Skip to content

build(deps): bump build 1.6.1, tzdata 2026.4, pyproject-hooks 1.3.3, pyjwt 2.14.0 - #902

Merged
pengfei-threemoonslab merged 1 commit into
mainfrom
claude/deps-bumps-2026-09-27
Sep 27, 2026
Merged

pengfei-threemoonslab merged 1 commit into
mainfrom
claude/deps-bumps-2026-09-27

Conversation

@pengfei-threemoonslab

Copy link
Copy Markdown
Contributor

Carries the four open Dependabot lock bumps in one change, so they need one CI run under the strict up-to-date rule instead of four. This supersedes #881, #882, #883 and #884. Dependabot closes each one once main carries its version.

package from → to lock(s) Dependabot PR
build 1.6.0 → 1.6.1 dev.txt, release-seal.in, release-seal.txt #881
tzdata 2026.3 → 2026.4 dev.txt #882
pyproject-hooks 1.2.0 → 1.3.3 dev.txt #883
pyjwt 2.13.0 → 2.14.0 dev.txt #884

Why #881 is not merged as-is

All four of #881's suite jobs failed within 30 seconds at Verify the dependency locks. Dependabot regenerated constraints/release-seal.txt with its own pip-compile, and that rewrite:

  • wrote pydantic[email]==2.13.5, which scripts/verify_dependency_lock.py cannot parse;
  • dropped the platform_python_implementation != 'PyPy' markers on cffi and pycparser;
  • deleted the Windows-only colorama==0.4.6 ; os_name == 'nt';
  • left declares: build==1.6.0 in the header.

Here the seal lock changes only in build's pin, its two hashes and the declares line.

Checks

  • Every new hash matches PyPI's published sha256 digests for that version.
  • requires_dist is unchanged between the old and new version of each package, so no closure widens.
  • Each hand edit is byte-identical to a pinned uv 0.12.9 uv pip compile --universal --generate-hashes run that keeps the existing pins as preferences. A bare scripts/update_locks.py has no preferences and would also move eight unrelated seal pins, so it was not used.
  • scripts/verify_dependency_lock.py passes for all four locks locally.
  • tests/test_release_pipeline.py and tests/test_release_engine_smoke.py pass locally.

#885 (the claude-agent-sdk floor in harness/requirements.txt) is left out on purpose. That file says to raise the floor only after re-running the smoke and a paid Sonnet cell.

🤖 Generated with Claude Code

…pyjwt 2.14.0

Applies the four open Dependabot lock bumps (#881, #882, #883, #884) in one
change, so they share one CI run under the strict up-to-date rule.

#881's own regeneration of constraints/release-seal.txt is not carried: its
pip-compile wrote `pydantic[email]==2.13.5`, which verify_dependency_lock.py
cannot parse (all four suite jobs failed on it), dropped the PyPy markers on
cffi and pycparser, dropped Windows-only colorama, and left the
`declares: build==1.6.0` line behind. Here the seal lock changes only in its
build pin, hashes and declares line.

Each hand edit is byte-identical to a pinned uv 0.12.9
`uv pip compile --universal --generate-hashes` run that keeps the existing pins
as preferences. All hashes match PyPI's digests, and requires_dist is unchanged
for every bumped version, so no closure widens.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@pengfei-threemoonslab
pengfei-threemoonslab merged commit e79f95e into main Sep 27, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant