Batch the open Dependabot updates - #688
Merged
Merged
Conversation
Bumps the python-minor-patch group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` | | [langchain-core](https://github.com/langchain-ai/langchain) | `1.5.1` | `1.6.3` | | [langchain-openai](https://github.com/langchain-ai/langchain) | `1.4.1` | `1.6.2` | | [nltk](https://github.com/nltk/nltk) | `3.10.0` | `3.10.3` | | [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.66.1` | `2.69.1` | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [langfuse](https://github.com/langfuse/langfuse) | `4.14.1` | `4.15.2` | | [opentelemetry-instrumentation-anthropic](https://github.com/traceloop/openllmetry) | `0.62.1` | `0.62.3` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.0` | `0.16.7` | Updates `python-dotenv` from 1.2.2 to 1.2.3 - [Release notes](https://github.com/theskumar/python-dotenv/releases) - [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md) - [Commits](theskumar/python-dotenv@v1.2.2...v1.2.3) Updates `langchain-core` from 1.5.1 to 1.6.3 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](langchain-ai/langchain@langchain-core==1.5.1...langchain-core==1.6.3) Updates `langchain-openai` from 1.4.1 to 1.6.2 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](langchain-ai/langchain@langchain-openai==1.4.1...langchain-openai==1.6.2) Updates `nltk` from 3.10.0 to 3.10.3 - [Release notes](https://github.com/nltk/nltk/releases) - [Changelog](https://github.com/nltk/nltk/blob/develop/ChangeLog) - [Commits](nltk/nltk@v3.10.0...v3.10.3) Updates `sentry-sdk` from 2.66.1 to 2.69.1 - [Release notes](https://github.com/getsentry/sentry-python/releases) - [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md) - [Commits](getsentry/sentry-python@2.66.1...2.69.1) Updates `psycopg2-binary` from 2.9.12 to 2.9.13 - [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS) - [Commits](psycopg/psycopg2@2.9.12...2.9.13) Updates `langfuse` from 4.14.1 to 4.15.2 - [Release notes](https://github.com/langfuse/langfuse/releases) - [Commits](https://github.com/langfuse/langfuse/commits) Updates `opentelemetry-instrumentation-anthropic` from 0.62.1 to 0.62.3 - [Release notes](https://github.com/traceloop/openllmetry/releases) - [Changelog](https://github.com/traceloop/openllmetry/blob/main/CHANGELOG.md) - [Commits](traceloop/openllmetry@0.62.1...0.62.3) Updates `ruff` from 0.16.0 to 0.16.7 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.0...0.16.7) --- updated-dependencies: - dependency-name: python-dotenv dependency-version: 1.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: langchain-core dependency-version: 1.6.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: langchain-openai dependency-version: 1.6.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: nltk dependency-version: 3.10.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: sentry-sdk dependency-version: 2.69.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: psycopg2-binary dependency-version: 2.9.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: langfuse dependency-version: 4.15.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: opentelemetry-instrumentation-anthropic dependency-version: 0.62.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: ruff dependency-version: 0.16.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [docker/login-action](https://github.com/docker/login-action) from 4 to 4.5.2. - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@v4...v4.5.2) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: 4.5.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
hanna-paasivirta
marked this pull request as ready for review
September 17, 2026 18:33
Contributor
Author
|
@josephjclark I have tested these, am I ok to merge these into your release branch? |
Collaborator
|
Perfect, I was going to exaclty this. Thanks! |
josephjclark
added a commit
that referenced
this pull request
Sep 23, 2026
* embed_docsite: rewrite to use git clone (#685) * embed_docsite: download docsite via git clone instead of GitHub contents API (#627) * feat: download docsite via git clone instead of the GitHub contents API * perf: clone the docsite blobless and sparse * fix: raise ApolloError on empty docs checkout and skip unreadable files * refactor: drop private underscores and memoize the docs sync with functools.cache * refactor: fold docs_repo into github_utils with public API at the top * test: assert corpus invariants instead of exact docsite file counts * changeset --------- Co-authored-by: Isaac <ong.izo.zh@gmail.com> * Batch the open Dependabot updates (#688) * Bump the python-minor-patch group across 1 directory with 9 updates Bumps the python-minor-patch group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` | | [langchain-core](https://github.com/langchain-ai/langchain) | `1.5.1` | `1.6.3` | | [langchain-openai](https://github.com/langchain-ai/langchain) | `1.4.1` | `1.6.2` | | [nltk](https://github.com/nltk/nltk) | `3.10.0` | `3.10.3` | | [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.66.1` | `2.69.1` | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [langfuse](https://github.com/langfuse/langfuse) | `4.14.1` | `4.15.2` | | [opentelemetry-instrumentation-anthropic](https://github.com/traceloop/openllmetry) | `0.62.1` | `0.62.3` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.0` | `0.16.7` | Updates `python-dotenv` from 1.2.2 to 1.2.3 - [Release notes](https://github.com/theskumar/python-dotenv/releases) - [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md) - [Commits](theskumar/python-dotenv@v1.2.2...v1.2.3) Updates `langchain-core` from 1.5.1 to 1.6.3 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](langchain-ai/langchain@langchain-core==1.5.1...langchain-core==1.6.3) Updates `langchain-openai` from 1.4.1 to 1.6.2 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](langchain-ai/langchain@langchain-openai==1.4.1...langchain-openai==1.6.2) Updates `nltk` from 3.10.0 to 3.10.3 - [Release notes](https://github.com/nltk/nltk/releases) - [Changelog](https://github.com/nltk/nltk/blob/develop/ChangeLog) - [Commits](nltk/nltk@v3.10.0...v3.10.3) Updates `sentry-sdk` from 2.66.1 to 2.69.1 - [Release notes](https://github.com/getsentry/sentry-python/releases) - [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md) - [Commits](getsentry/sentry-python@2.66.1...2.69.1) Updates `psycopg2-binary` from 2.9.12 to 2.9.13 - [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS) - [Commits](psycopg/psycopg2@2.9.12...2.9.13) Updates `langfuse` from 4.14.1 to 4.15.2 - [Release notes](https://github.com/langfuse/langfuse/releases) - [Commits](https://github.com/langfuse/langfuse/commits) Updates `opentelemetry-instrumentation-anthropic` from 0.62.1 to 0.62.3 - [Release notes](https://github.com/traceloop/openllmetry/releases) - [Changelog](https://github.com/traceloop/openllmetry/blob/main/CHANGELOG.md) - [Commits](traceloop/openllmetry@0.62.1...0.62.3) Updates `ruff` from 0.16.0 to 0.16.7 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.0...0.16.7) --- updated-dependencies: - dependency-name: python-dotenv dependency-version: 1.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: langchain-core dependency-version: 1.6.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: langchain-openai dependency-version: 1.6.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: nltk dependency-version: 3.10.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: sentry-sdk dependency-version: 2.69.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: psycopg2-binary dependency-version: 2.9.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: langfuse dependency-version: 4.15.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: opentelemetry-instrumentation-anthropic dependency-version: 0.62.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: ruff dependency-version: 0.16.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com> * Bump docker/login-action from 4 to 4.5.2 Bumps [docker/login-action](https://github.com/docker/login-action) from 4 to 4.5.2. - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@v4...v4.5.2) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: 4.5.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> * Bump aiohttp to 3.14.3 * Add changeset --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Add postgres support to docsite services (#687) * feat: parameterize chunk size in DocsiteProcessor * fix: revert unauthorized nltk import and _accumulate_chunks changes to match brief spec * feat: rewrite DocsiteIndexer for Postgres batch lifecycle * feat: rewire main() to the Postgres batch lifecycle * feat: rewrite DocsiteSearch for Postgres hybrid search, preserve legacy Pinecone path * fix: order keyword CTE by rank before limiting in hybrid search * feat: backend-flagged docsite search with Postgres shadow-mode comparison * fix: correct shadow-mode docstrings and test import placement * feat: add offline golden-query recall/latency eval script * fix: remove orphaned threshold arg and revert unrequested noqa suppressions * fix: Restore back threshold to 0.8 * fix: apply the 0.7 relevance gate to both search_documentation backends * refactor: remove shadow-mode Postgres comparison from job_chat * fix: cast hybrid RRF score to float8 so results stay JSON-serializable * fix: use semantic strategy on Postgres so the relevance gate survives cutover * feat: add per-request backend selection to search_docsite * feat: restore Pinecone write path behind embed_docsite target param * fix: add type annotations to embed_docsite's new helper functions * feat: add versioned migration runner for the docsite schema * feat: report backend agreement in the offline docsite eval * docs: correct stale LegacyPineconeDocsiteSearch docstring * refactor: revert unrelated churn in docsite_processor * refactor: revert import and formatting churn in docsite consumers Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * refactor: drop type annotations from internal helpers * refactor: extract shared docsite backend resolver * docs: focus docsite comments on invariants * fix: run docsite migrations from the indexer, not every connection * Remove openai key test * fix: return a clear 503 when the docsite schema is not initialised * fix: bind docsite embeddings as pgvector Vector * fix: commit before toggling autocommit, and mark failed batches * test: add Postgres docsite roundtrip integration suite * fix: don't let a pruning failure invalidate the batch just promoted * fix: change integration test to use 127.0.0.1 instead of localhost to speedup * fix: update env example to support docsite backend and postgres test url for integration testing * fix: run_eval compares postgres semantic, and loads dotenv * Add results from running golden queries * fix: import ordering and streamline comments * lint: fix B008 and B904 linting issues * lint: fix B905, RUF059, edited docs in helpers * fix: lint F401 and docsite name accepting in pinecone * feat: add results for each query for run_eval.py * refactor: use a timestamped migration filename * test: expand golden query set to 30 categorised queries * feat: report eval recall per query category * feat: resolve docsite eval batches by chunk size * feat: compare semantic and hybrid across chunk sizes in the eval * docs: update comments in roundtrip test * changeset * remove unused tests * move test into legacy --------- Co-authored-by: IZO-Ong <ong.izo.zh@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * versions --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Isaac <ong.izo.zh@gmail.com> Co-authored-by: Hanna Paasivirta <hanna@openfn.org> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Short Description
Batches the open Dependabot PRs into one branch to test once.
Implementation Details
Cut from
release/nextand targets it.python-minor-patchgroup (9 packages), cherry-picked as-is.@v4→@4.5.2, cherry-picked as-is.poetry update aiohttprather than cherry-picked, since that branch was 83 commits behind and merging a stalepoetry.lockisn't worth trusting. Only the aiohttp block and its hashes change.All four can be closed once this lands.