Skip to content

fix: admit tested Hermes dependency versions - #12

Open
ethernet8023 wants to merge 1 commit into
lancedb:mainfrom
ethernet8023:fix/hermes-tested-dependency-ranges
Open

ethernet8023 wants to merge 1 commit into
lancedb:mainfrom
ethernet8023:fix/hermes-tested-dependency-ranges

Conversation

@ethernet8023

Copy link
Copy Markdown

change

lower the dependency minimums to the versions Hermes actually ships, with upper bounds:

  • openai>=2.24.0,<3
  • requests>=2.33.0,<3
  • botocore>=1.42.97,<2

this completes the approach in #11, which lowers OpenAI/Requests but leaves botocore>=1.43.16. that remaining floor conflicts with Hermes's boto3 requirement. credit to @teknium1 for #11.

verification

  • the original requirements fail in a real PM-generated Hermes workspace; the changed package locks while keeping Hermes's exact versions.
  • 50 offline tests pass at the tested minima, including the real OpenAI client with mocked HTTP. i reran all 50 before submission; dependency checks pass.
  • S3 model/stub calls and Requests request preparation pass.
  • tests also pass with the resolver-selected LanceDB 0.39.0.
  • dependency regression tests fail against the old floors. lock refresh does not upgrade package versions.

adds Python 3.14/minimum-version CI coverage using uv run --no-sync so tests retain the selected versions. Requests 2.33.0 keeps the documented security fix. no hosted API or downloaded reranker was exercised.

Infographic

upstream compatibility fixes

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant