Skip to content

chore(deps): uv: bump the all-python group across 1 directory with 6 updates#626

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/agent/all-python-562714a858
Open

chore(deps): uv: bump the all-python group across 1 directory with 6 updates#626
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/agent/all-python-562714a858

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-python group with 6 updates in the /agent directory:

Package From To
boto3 1.43.40 1.43.46
bedrock-agentcore 1.17.0 1.18.0
claude-agent-sdk 0.2.110 0.2.116
uvicorn 0.50.0 0.51.0
ruff 0.15.20 0.15.21
ty 0.0.56 0.0.58

Updates boto3 from 1.43.40 to 1.43.46

Commits
  • c7888d6 Merge branch 'release-1.43.46'
  • 1479621 Bumping version to 1.43.46
  • 54abdb4 Add changelog entries from botocore
  • 75de637 Merge branch 'release-1.43.45'
  • d3449aa Merge branch 'release-1.43.45' into develop
  • 497253d Bumping version to 1.43.45
  • 5e9768e Add changelog entries from botocore
  • 19a915b Merge branch 'release-1.43.44'
  • 1b69a06 Merge branch 'release-1.43.44' into develop
  • b0e3f6a Bumping version to 1.43.44
  • Additional commits viewable in compare view

Updates bedrock-agentcore from 1.17.0 to 1.18.0

Release notes

Sourced from bedrock-agentcore's releases.

Bedrock AgentCore SDK v1.18.0

Installation

pip install bedrock-agentcore==1.18.0

What's Changed

See CHANGELOG.md for details.

What's Changed

New Contributors

Full Changelog: aws/bedrock-agentcore-sdk-python@v1.17.0...v1.18.0

Changelog

Sourced from bedrock-agentcore's changelog.

[1.18.0] - 2026-07-10

Fixed

  • fix: floor monotonic timestamps to milliseconds before comparison (#573) (f855616)
  • fix: order AgentCore Memory events at millisecond resolution (#572) (a271ab4)

Other Changes

  • ci: add API reference docs generation workflow (#569) (168f4be)
  • fix(payments): address langgraph middleware review follow-ups (#570) (46a0bea)
  • feat(payments): Add LangGraph integration for payment handling (#546) (0a8a486)
Commits
  • 8df87bb chore: bump version to 1.18.0 (#574)
  • f855616 fix: floor monotonic timestamps to milliseconds before comparison (#573)
  • a271ab4 fix: order AgentCore Memory events at millisecond resolution (#572)
  • 168f4be ci: add API reference docs generation workflow (#569)
  • 46a0bea fix(payments): address langgraph middleware review follow-ups (#570)
  • 0a8a486 feat(payments): Add LangGraph integration for payment handling (#546)
  • See full diff in compare view

Updates claude-agent-sdk from 0.2.110 to 0.2.116

Release notes

Sourced from claude-agent-sdk's releases.

v0.2.116

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.207
  • Fixed CI workspace trust so Claude Code honors project-scoped permission grants in checkout directories (#1085)

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.116/

pip install claude-agent-sdk==0.2.116

v0.2.115

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.206

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.115/

pip install claude-agent-sdk==0.2.115

v0.2.114

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.205

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.114/

pip install claude-agent-sdk==0.2.114

v0.2.113

Internal/Other Changes

... (truncated)

Changelog

Sourced from claude-agent-sdk's changelog.

0.2.116

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.207
  • Fixed CI workspace trust so Claude Code honors project-scoped permission grants in checkout directories (#1085)

0.2.115

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.206

0.2.114

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.205

0.2.113

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.204

0.2.112

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.203

0.2.111

Bug Fixes

  • Zombie CLI subprocess prevention: Shielded subprocess cleanup from asyncio cancellation so SIGTERM/SIGKILL teardown always runs, preventing orphaned claude child processes when the parent task is cancelled (#1082)
  • Silent whitespace loss on large NDJSON lines: Fixed the NDJSON parser silently dropping whitespace when a single line exceeded the 64 KiB stream buffer, which could corrupt tool output or assistant message content (#1083)
  • TypeError on non-dict message content: Fixed an uncaught TypeError when the CLI emits a message whose content field is a plain string or other non-dict value instead of the expected list of content blocks (#1058)
  • can_use_tool shadowed by allowed_tools: Added a runtime warning when a can_use_tool callback is registered alongside allowed_tools or bypassPermissions, which silently prevents the callback from ever firing (#1081)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.202
  • Fixed e2e stderr test flakiness by running the query from a clean working directory (#1084)
Commits
  • 528265f docs: update changelog for v0.2.116
  • 1a887d9 chore: release v0.2.116
  • 85ad6a6 chore: bump bundled CLI version to 2.1.207
  • b817bf5 ci: trust the checkout workspace so Claude Code honors project-scoped grants ...
  • 41f7b2d docs: update changelog for v0.2.115
  • ac4772e chore: release v0.2.115
  • 66bfd70 chore: bump bundled CLI version to 2.1.206
  • fdee0ad docs: update changelog for v0.2.114
  • 5aa66ae chore: release v0.2.114
  • 8d4ab78 chore: bump bundled CLI version to 2.1.205
  • Additional commits viewable in compare view

Updates uvicorn from 0.50.0 to 0.51.0

Release notes

Sourced from uvicorn's releases.

Version 0.51.0

What's Changed

Full Changelog: Kludex/uvicorn@0.50.2...0.51.0

Version 0.50.1

What's Changed

New Contributors

Full Changelog: Kludex/uvicorn@0.50.0...0.50.1

Changelog

Sourced from uvicorn's changelog.

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

0.50.2 (July 6, 2026)

Fixed

  • Require websockets>=13.0, which the default websockets-sansio implementation needs (#3021)

0.50.1 (July 6, 2026)

Fixed

  • Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansio implementation (#3019)
Commits
  • e4d0b05 Version 0.51.0 (#3028)
  • 944e43d Remove colorama from the standard extra (#3027)
  • 2e78770 Restart workers with overlap on SIGHUP for near-zero-downtime reloads (#3025)
  • a1b570c Version 0.50.2 (#3022)
  • 83c7da7 Require websockets>=13.0 for the default sansio implementation (#3021)
  • b4d0116 Version 0.50.1 (#3020)
  • 2a9151d Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansi...
  • 1bf3ab4 Cover the excluded-directory branch in FileFilter with a direct test (#3014)
  • 837b5f9 Deflake multiprocess, reload, and signal supervisor tests (#2975)
  • See full diff in compare view

Updates ruff from 0.15.20 to 0.15.21

Release notes

Sourced from ruff's releases.

0.15.21

Release Notes

Released on 2026-07-09.

Preview features

  • Add --add-ignore for adding ruff:ignore comments (#26346)
  • [flake8-comprehensions] Drop C409 tuple comprehension preview behavior (#25707)
  • Avoid whitespace normalization when formatting comments (#26455)
  • [pyupgrade] Lint and fix use of deprecated abc decorators (UP051) (#26417)

Bug fixes

  • Refine non-empty f-string detection (#26526)
  • Detect syntax errors in individual notebook cells (#26419)
  • [flake8-implicit-str-concat] Fix ISC003 autofix incorrectly stripping + from comments (#26554)

Rule changes

  • [flake8-executable] Mark EXE004 fix as unsafe (#26033)
  • [flake8-pyi] Mark PYI061 fixes as unsafe in Python files (#26533)
  • [pydocstyle] Skip overload-with-docstring in stub files (D418) (#26318)

Performance

  • Avoid per-token source index visitor calls (#26506)
  • Cache parenthesized expression boundaries in the formatter (#26344)
  • Improve performance of rendering edits in preview mode (#26565)
  • Inline fits_element in formatter (#26429)
  • Inline formatter printing hot paths (#26504)
  • Lazily create builtin bindings (#26510)
  • Skip empty trivia scans in the source indexer (#26507)
  • Use ICF for macOS release builds (#25780)

Formatter

  • Add --extend-exclude to ruff format (#26372)

Documentation

  • Add "How does Ruff's import sorting compare to isort?" link to README (#26530)
  • Fix Mozilla Firefox repository link in README (#26537)
  • [flake8-bandit] Fix misleading docstring for mako-templates (S702) (#26432)
  • [ruff] Fix non-triggering example for if-key-in-dict-del (RUF051) (#26433)

Contributors

... (truncated)

Changelog

Sourced from ruff's changelog.

0.15.21

Released on 2026-07-09.

Preview features

  • Add --add-ignore for adding ruff:ignore comments (#26346)
  • [flake8-comprehensions] Drop C409 tuple comprehension preview behavior (#25707)
  • Avoid whitespace normalization when formatting comments (#26455)
  • [pyupgrade] Lint and fix use of deprecated abc decorators (UP051) (#26417)

Bug fixes

  • Refine non-empty f-string detection (#26526)
  • Detect syntax errors in individual notebook cells (#26419)
  • [flake8-implicit-str-concat] Fix ISC003 autofix incorrectly stripping + from comments (#26554)

Rule changes

  • [flake8-executable] Mark EXE004 fix as unsafe (#26033)
  • [flake8-pyi] Mark PYI061 fixes as unsafe in Python files (#26533)
  • [pydocstyle] Skip overload-with-docstring in stub files (D418) (#26318)

Performance

  • Avoid per-token source index visitor calls (#26506)
  • Cache parenthesized expression boundaries in the formatter (#26344)
  • Improve performance of rendering edits in preview mode (#26565)
  • Inline fits_element in formatter (#26429)
  • Inline formatter printing hot paths (#26504)
  • Lazily create builtin bindings (#26510)
  • Skip empty trivia scans in the source indexer (#26507)
  • Use ICF for macOS release builds (#25780)

Formatter

  • Add --extend-exclude to ruff format (#26372)

Documentation

  • Add "How does Ruff's import sorting compare to isort?" link to README (#26530)
  • Fix Mozilla Firefox repository link in README (#26537)
  • [flake8-bandit] Fix misleading docstring for mako-templates (S702) (#26432)
  • [ruff] Fix non-triggering example for if-key-in-dict-del (RUF051) (#26433)

Contributors

... (truncated)

Commits

Updates ty from 0.0.56 to 0.0.58

Release notes

Sourced from ty's releases.

0.0.58

Release Notes

Released on 2026-07-09.

Bug fixes

  • Fix protocol matching for class variables (#26669)
  • Fix reflected binary dispatch for runtime classes (#26623)
  • Support cached properties in protocols (#26681)

Diagnostics

  • Add assignability context to upper-bound diagnostics (#26645)
  • Add blanket ignore comment rule (#26426)
  • Improve protocol attribute diagnostic context (#26644)

Library support

  • Pydantic: Add fields from mixin classes (#26631)
  • Pydantic: Add support for validate_by_{name,alias} (#26598)
  • Pydantic: Add support for validation_alias (#26629)
  • Pydantic: Fix float conversion in unions (#26655)
  • Pydantic: Ignore private attributes (#26630)
  • Pydantic: Make BaseSettings fields optional by default (#26628)
  • Pydantic: Recognize frozen models via config (#26648)
  • Pydantic: Support dict model configurations (#26632)
  • Pydantic: Support validation of RootModel fields (#26634)
  • Pydantic: Understand ellipsis as providing no default value (#26637)

Core type checking

  • Gate membership narrowing on __contains__ semantics (#25964)
  • Handle callable classes in solver (#26090)
  • Infer ModuleType.__doc__ as str in the presence of a docstring (#26505)
  • Infer metaclass-declared attributes on class instances (#26512)
  • Respect user stub overlays during module resolution (#26123)

Performance

  • Avoid allocating decorated parameter names (#26666)
  • Optimize TypeCollector (#26593)

Contributors

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.58

Released on 2026-07-09.

Bug fixes

  • Fix protocol matching for class variables (#26669)
  • Fix reflected binary dispatch for runtime classes (#26623)
  • Support cached properties in protocols (#26681)

Diagnostics

  • Add assignability context to upper-bound diagnostics (#26645)
  • Add blanket ignore comment rule (#26426)
  • Improve protocol attribute diagnostic context (#26644)

Library support

  • Pydantic: Add fields from mixin classes (#26631)
  • Pydantic: Add support for validate_by_{name,alias} (#26598)
  • Pydantic: Add support for validation_alias (#26629)
  • Pydantic: Fix float conversion in unions (#26655)
  • Pydantic: Ignore private attributes (#26630)
  • Pydantic: Make BaseSettings fields optional by default (#26628)
  • Pydantic: Recognize frozen models via config (#26648)
  • Pydantic: Support dict model configurations (#26632)
  • Pydantic: Support validation of RootModel fields (#26634)
  • Pydantic: Understand ellipsis as providing no default value (#26637)

Core type checking

  • Gate membership narrowing on __contains__ semantics (#25964)
  • Handle callable classes in solver (#26090)
  • Infer ModuleType.__doc__ as str in the presence of a docstring (#26505)
  • Infer metaclass-declared attributes on class instances (#26512)
  • Respect user stub overlays during module resolution (#26123)

Performance

  • Avoid allocating decorated parameter names (#26666)
  • Optimize TypeCollector (#26593)

Contributors

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the all-python group with 6 updates in the /agent directory:

| Package | From | To |
| --- | --- | --- |
| [boto3](https://github.com/boto/boto3) | `1.43.40` | `1.43.46` |
| [bedrock-agentcore](https://github.com/aws/bedrock-agentcore-sdk-python) | `1.17.0` | `1.18.0` |
| [claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-python) | `0.2.110` | `0.2.116` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.50.0` | `0.51.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.20` | `0.15.21` |
| [ty](https://github.com/astral-sh/ty) | `0.0.56` | `0.0.58` |



Updates `boto3` from 1.43.40 to 1.43.46
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.40...1.43.46)

Updates `bedrock-agentcore` from 1.17.0 to 1.18.0
- [Release notes](https://github.com/aws/bedrock-agentcore-sdk-python/releases)
- [Changelog](https://github.com/aws/bedrock-agentcore-sdk-python/blob/main/CHANGELOG.md)
- [Commits](aws/bedrock-agentcore-sdk-python@v1.17.0...v1.18.0)

Updates `claude-agent-sdk` from 0.2.110 to 0.2.116
- [Release notes](https://github.com/anthropics/claude-agent-sdk-python/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-agent-sdk-python@v0.2.110...v0.2.116)

Updates `uvicorn` from 0.50.0 to 0.51.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.50.0...0.51.0)

Updates `ruff` from 0.15.20 to 0.15.21
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.20...0.15.21)

Updates `ty` from 0.0.56 to 0.0.58
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.56...0.0.58)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: bedrock-agentcore
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: claude-agent-sdk
  dependency-version: 0.2.116
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: uvicorn
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: ruff
  dependency-version: 0.15.21
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: ty
  dependency-version: 0.0.58
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 18, 2026
@dependabot
dependabot Bot requested review from a team as code owners July 18, 2026 06:14
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 18, 2026

@scottschreckengaust scottschreckengaust left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: Request changes

The build (agentcore) check is red, and I reproduced the cause in the worktree: it is a real incompatibility introduced by the ty 0.0.56 → 0.0.58 bump in this PR, not a flake. A second, quieter problem: the claude-agent-sdk bump silently breaks the documented Dockerfile CLI lockstep invariant (#215). Both must be resolved before merge. The other four bumps (boto3, bedrock-agentcore, uvicorn, ruff) are clean.

Vision alignment

Routine dependency hygiene under the repo's own .github/dependabot.yml uv / all-python group — no tenet impact, no blast-radius change, control plane untouched. Governance is satisfied: the Dependabot config is the standing authorization, so the ADR-003 approved-issue gate does not apply, and dependabot/uv/agent/all-python-... is the standard bot branch format (de-facto-waived nit). The change belongs — but a green build is table stakes, and keeping the CLI lockstep intact is exactly the kind of "bounded, improvable control plane" hygiene the vision calls for.

Blocking issues

B1 — ty 0.0.58 bump breaks the typecheck; the required suppressions/fixes are not in this PR (agent/uv.lock:189-211, source unchanged).
Root cause, verified by running both pins against the same worktree source:

  • uvx ty@0.0.56 checkAll checks passed (exit 0) — this is main's pin.
  • uv run ty check (this PR's 0.0.58) → Found 9 diagnostics (exit 1) — identical to the CI log for run 29633654727.

So the bump alone flips the build red. ty 0.0.58 changed two behaviors:

  1. It now treats frozen-Pydantic (ConfigDict(frozen=True)) fields as read-only properties and statically errors on assignment. Every failing site is inside a deliberate with pytest.raises(ValidationError): block that mutates a frozen model to assert the runtime rejects it — a correct, intentional test pattern (agent/tests/test_attachments.py:46; agent/tests/test_models.py:30,63,140,170,416,447). The test code is correct at runtime; only the new checker rejects it.
  2. It tightened dict-literal inference: content_trust={...} literals are inferred as dict[str, str], no longer assignable to Mapping[str, Literal["trusted","untrusted-external","memory"]] | None (agent/tests/test_models.py:237,244).

Fix (pick one, in this PR so it lands atomically with the bump):

  • Add targeted # ty: ignore[invalid-assignment] to the seven frozen-mutation lines and # ty: ignore[invalid-argument-type] (or annotate the literal, e.g. content_trust: dict[str, ContentTrust] = {...} / cast(...)) to the two content_trust sites; or
  • Hold ty at 0.0.56 (exclude it from this group bump) until the test suppressions are prepared separately.
    Merging as-is lands a red build on main.

B2 — claude-agent-sdk 0.2.116 breaks the #215 CLI lockstep; Dockerfile npm pin and comment not updated (agent/pyproject.toml:19, agent/Dockerfile:49,56).
The pin comment states the SDK is "kept in lockstep with the npm CLI pin in the Dockerfile, #215." Per the upstream v0.2.116 release notes, claude-agent-sdk 0.2.116 bundles Claude CLI 2.1.207, but:

  • agent/Dockerfile:56 still installs @anthropic-ai/claude-code@2.1.191.
  • agent/Dockerfile:49 comment still says "Pinned 2.1.191 to match the CLI bundled by claude-agent-sdk 0.2.110."
  • agent/pyproject.toml:19 comment still reads .../releases/tag/v0.2.110 (bundles claude CLI 2.1.191...) while pinning 0.2.116 — stale and now wrong on both the version and the CLI number.
    This is precisely the divergence the invariant exists to prevent: the SDK's bundled subprocess CLI (2.1.207) and the globally-installed npm CLI (2.1.191) would drift apart. Fix: bump the Dockerfile npm pin to @anthropic-ai/claude-code@2.1.207 and update both comments — or, if the mismatch is deliberate, document why in the comment. Note Dependabot cannot cross-update the Dockerfile npm pin from a uv group, so this must be done by hand on the branch.

Non-blocking suggestions / nits

  • N1 — ty is unpinned in pyproject.toml (agent/pyproject.toml:88, bare "ty",) yet pinned in uv.lock. That is why Dependabot moved it as part of the group even though there is no explicit == spec to bump. Consider pinning ty==<version> like the other dev tools so pre-release type-checker churn cannot silently re-break the build on the next lock refresh.
  • N2 — Branch name dependabot/uv/agent/all-python-562714a858 does not match (feat|fix|chore|docs)/<issue>-desc; standard for Dependabot, de-facto waived.

Documentation

No docs/guides/design changes required for a dep bump, and the Starlight mirror is untouched (no docs/ edits) — mirror-sync N/A. However, B2 is partly a documentation-accuracy defect: the pyproject.toml:19 and Dockerfile:49 comments are now factually stale (v0.2.110 / CLI 2.1.191) and must be corrected alongside the code fix.

Tests & CI

  • No test logic changed; the two edited files are agent/pyproject.toml and agent/uv.lock only.
  • CI: build (agentcore) FAILURE (the //agent:typecheck step — B1). Secrets, deps, and workflow scan SUCCESS, Validate PR title SUCCESS, Dead-code detection SUCCESS (advisory), CodeQL NEUTRAL, auto-approve SKIPPED. mergeStateStatus: BLOCKED on the red check.
  • Bootstrap synth-coverage: not applicable — no CDK construct/stack/handler or CFN resource-type change.
  • Supply-chain integrity (checked directly on the lock diff): all 50 added url/sdist entries carry sha256: hashes; no hash-stripped or unpinned lines; no new name = package sections (no stealth transitive additions — versions/hashes updated in place). No OSV/malware advisory names uvicorn 0.51.0, boto3 1.43.46, or bedrock-agentcore 1.18.0 as affected. bedrock-agentcore 1.18.0 release notes show no breaking changes.

Review agents run

  • /security-review (supply-chain scope) — Ran. Its auto-collected git context resolved to the repo root (empty diff), so I performed the supply-chain assessment directly against the lock diff in the worktree: hash-pin integrity, no unexpected/transitive package additions, and OSV/malware cross-check of the six versions (esp. the poisoned-"fix" pattern from the astro 7.1.0 / MAL-2026-10726 incident). No supply-chain findings.
  • code-reviewer — Effectively performed by hand for a two-file manifest diff: the load-bearing issues are B1 (version delta vs. CI) and B2 (cross-file lockstep with the Dockerfile), both covered above.
  • silent-failure-hunter — Omitted: no error-handling/fallback code in the diff (manifests only).
  • type-design-analyzer — Omitted: no new/changed types (the ty diagnostics are checker-behavior changes against existing types, addressed in B1).
  • comment-analyzer — In scope and applied: found the stale claude-agent-sdk comment (folded into B2/N1).
  • pr-test-analyzer — Omitted: no test code added/changed; the failing tests are unchanged and correct at runtime (the checker regressed, not the tests).

Human heuristics

  • Proportionality — Pass. A grouped patch/minor dep bump; scope matches the problem.
  • Coherence — Concern. The claude-agent-sdk SDK pin and the Dockerfile npm CLI pin encode the same concept (which Claude CLI version runs) and must move together per #215; this PR moves one and not the other (agent/pyproject.toml:19 vs agent/Dockerfile:56).
  • Clarity — Concern. The pyproject.toml:19 comment now misstates both the SDK release tag (v0.2.110) and the bundled CLI (2.1.191) after the bump to 0.2.116 / CLI 2.1.207.
  • Appropriateness — Concern. Verified against real upstream behavior, not mocks: I reproduced the typecheck delta with uvx ty@0.0.56 vs 0.0.58 and confirmed the bundled-CLI number from the upstream release notes. As shipped, the change is not mergeable (red build) and not maintainable-as-is (silent lockstep drift).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant