Skip to content

Commit 6d7c76a

Browse files
authored
Merge pull request #1311 from tisnik/lcore-1326-update-dependencies
LCORE-1326: Update dependencies + CVE fix
2 parents 29ba660 + 9cb80c6 commit 6d7c76a

6 files changed

Lines changed: 166 additions & 141 deletions

.tekton/lightspeed-stack-pull-request.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ spec:
5454
],
5555
"requirements_build_files": ["requirements-build.txt"],
5656
"binary": {
57-
"packages": "aiohappyeyeballs,aiohttp,aiosignal,aiosqlite,annotated-doc,annotated-types,anyio,asyncpg,attrs,cffi,chevron,click,cryptography,datasets,dill,distro,dnspython,docstring-parser,durationpy,einops,email-validator,faiss-cpu,fire,frozenlist,fsspec,google-cloud-core,google-cloud-resource-manager,google-crc32c,google-genai,google-resumable-media,grpc-google-iam-v1,grpcio,grpcio-status,h11,hf-xet,httpcore,httpx,httpx-sse,idna,importlib-metadata,jinja2,jiter,joblib,jsonschema,jsonschema-specifications,kubernetes,lxml,markdown-it-py,mcp,mdurl,mpmath,multidict,networkx,numpy,oauthlib,packaging,pandas,peft,pillow,prometheus-client,prompt-toolkit,propcache,psycopg2-binary,pyarrow,pyasn1,pyasn1-modules,pycparser,pydantic,pydantic-core,pygments,python-dateutil,python-multipart,pyyaml,referencing,requests,requests-oauthlib,rpds-py,rsa,safetensors,scikit-learn,scipy,setuptools,six,sniffio,sqlalchemy,starlette,sympy,termcolor,threadpoolctl,tiktoken,tokenizers,torch,tornado,tqdm,transformers,tree-sitter,triton,typing-extensions,typing-inspection,tzdata,urllib3,websocket-client,websockets,wrapt,xxhash,yarl,zipp,uv,pip,maturin",
57+
"packages": "aiohappyeyeballs,aiohttp,aiosignal,aiosqlite,annotated-doc,annotated-types,anyio,asyncpg,attrs,build,cffi,chevron,click,cryptography,datasets,dill,distro,dnspython,docstring-parser,durationpy,einops,email-validator,faiss-cpu,fire,frozenlist,fsspec,google-cloud-core,google-cloud-resource-manager,google-crc32c,google-genai,google-resumable-media,grpc-google-iam-v1,grpcio,grpcio-status,h11,hf-xet,httpcore,httpx,httpx-sse,idna,importlib-metadata,jinja2,jiter,joblib,jsonschema,jsonschema-specifications,kubernetes,lxml,markdown-it-py,mcp,mdurl,mpmath,multidict,networkx,numpy,oauthlib,packaging,pandas,peft,pillow,prometheus-client,prompt-toolkit,propcache,psycopg2-binary,pyarrow,pyasn1,pyasn1-modules,pycparser,pydantic,pydantic-core,pygments,pyproject-hooks,python-dateutil,python-multipart,pyyaml,referencing,requests,requests-oauthlib,rpds-py,rsa,safetensors,scikit-learn,scipy,setuptools,six,sniffio,sqlalchemy,starlette,sympy,termcolor,threadpoolctl,tiktoken,tokenizers,torch,tqdm,transformers,tree-sitter,triton,typing-extensions,typing-inspection,tzdata,urllib3,websocket-client,websockets,wheel,wrapt,xxhash,yarl,zipp,uv,pip,maturin",
5858
"os": "linux",
5959
"arch": "x86_64,aarch64",
6060
"py_version": 312

