Skip to content

chore(deps): consolidate core Dependabot GitHub Actions bumps - #1271

Draft
cursor[bot] wants to merge 9 commits into
mainfrom
automation/dependabot-core-2026-09-29
Draft

cursor[bot] wants to merge 9 commits into
mainfrom
automation/dependabot-core-2026-09-29

Conversation

@cursor

@cursor cursor Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Summary

Consolidates 5 open, green, CLEAN Dependabot PRs that bump pinned-SHA GitHub Actions versions in .github/workflows/ (outside envs/) into a single mergeable PR:

All 5 are simple SHA-pin bumps to workflow-referenced actions, verified by diffing each PR and confirming the merged branch diff against main is exactly the union of the 5 individual diffs (no extra churn). Each PR individually shows mergeStateStatus: CLEAN and all CI checks green (test 3.11/3.12, lint, validate-env-locks, runtime validation, doc build, Bugbot) at time of writing.

Excluded from this core bucket: #1222 (fastmcp requirement widen <4.0.0,>=3.0.0 → >=3.0.0,<5.0.0, touches root pyproject.toml). This is intentionally left out because it currently fails test (3.11) and test (3.12) — FastMCP 4.x changed ctx.set_state to be request-scoped, breaking OpenEnv's MCP session-persistence tests (tests/core/test_production_mode_routes.py::TestMCPSessionTransportPersistence). Per repo policy ("everything that goes on main in src/ is of the highest standard"), a failing core dependency bump should not be folded into an easy-to-merge aggregate. A human maintainer should either drive the FastMCP 4 migration or close #1222.

No open Dependabot PRs currently touch envs/, so no envs aggregate PR was opened this run (would be empty).

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation
  • New environment
  • Refactoring (dependency/CI maintenance)

Alignment Checklist

  • I have read .claude/docs/PRINCIPLES.md and this PR aligns with our principles
  • I have checked .claude/docs/INVARIANTS.md and no invariants are violated
  • CI on this branch (and on each source PR individually) is green

RFC Status

  • Not required (bug fix, docs, minor refactoring) — CI-only pinned-SHA version bumps

Test Plan

This branch is a clean merge of the 5 individual Dependabot branches on top of main; the combined diff is exactly the union of the 5 PR diffs (verified via git diff origin/main..HEAD). Each source PR already has full green CI (test (3.11), test (3.12), lint, validate-env-locks, Runtime validation / Linux Docker, doc builds, Cursor Bugbot). CI on this aggregate PR will re-verify.

Maintainer action needed

Once this PR is merged, please close the following superseded single PRs (this automation cannot close PRs itself — gh access is read-only and no close-capable tool is configured):

Leave #1222 (FastMCP) open separately — it is excluded from this aggregate because it fails core tests; it needs either a code migration for FastMCP 4's session model or a maintainer decision to close it.

Claude Code Review

N/A

Open in Web View Automation 

dependabot Bot and others added 9 commits September 29, 2026 02:53
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.2 to 7.0.1.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4.6.2...043fb46)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 7.6.0 to 10.2.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@37802ad...c18668a)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…_documentation.yml

Bumps [huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml](https://github.com/huggingface/doc-builder) from 9f9bb430a712b5650d0e43e510656098ecdd75d4 to ef23fb82532fe347298732dc81dacad2f8eff961.
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md)
- [Commits](huggingface/doc-builder@9f9bb43...ef23fb8)

---
updated-dependencies:
- dependency-name: huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml
  dependency-version: ef23fb82532fe347298732dc81dacad2f8eff961
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…n_documentation.yml

Bumps [huggingface/doc-builder/.github/workflows/build_main_documentation.yml](https://github.com/huggingface/doc-builder) from 9f9bb430a712b5650d0e43e510656098ecdd75d4 to ef23fb82532fe347298732dc81dacad2f8eff961.
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md)
- [Commits](huggingface/doc-builder@9f9bb43...ef23fb8)

---
updated-dependencies:
- dependency-name: huggingface/doc-builder/.github/workflows/build_main_documentation.yml
  dependency-version: ef23fb82532fe347298732dc81dacad2f8eff961
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…documentation.yml

Bumps [huggingface/doc-builder/.github/workflows/build_pr_documentation.yml](https://github.com/huggingface/doc-builder) from 9f9bb430a712b5650d0e43e510656098ecdd75d4 to ef23fb82532fe347298732dc81dacad2f8eff961.
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md)
- [Commits](huggingface/doc-builder@9f9bb43...ef23fb8)

---
updated-dependencies:
- dependency-name: huggingface/doc-builder/.github/workflows/build_pr_documentation.yml
  dependency-version: ef23fb82532fe347298732dc81dacad2f8eff961
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…-sh/setup-uv-10.2.0' into automation/dependabot-core-2026-09-29

Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
…gface/doc-builder/dot-github/workflows/upload_pr_documentation.yml-ef23fb82532fe347298732dc81dacad2f8eff961' into automation/dependabot-core-2026-09-29

Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
…gface/doc-builder/dot-github/workflows/build_main_documentation.yml-ef23fb82532fe347298732dc81dacad2f8eff961' into automation/dependabot-core-2026-09-29

Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
…gface/doc-builder/dot-github/workflows/build_pr_documentation.yml-ef23fb82532fe347298732dc81dacad2f8eff961' into automation/dependabot-core-2026-09-29

Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant