Skip to content

fix(deps): update dependencies for GA - #76

Merged
catinspace-au merged 1 commit into
mainfrom
fix/ga-deps
Oct 6, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/ga-deps

Conversation

@catinspace-au

@catinspace-au catinspace-au commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

GA dependency pass on scalo-py, ahead of the dfe-engine rebuild. Every group, extra and the lock moved to the newest release. The 7-day cooldown is waived for GA, so an exclude-newer-package table admits the 32 packages it was holding; every entry is a no-op once the span passes 2026-10-13, and the table goes then.

What reaches consumers (pyproject):

  • purgatory removed from the resilience and http extras. Nothing in scalo imports it; the breaker is scalo.resilience, which is stdlib-only. AUTO-WIRING.md, EXTRAS-FLAGS.md and architecture.md updated to match (architecture.md also wrongly said scalo-rs vendors purgatory; its breaker is tiered_sink::CircuitBreaker).
  • Runtime floors are unchanged. The lock now tests dynaconf 3.3.5, common-expression-language 0.10.0, typer 0.27.2, OpenTelemetry 1.45.0 / 0.66b0, prometheus-client 0.26.0, confluent-kafka 2.15.1.
  • uv_build floor 0.8.0 -> 0.12.23. dev and docs floors follow the lock (pytest 9.1.1, pytest-asyncio 1.4.0, mypy 2.4.0, tiktoken 0.14.0, sphinx 9.1.0, sphinx-autobuild 2025.8.25).

Fixes the new versions needed:

  • scalo.kafka.health reads its config with dict() instead of DataDict.to_dict(), deprecated in dynaconf 3.3.
  • The OTel reader tests read MeterProvider._metric_readers; opentelemetry-sdk 1.45 moved the list off SdkConfiguration.
  • Class-scoped scrubber fixtures are classmethods, as pytest 9.1 requires.

Lock and tooling only:

  • uv.lock: 94 packages move, 2 added, 3 dropped.
  • The boto3/botocore override was forcing botocore 1.43.108 past aiobotocore 3.9.2's declared <1.43.107. Dropped, with the protobuf / rich / importlib_metadata overrides that no longer changed anything. botocore resolves to 1.43.106.
  • Compose images pinned by digest: apache/kafka 4.3.1 in both compose files and the example README (the example was on 3.9.0, and boots healthy on 4.3.1), openbao 2.7.1, provectuslabs/kafka-ui v0.7.2.

Public-flip cleanup:

  • The private estate Kafka host is gone from the Kafka compose header, tests/conftest.py and both Kafka test files. The fixture tests use the neutral kafka.example.internal:30092 (.internal is reserved for private use, and a non-localhost name keeps the remote-versus-local meaning the tests assert). The integration docstring's SASL username and password are <username> / <password> now.
  • Still to do, outside this PR: bao.devex.hyperi.io sits in tests/.env.integration.example:49 (with a "devex environment" comment at :46) and tests/integration/test_secrets_cloud_providers.py:35. The old docstring password also stays in git history.
  • Examples: scalo >= 2.31.0 and current test deps.

Local hyperi-ci check: quality green, pip-audit clean. The test failures left are this host's, not the code: six GCP provider integration tests need a fresh gcloud ADC login, and the Dockerfile build test cannot fetch a ghcr.io token. Main's CI Test job is green with both in the suite.

Done when CI is green on this head and it merges with the release.

GA dependency pass over every group, extra and the lock. The 7-day cooldown is waived for this release: an exclude-newer-package table admits the newest of the 32 packages it was holding, and goes once the span passes it on 2026-10-13.

- uv.lock moves 94 packages, adds 2 and drops 3, including dynaconf 3.3.5, common-expression-language 0.10.0, typer 0.27.2, OpenTelemetry 1.45.0 / 0.66b0, prometheus-client 0.26.0, confluent-kafka 2.15.1, cryptography 50.0.2, aiohttp 3.14.4 and protobuf 7.36.2. Runtime floors are unchanged.
- Fixes the new versions asked for. kafka.health reads its cascade section with dict() instead of DataDict.to_dict(), which dynaconf 3.3 deprecates. The OTel reader tests read MeterProvider._metric_readers, where opentelemetry-sdk 1.45 keeps the list. Class-scoped scrubber fixtures are classmethods, as pytest 9.1 requires.
- purgatory leaves the resilience and http extras. Nothing in scalo imports it; the circuit breaker is scalo.resilience, which is stdlib-only. The extras docs say so now.
- The boto3/botocore override forced botocore 1.43.108 past aiobotocore 3.9.2's declared <1.43.107. Dropped, with the protobuf, rich and importlib_metadata overrides that no longer changed the resolution. botocore now resolves to 1.43.106.
- dev and docs floors follow the lock: pytest 9.1.1, pytest-asyncio 1.4.0, mypy 2.4.0, tiktoken 0.14.0, sphinx 9.1.0, sphinx-autobuild 2025.8.25, fastapi 0.142.2 in the dev group. uv_build floor 0.12.23.
- Examples: scalo 2.31.0, pytest 9.1.1, pytest-asyncio 1.4.0, fastapi 0.142.2, uvicorn 0.54.0, confluent-kafka 2.15.1.
- Compose images pinned by digest: apache/kafka 4.3.1 in both files and the example README (the example was on 3.9.0), openbao 2.7.1, provectuslabs/kafka-ui v0.7.2.
- No environment-specific host left in the Kafka compose header, conftest or the Kafka tests: the fixture tests use kafka.example.internal:30092 for the remote broker, and the integration docstring's SASL credentials are placeholders.
@catinspace-au
catinspace-au merged commit 8012067 into main Oct 6, 2026
17 checks passed
@catinspace-au
catinspace-au deleted the fix/ga-deps branch October 6, 2026 01:34
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Released in v2.31.1 -- https://github.com/hyperi-io/scalo-py/releases/tag/v2.31.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant