build(deps): bump build 1.6.1, tzdata 2026.4, pyproject-hooks 1.3.3, pyjwt 2.14.0 - #902
Merged
Merged
Conversation
…pyjwt 2.14.0 Applies the four open Dependabot lock bumps (#881, #882, #883, #884) in one change, so they share one CI run under the strict up-to-date rule. #881's own regeneration of constraints/release-seal.txt is not carried: its pip-compile wrote `pydantic[email]==2.13.5`, which verify_dependency_lock.py cannot parse (all four suite jobs failed on it), dropped the PyPy markers on cffi and pycparser, dropped Windows-only colorama, and left the `declares: build==1.6.0` line behind. Here the seal lock changes only in its build pin, hashes and declares line. Each hand edit is byte-identical to a pinned uv 0.12.9 `uv pip compile --universal --generate-hashes` run that keeps the existing pins as preferences. All hashes match PyPI's digests, and requires_dist is unchanged for every bumped version, so no closure widens. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Carries the four open Dependabot lock bumps in one change, so they need one CI run under the strict up-to-date rule instead of four. This supersedes #881, #882, #883 and #884. Dependabot closes each one once main carries its version.
dev.txt,release-seal.in,release-seal.txtdev.txtdev.txtdev.txtWhy #881 is not merged as-is
All four of #881's suite jobs failed within 30 seconds at Verify the dependency locks. Dependabot regenerated
constraints/release-seal.txtwith its own pip-compile, and that rewrite:pydantic[email]==2.13.5, whichscripts/verify_dependency_lock.pycannot parse;platform_python_implementation != 'PyPy'markers oncffiandpycparser;colorama==0.4.6 ; os_name == 'nt';declares: build==1.6.0in the header.Here the seal lock changes only in build's pin, its two hashes and the declares line.
Checks
requires_distis unchanged between the old and new version of each package, so no closure widens.uv pip compile --universal --generate-hashesrun that keeps the existing pins as preferences. A barescripts/update_locks.pyhas no preferences and would also move eight unrelated seal pins, so it was not used.scripts/verify_dependency_lock.pypasses for all four locks locally.tests/test_release_pipeline.pyandtests/test_release_engine_smoke.pypass locally.#885 (the
claude-agent-sdkfloor inharness/requirements.txt) is left out on purpose. That file says to raise the floor only after re-running the smoke and a paid Sonnet cell.🤖 Generated with Claude Code