chore(deps): bump the python-security group across 1 directory with 2 updates - #3991
dependabot[bot] wants to merge 10 commits into
Conversation
Castiron custom codeEvaluated main: ✅ No new custom-code files detected. 47 mixed files remain; 0 existing customizations changed. Compared 47 existing customizations unchanged
7 more in the full report. A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 37065823877 --repo openai/openai-python \
--name castiron-custom-code-37065823877-1 --dir /tmp/castiron-custom-code-37065823877-1
git apply --stat /tmp/castiron-custom-code-37065823877-1/custom-code.patch
cat /tmp/castiron-custom-code-37065823877-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin becc1d20eed83c1b8d85e15dc131a372d9dc7813 ed686f06e8aa24111430944da38ae916ead4f9ff
python3 scripts/castiron/custom_code_report.py report \
--base becc1d20eed83c1b8d85e15dc131a372d9dc7813 \
--head ed686f06e8aa24111430944da38ae916ead4f9ff --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-ed686f06e8aa
cat /tmp/castiron-custom-code-ed686f06e8aa/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2f395e3c3f
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
… updates Bumps the python-security group with 2 updates in the / directory: [anyio](https://github.com/agronholm/anyio) and [pyjwt](https://github.com/jpadilla/pyjwt). Updates `anyio` from 4.12.1 to 4.14.2 - [Release notes](https://github.com/agronholm/anyio/releases) - [Commits](agronholm/anyio@4.12.1...4.14.2) Updates `pyjwt` from 2.13.0 to 2.14.0 - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.13.0...2.14.0) --- updated-dependencies: - dependency-name: anyio dependency-version: 4.14.2 dependency-type: direct:production dependency-group: python-security - dependency-name: pyjwt dependency-version: 2.14.0 dependency-type: indirect dependency-group: python-security ... Signed-off-by: dependabot[bot] <support@github.com>
2f395e3 to
fc6ed7e
Compare
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aaa2cf0e07
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Pull request was converted to draft
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5b5a4d9d36
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if ( | ||
| name == "anyio" | ||
| and previous_contexts == current_contexts == {("runtime", "", (), ()): {"anyio>=4.10.0,<5"}} | ||
| and previous_domains == {(): {"4.12.1"}} | ||
| and current_domains == {(): {"4.14.2"}} |
There was a problem hiding this comment.
Land the AnyIO exemption before using it
In the intended Dependabot python-security PR, the dependency-locks job runs git show "$BASE_SHA:scripts/check-dependency-security.py" | python -I - (.github/workflows/ci.yml:55), so it executes the parent version of this checker rather than these newly added lines. That parent checker rejects this commit's unchanged anyio>=4.10.0,<5 requirement with Raise the published security-fixed minimum for anyio; the new tests miss this because their helper compiles the candidate checker. The exemption must therefore be present in the trusted base before the lock-only AnyIO update relies on it.
Useful? React with 👍 / 👎.
Bumps the python-security group with 2 updates in the / directory: anyio and pyjwt.
Updates
anyiofrom 4.12.1 to 4.14.2Release notes
Sourced from anyio's releases.
... (truncated)
Commits
c384f99Bumped up the versiondbba29dFixed 100% CPU spin on cancel scope misuse (#1217)6bbc6c3Fix CapacityLimiter over-granting tokens on asyncio (#1172)6f82b25Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flakybe24b04Relaxed timeouts to fix test flakiness8113506Fix test flakiness caused by slow callback duration logging1e988b6Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (#1...44713f3Pin setup-uv to a commit sha across downstream jobs (#1213)f1b7301Fixed stderr writes in a worker subprocess causing a deadlock (#1207)212be93Fix flaky test_tcp_listener_same_port using a hardcoded port (#1206)Updates
pyjwtfrom 2.13.0 to 2.14.0Release notes
Sourced from pyjwt's releases.
Changelog
Sourced from pyjwt's changelog.