANTS.mdand no invariants are violated (envs lockfiles only; no agent-facing reset/API changes)uv lock --checkpassed in every updated envRFC Status
Test Plan
git diff --check origin/main...HEADenvs/**/uv.lockonly (17 files)uv lock --checkin each updated environment: passsrc/or rootpyproject.tomlchangesClaude Code Review
N/A — Dependabot lockfile rollup.
This automation cannot close PRs (GitHub token returns 403). Please close these superseded aggregates: