Repository navigation
chore(deps): upgrade Python and GitHub Actions dependencies - #333
Merged
Merged
Conversation
There was a problem hiding this comment.
🔵 Needs a closer look
The broad dependency refresh affects 49 packages while the required full test suite remains red from the documented pre-existing deadline failure.
0 open findings
What changed in this PR
Refreshes Python and GitHub Actions dependencies, including security-related pypdf and urllib3 upgrades, with compatibility adjustments for updated tooling.
Changes:
- Refreshes the Python lockfile and raises pypdf and uv_build minimums.
- Updates pinned GitHub Actions releases.
- Adapts annotations, constructors, utilities, and tests to updated Ruff and ty checks.
| File | Description |
|---|---|
uv.lock |
Refreshes resolved dependencies. |
pyproject.toml |
Raises pypdf and uv_build minimums. |
.github/workflows/test.yml |
Updates setup-uv. |
.github/workflows/pr.yml |
Updates setup-uv. |
.github/workflows/release.yml |
Updates setup-uv and artifact actions. |
src/graphon/variables/utils.py |
Simplifies iterable extension. |
src/graphon/runtime/execution.py |
Corrects context-manager annotations. |
src/graphon/file/runtime.py |
Corrects context-manager annotation. |
src/graphon/engine/worker/worker.py |
Corrects context-manager annotation. |
src/graphon/model_runtime/model_providers/base/large_language_model.py |
Simplifies JSON value annotations. |
src/graphon/dsl/slim/llm.py |
Removes constructor override annotation. |
src/graphon/nodes/code/code_node.py |
Removes constructor override annotation. |
src/graphon/nodes/http_request/node.py |
Removes constructor override annotation. |
src/graphon/nodes/human_input/human_input_node.py |
Removes constructor override annotation. |
src/graphon/nodes/llm/node.py |
Removes constructor override annotation. |
src/graphon/nodes/parameter_extractor/parameter_extractor_node.py |
Removes constructor override annotation. |
src/graphon/nodes/template_transform/template_transform_node.py |
Removes constructor override annotation. |
src/graphon/nodes/tool/tool_node.py |
Removes constructor override annotation. |
tests/engine/test_cooperative_container_execution.py |
Updates generator annotation. |
tests/engine/test_file_runtime.py |
Updates generator annotation. |
tests/engine/test_layer_node_run_context.py |
Updates generator annotations. |
tests/graph/test_graph_validation.py |
Removes obsolete test initialization. |
tests/nodes/http_request/test_dispatch.py |
Passes typed node data directly. |
tests/nodes/if_else/test_entities.py |
Passes typed node data directly. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This was referenced Oct 8, 2026
WH-2099
force-pushed
the
chore/upgrade-dependencies-20261008
branch
from
October 9, 2026 10:03
d49195e to
c13684e
Compare
There was a problem hiding this comment.
🟡 Changes recommended
The build-backend floor remains behind the latest stable uv-build release requested by issue #332.
1 open finding
🧠 Review effort: Balanced
zhsama
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Important
!Related Issue
Closes #332.
Replaces the closed dependency PRs #297, #329, #330, and #331.
Summary
Refresh the complete dependency environment with
uv lock --upgrade, updating 49 runtime, development, and transitive packages.This includes pypdf 6.19.0 and urllib3 2.8.0, which cover the eight currently open lockfile security alerts, plus newer transformers, ty, and prek releases than the superseded PRs.
Raise the published pypdf minimum to 6.19.0 and the build backend minimum to uv_build 0.12.24.
Update all available stable GitHub Actions releases while retaining commit SHA pins: setup-uv 10.2.0, upload-artifact 7.0.2, and download-artifact 8.0.2.
Adapt generator annotations, constructor decorators, JSON value annotations, and test inputs to the updated Ruff and ty checks.
Remove an unnecessary iterable truthiness check and unused graph-test initialization.
Four packages remain below their latest releases because current upstream requirements prevent further upgrades:
<4.0.0<2.0<1.0.0<8.4.0Validation
just check: passed, including lock consistency, formatting, Ruff, ty, and import boundaries.uv run --locked --python 3.12 pytest -n 4— 956 passed.uv build --no-create-gitignore --no-sources: wheel and source distribution built successfully.pypdf>=6.19.0and the supported Python range.The branch includes the documentation review merged in #335.
Documentation freshness and link checks now pass on both supported Python versions.
The release and publication workflows have not been executed.
Checklist
!