.tekton/lightspeed-stack-push.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ spec:
4646
],
4747
"requirements_build_files": ["requirements-build.txt"],
4848
"binary": {
49-
"packages": "aiohappyeyeballs,aiohttp,aiosignal,aiosqlite,annotated-doc,annotated-types,anyio,asyncpg,attrs,cffi,chevron,click,cryptography,datasets,dill,distro,dnspython,docstring-parser,durationpy,einops,email-validator,faiss-cpu,fire,frozenlist,fsspec,google-cloud-core,google-cloud-resource-manager,google-crc32c,google-genai,google-resumable-media,grpc-google-iam-v1,grpcio,grpcio-status,h11,hf-xet,httpcore,httpx,httpx-sse,idna,importlib-metadata,jinja2,jiter,joblib,jsonschema,jsonschema-specifications,kubernetes,lxml,markdown-it-py,mcp,mdurl,mpmath,multidict,networkx,numpy,oauthlib,packaging,pandas,peft,pillow,prometheus-client,prompt-toolkit,propcache,psycopg2-binary,pyarrow,pyasn1,pyasn1-modules,pycparser,pydantic,pydantic-core,pygments,python-dateutil,python-multipart,pyyaml,referencing,requests,requests-oauthlib,rpds-py,rsa,safetensors,scikit-learn,scipy,setuptools,six,sniffio,sqlalchemy,starlette,sympy,termcolor,threadpoolctl,tiktoken,tokenizers,torch,tornado,tqdm,transformers,tree-sitter,triton,typing-extensions,typing-inspection,tzdata,urllib3,websocket-client,websockets,wrapt,xxhash,yarl,zipp,uv,pip,maturin",
49+
"packages": "aiohappyeyeballs,aiohttp,aiosignal,aiosqlite,annotated-doc,annotated-types,anyio,asyncpg,attrs,build,cffi,chevron,click,cryptography,datasets,dill,distro,dnspython,docstring-parser,durationpy,einops,email-validator,faiss-cpu,fire,frozenlist,fsspec,google-cloud-core,google-cloud-resource-manager,google-crc32c,google-genai,google-resumable-media,grpc-google-iam-v1,grpcio,grpcio-status,h11,hf-xet,httpcore,httpx,httpx-sse,idna,importlib-metadata,jinja2,jiter,joblib,jsonschema,jsonschema-specifications,kubernetes,lxml,markdown-it-py,mcp,mdurl,mpmath,multidict,networkx,numpy,oauthlib,packaging,pandas,peft,pillow,prometheus-client,prompt-toolkit,propcache,psycopg2-binary,pyarrow,pyasn1,pyasn1-modules,pycparser,pydantic,pydantic-core,pygments,pyproject-hooks,python-dateutil,python-multipart,pyyaml,referencing,requests,requests-oauthlib,rpds-py,rsa,safetensors,scikit-learn,scipy,setuptools,six,sniffio,sqlalchemy,starlette,sympy,termcolor,threadpoolctl,tiktoken,tokenizers,torch,tqdm,transformers,tree-sitter,triton,typing-extensions,typing-inspection,tzdata,urllib3,websocket-client,websockets,wheel,wrapt,xxhash,yarl,zipp,uv,pip,maturin",
5050
"os": "linux",
5151
"arch": "x86_64,aarch64",
5252
"py_version": 312

requirements-build.txt

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@ flit-core==3.12.0
1515
# jinja2
1616
# packaging
1717
# pathspec
18+
# pip
1819
# wheel
1920
hatch-fancy-pypi-readme==25.1.0
2021
# via
@@ -55,7 +56,7 @@ jinja2==3.1.6
5556
# via uv-dynamic-versioning
5657
markupsafe==3.0.3
5758
# via jinja2
58-
maturin==1.12.6
59+
maturin==1.10.2
5960
# via fastuuid
6061
packaging==26.0
6162
# via
@@ -72,8 +73,10 @@ poetry-core==2.3.1
7273
# via
7374
# dunamai
7475
# litellm
76+
# pybuild-deps
7577
# rich
7678
# tomlkit
79+
# xdg
7780
semantic-version==2.10.0
7881
# via setuptools-rust
7982
setuptools-rust==1.12.0
@@ -83,6 +86,7 @@ setuptools-scm==9.2.2
8386
# hatch-vcs
8487
# llama-stack
8588
# llama-stack-api
89+
# pip-tools
8690
# pluggy
8791
# setuptools-rust
8892
# tenacity
@@ -101,6 +105,7 @@ wheel==0.46.3
101105
# oci
102106
# oracledb
103107
# sentence-transformers
108+
# tornado
104109

105110
# The following packages are considered to be unsafe in a requirements file:
106111
setuptools==82.0.0
@@ -126,6 +131,7 @@ setuptools==82.0.1
126131
# oci
127132
# oracledb
128133
# pathspec
134+
# pip-tools
129135
# pluggy
130136
# polyleven
131137
# proto-plus
@@ -140,5 +146,6 @@ setuptools==82.0.1
140146
# setuptools-scm
141147
# sse-starlette
142148
# tenacity
149+
# tornado
143150
# trl
144151
# trove-classifiers

requirements.hashes.source.txt

Lines changed: 57 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -29,34 +29,34 @@ cachetools==7.0.5 \
2929
certifi==2026.2.25 \
3030
--hash=sha256:027692e4402ad994f1c42e52a4997a9763c646b73e4096e4d5d6db8af1d6f0fa \
3131
--hash=sha256:e887ab5cee78ea814d3472169153c2d12cd43b14bd03329a39a9c6e2e80bfba7
32-
chardet==7.0.1 \
33-
--hash=sha256:11f51985946b49739968b6dc2fa70e7d8f490bb15574377c5ee114f33d19ef7e \
34-
--hash=sha256:1566d0f91990b8f33b53836391d557f779584bd48beabf90efbf7a6efa89179e \
35-
--hash=sha256:169951fa88d449e72e0c6194cec1c5e405fd36a6cfbe74c7dab5494cc35f1700 \
36-
--hash=sha256:26186f0ea03c4c1f9be20c088b127c71b0e9d487676930fab77625ddec2a4ef2 \
37-
--hash=sha256:265cb3b5dafc0411c0949800a0692f07e986fb663b6ae1ecfba32ad193a55a03 \
38-
--hash=sha256:302798e1e62008ca34a216dd04ecc5e240993b2090628e2a35d4c0754313ea9a \
39-
--hash=sha256:3355a3c8453d673e7c1664fdd24a0c6ef39964c3d41befc4849250f7eb1de3b5 \
40-
--hash=sha256:33f4132f9781302beff34713fe6c990badd009aa8ea730611aef0931b27f1541 \
41-
--hash=sha256:44011e3b4fd4a8a15bc94736717414b7ec82880066fb22d9f476c68a4ded2647 \
42-
--hash=sha256:4af34cf0652a9da44720540c97f11e30781a77900c89547b311984a7272b33f7 \
43-
--hash=sha256:5333f9967863ea7d8642df0e00cf4d33e8ed7e99fe7b6464b40ba969a2808544 \
44-
--hash=sha256:54e448fab0c11b27bb908ea0218e2094578c583d05faa5f65b91fa6ccfa45570 \
45-
--hash=sha256:63bc210ce73f8a1b87430b949f84d086cb326d67eb259305862e7c8861b73374 \
46-
--hash=sha256:67fe3f453416ed9343057dcf06583b36aae6d8bdb013370b3ff46bc37b7e30ac \
47-
--hash=sha256:69708a504a43464b60ea16d031250b58206969c9bbd6851266e2f39afef53168 \
48-
--hash=sha256:6f907962b18df78d5ca87a7484e4034354408d2c97cec6f53634b0ea0424c594 \
49-
--hash=sha256:6fce895c12c5495bb598e59ae3cd89306969b4464ec7b6dd609b9c86e3397fe3 \
50-
--hash=sha256:8714f0013c208452a98e23595d99cef53c5364565454425f431446eb586e2591 \
51-
--hash=sha256:88793aeebb28a5296eea9bdd9b5e74ee4e3582766a6a2cb7f39e4761a96fdd55 \
52-
--hash=sha256:8a8d87853c7f191029933307094a8896b087c2c436703281cb289a22aa4ae8bd \
53-
--hash=sha256:9e827211249d8e3cacc1adf6950a7a8cf56920e5e303e56dcab827b71c03df33 \
54-
--hash=sha256:c12abc65830068ad05bd257fb953aaaf63a551446688e03e145522086be5738c \
55-
--hash=sha256:c3f59dc3e148b54813ec5c7b4b2e025d37f5dc221ee28a06d1a62f169cfaedf5 \
56-
--hash=sha256:dd6db7505556ae8f9e2a3bf6d689c2b86aa6b459cf39552645d2c4d3fdbf489c \
57-
--hash=sha256:e51e1ff2c51b2d622d97c9737bd5ee9d9b9038f05b7dd8f9ea10b9e2d9674c24 \
58-
--hash=sha256:f661edbfa77b8683a503043ddc9b9fe9036cf28af13064200e11fa1844ded79c \
59-
--hash=sha256:fb14755377d8de845c69378bbaedc0e35109c21a43824450524fd9c3178792d5
32+
chardet==7.1.0 \
33+
--hash=sha256:00c3182f739ae7715641e8c08e0ee8ae21b5db6402b883264aa04511edf428b9 \
34+
--hash=sha256:18afc27681cd9f583fac47282179f8b73f37b1cab171a528e8af89e7e4562b32 \
35+
--hash=sha256:1a3c22672c9502af99e0433b47421d0d72c8803efce2cd4a91a3ae1ab5972243 \
36+
--hash=sha256:20b73403b7a21487e31b2810ea9d7182ce5e301a8ebe847b49d91ec6022e214a \
37+
--hash=sha256:38be4c07e016dac37fb6060094f3a720200e3e49dc14f55924a1c230eeffa59f \
38+
--hash=sha256:43c1e3cba6c41d8958ee4acdab94c151dbe256d7ef8df4ae032dc62a892f294f \
39+
--hash=sha256:49b5edd762751735704d1fec38665ee219da28c66f2a4921d615b12be389735b \
40+
--hash=sha256:5d86d349f768e6d35f6804013f6643d880ec877b94c453fa40a3fd10d16ddb48 \
41+
--hash=sha256:619d7ef3187ff1691525a7fdbe8c30f5a519885e1de82f6f57e26a29866bf11b \
42+
--hash=sha256:6f806f325825325e0682226269a2a4859993344cccca14f2463855d4f5a93272 \
43+
--hash=sha256:70adef4a036d39d9b5f6c2702f773118a9985c0dff23b650e1045f20e33c9467 \
44+
--hash=sha256:7f677725333bf53f84b7f57458f44669a8a5eb2ac4092ac699cdfa9b1af08a5f \
45+
--hash=sha256:8e067ee79709ccf9caa5732419df2dbef476bd9b9658ffc929d45cf13fc91ed7 \
46+
--hash=sha256:8f47bc4accac17bd9accbb4acc1d563acc024a783806c0a43c3a583f5285690b \
47+
--hash=sha256:96e7fe0770cd77361bec21a1dd8524e77aaa567577fa8372368d5fa8dd0ef00b \
48+
--hash=sha256:97cdd7a016fbb451a4dc26b3b1173960b3c0071bbe46a46d6b70027a517170ff \
49+
--hash=sha256:a02197831a4304eed360559e0ffc58deccc9cdda9f9315c6e7ad978f7d8617d3 \
50+
--hash=sha256:a6492bebaba8882afb3e14c786fb69ed767326b6f514b8e093dcdf6e2a094d33 \
51+
--hash=sha256:b951107b254cdc766e52f4b8339dcfa97c7b45ca9f5509075308db2497e7f3af \
52+
--hash=sha256:bacc8f862998c59e9ee7fe4960538300d1cc3fe2c293b9cc99bbbc7bf3bedf51 \
53+
--hash=sha256:bbd4fccf1cf6d92fdd75a1827a478672abb5685e61e92ce863d9380b18cb813f \
54+
--hash=sha256:c35d17822fc94467b7951adebd897cb01c0e37ac694be18d2cbd2b676d61df4f \
55+
--hash=sha256:cc8c7520a9736da766f5794bbabb1c6cdfe446676429a5cf691af878631a80bf \
56+
--hash=sha256:dff284d0661563e82d235f79f1d410c526b15ef8d50adc0446cba8162db68d22 \
57+
--hash=sha256:e096d9c211050fff40e22748e1d09d0cec8348fc13ee6e2e0a1da079345b8a86 \
58+
--hash=sha256:eb2a9b4052be006b87a985dbdbb00ab35b4b1b66d2751b0ee12680f8f4e90406 \
59+
--hash=sha256:fdfc42dfc44ccd569b84fe6a1fdea1df66dc0c48461bc3899dea5efea8d507f6
6060
charset-normalizer==3.4.5 \
6161
--hash=sha256:014837af6fabf57121b6254fa8ade10dceabc3528b27b721a64bbc7b8b1d4eb4 \
6262
--hash=sha256:01a1ed54b953303ca7e310fafe0fe347aab348bd81834a0bcd602eb538f89d66 \
@@ -259,18 +259,18 @@ fastuuid==0.14.0 \
259259
--hash=sha256:ec27778c6ca3393ef662e2762dba8af13f4ec1aaa32d08d77f71f2a70ae9feb8 \
260260
--hash=sha256:f54d5b36c56a2d5e1a31e73b950b28a0d83eb0c37b91d10408875a5a29494bad \
261261
--hash=sha256:f74631b8322d2780ebcf2d2d75d58045c3e9378625ec51865fe0b5620800c39d
262-
filelock==3.25.1 \
263-
--hash=sha256:18972df45473c4aa2c7921b609ee9ca4925910cc3a0fb226c96b92fc224ef7bf \
264-
--hash=sha256:b9a2e977f794ef94d77cdf7d27129ac648a61f585bff3ca24630c1629f701aa9
262+
filelock==3.25.2 \
263+
--hash=sha256:b64ece2b38f4ca29dd3e810287aa8c48182bbecd1ae6e9ae126c9b35f1382694 \
264+
--hash=sha256:ca8afb0da15f229774c9ad1b455ed96e85a81373065fb10446672f64444ddf70
265265
google-api-core==2.30.0 \
266266
--hash=sha256:02edfa9fab31e17fc0befb5f161b3bf93c9096d99aed584625f38065c511ad9b \
267267
--hash=sha256:80be49ee937ff9aba0fd79a6eddfde35fe658b9953ab9b79c57dd7061afa8df5
268268
google-auth==2.49.0 \
269269
--hash=sha256:9cc2d9259d3700d7a257681f81052db6737495a1a46b610597f4b8bafe5286ae \
270270
--hash=sha256:f893ef7307f19cf53700b7e2f61b5a6affe3aa0edf9943b13788920ab92d8d87
271-
google-cloud-aiplatform==1.140.0 \
272-
--hash=sha256:e94493a2682b9d17efa7146a53bb3665bf1595c3394fd3d0f45d18f71623fddc \
273-
--hash=sha256:ea7eb1870b4cf600f8c2472102e21c3a1bcaf723d6e49f00ed51bc6b88d54fff
271+
google-cloud-aiplatform==1.141.0 \
272+
--hash=sha256:6bd25b4d514c40b8181ca703e1b313ad6d0454ab8006fc9907fb3e9f672f31d1 \
273+
--hash=sha256:e3b1cdb28865dd862aac9c685dfc5ac076488705aba0a5354016efadcddd59c6
274274
google-cloud-bigquery==3.40.1 \
275275
--hash=sha256:75afcfb6e007238fe1deefb2182105249321145ff921784fe7b1de2b4ba24506 \
276276
--hash=sha256:9082a6b8193aba87bed6a2c79cf1152b524c99bb7e7ac33a785e333c09eac868
@@ -542,6 +542,12 @@ oracledb==3.4.2 \
542542
--hash=sha256:f8ea989965a4f636a309444bd696ab877bba373d5d67bf744785f9bd8c560865 \
543543
--hash=sha256:f93cae08e8ed20f2d5b777a8602a71f9418389c661d2c937e84d94863e7e7011 \
544544
--hash=sha256:ff3c89cecea62af8ca02aa33cab0f2edc0214c747eac7d3364ed6b2640cb55e4
545+
pip==26.0.1 \
546+
--hash=sha256:bdb1b08f4274833d62c1aa29e20907365a2ceb950410df15fc9521bad440122b \
547+
--hash=sha256:c4037d8a277c89b320abe636d59f91e6d0922d08a05b60e85e53b296613346d8
548+
pip-tools==7.5.3 \
549+
--hash=sha256:3aac0c473240ae90db7213c033401f345b05197293ccbdd2704e52e7a783785e \
550+
--hash=sha256:8fa364779ebc010cbfe17cb9de404457ac733e100840423f28f6955de7742d41
545551
polyleven==0.11.0 \
546552
--hash=sha256:046e90c02c5b8dae2ab71c4fb33772bd6f27b7883b05e2117573bf478b5ced44 \
547553
--hash=sha256:05207bb66da15a2dc5c530e2f5cb5f0588d0a7e79b3bd542965f9e06e3fb14fe \
@@ -654,6 +660,9 @@ psutil==7.2.2 \
654660
pyaml==26.2.1 \
655661
--hash=sha256:489dd82997235d4cfcf76a6287fce2f075487d77a6567c271e8d790583690c68 \
656662
--hash=sha256:6261c2f0a2f33245286c794ad6ec234be33a73d2b05427079fd343e2812a87cf
663+
pybuild-deps==0.5.0 \
664+
--hash=sha256:4cc5b8634b5aac371755a7ff33da1f47cf528938e419c1fb943cc95a8c3337e7 \
665+
--hash=sha256:fa488db42cc53f93926ccb55ef56fb300fbd7769d31a56ebc7f83f11e28aeac8
657666
pycryptodomex==3.23.0 \
658667
--hash=sha256:02d87b80778c171445d67e23d1caef279bf4b25c3597050ccd2e13970b57fd51 \
659668
--hash=sha256:06698f957fe1ab229a99ba2defeeae1c09af185baa909a31a5d1f9d42b1aaed6 \
@@ -844,6 +853,17 @@ sse-starlette==3.3.2 \
844853
tenacity==9.1.4 \
845854
--hash=sha256:6095a360c919085f28c6527de529e76a06ad89b23659fa881ae0649b867a9d55 \
846855
--hash=sha256:adb31d4c263f2bd041081ab33b498309a57c77f9acf2db65aadf0898179cf93a
856+
tornado==6.5.5 \
857+
--hash=sha256:192b8f3ea91bd7f1f50c06955416ed76c6b72f96779b962f07f911b91e8d30e9 \
858+
--hash=sha256:2c9a876e094109333f888539ddb2de4361743e5d21eece20688e3e351e4990a6 \
859+
--hash=sha256:36abed1754faeb80fbd6e64db2758091e1320f6bba74a4cf8c09cd18ccce8aca \
860+
--hash=sha256:3f54aa540bdbfee7b9eb268ead60e7d199de5021facd276819c193c0fb28ea4e \
861+
--hash=sha256:435319e9e340276428bbdb4e7fa732c2d399386d1de5686cb331ec8eee754f07 \
862+
--hash=sha256:487dc9cc380e29f58c7ab88f9e27cdeef04b2140862e5076a66fb6bb68bb1bfa \
863+
--hash=sha256:6443a794ba961a9f619b1ae926a2e900ac20c34483eea67be4ed8f1e58d3ef7b \
864+
--hash=sha256:65a7f1d46d4bb41df1ac99f5fcb685fb25c7e61613742d5108b010975a9a6521 \
865+
--hash=sha256:dd3eafaaeec1c7f2f8fdcd5f964e8907ad788fe8a5a32c4426fbbdda621223b7 \
866+
--hash=sha256:e74c92e8e65086b338fd56333fb9a68b9f6f2fe7ad532645a290a464bcf46be5
847867
trl==0.29.0 \
848868
--hash=sha256:7d49cb1526c55cc1d798d921d9d91bb84a35ad5c645d6277441ffb7a30a233aa \
849869
--hash=sha256:b1c9f756a3d73c5457b7025b0c7bb9792873a87a2f3841cccf4f9d4f0e9ab273
@@ -853,3 +873,6 @@ uvicorn==0.41.0 \
853873
wcwidth==0.6.0 \
854874
--hash=sha256:1a3a1e510b553315f8e146c54764f4fb6264ffad731b3d78088cdb1478ffbdad \
855875
--hash=sha256:cdc4e4262d6ef9a1a57e018384cbeb1208d8abbc64176027e2c2455c81313159
876+
xdg==6.0.0 \
877+
--hash=sha256:24278094f2d45e846d1eb28a2ebb92d7b67fc0cab5249ee3ce88c95f649a1c92 \
878+
--hash=sha256:df3510755b4395157fc04fc3b02467c777f3b3ca383257397f09ab0d4c16f936

0 commit comments

Comments
 (0)