Skip to content

chore(deps): pin anyio to 4.15.1 across all lockfiles - #125

Merged
Diego Colombo (colombod) merged 1 commit into
mainfrom
chore/anyio-4.15.1-lockfiles
Sep 19, 2026
Merged

Diego Colombo (colombod) merged 1 commit into
mainfrom
chore/anyio-4.15.1-lockfiles

Conversation

@colombod

Copy link
Copy Markdown
Collaborator

Summary

Finishes the anyio dependency update that Dependabot started, and converges every
lockfile in the repo on a single version. Dependabot had bumped only two of the six
lockfiles that resolve anyio (#120, #121), leaving four different versions pinned
across the repo — 4.12.1, 4.13.0, 4.14.2, 4.15.1 — so the module test jobs were
each resolving a different anyio than the root suite. This pins all six at 4.15.1
(current latest on PyPI).

anyio is transitive only: it enters via httpx 0.28.1 in every lockfile that has
it. No source file in this repo imports anyio, and no pyproject.toml declares it, so
no declared constraint moved — this is a pure lock refresh.

Builds on #120 and #121 (both merged).

Versions before → after

Lockfile anyio before after
uv.lock 4.14.2 4.15.1
modules/hook-context-intelligence/uv.lock 4.12.1 4.15.1
modules/tool-context-intelligence-query/uv.lock 4.14.2 4.15.1
modules/tool-context-intelligence-recover/uv.lock 4.15.1 4.15.1 (already current, unchanged)
modules/tool-context-intelligence-upload/uv.lock 4.13.0 4.15.1
modules/tool-server-data-ops/uv.lock 4.14.2 4.15.1

typing-extensions 4.15.0 → 4.16.0 rides along in four of the five changed lockfiles —
it is anyio's own dependency and uv re-resolved it as part of the upgrade. Disclosed
rather than hidden: it is the only package other than anyio in the diff.

Scope / guardrails

  • Lock-only. The diff is 5 uv.lock files, 32 insertions / 32 deletions. No
    pyproject.toml, no source, no tests, no workflows, no bundle files.
  • Verified mechanically: every changed line in the diff is a version / sdist /
    url line inside the anyio or typing-extensions package block. Filtering the diff
    for any line not belonging to those two blocks returns 0 lines.
  • Produced with uv lock --upgrade-package anyio==4.15.1 per directory — the surgical
    form, not uv lock --upgrade, so no unrelated package was allowed to drift.
  • uv lock --check reports LOCK CONSISTENT in all six directories.
  • The write-side hook fan-out is untouched (fanout.py / _DestinationDispatcher /
    logging_handler). This change is neither read-side nor write-side — it touches no
    Python at all.
  • bundle.dot / bundle.png were regenerated as a side effect of running
    scripts/validate-full.sh and deliberately reverted — bundle structure did not
    change, and the validator itself reported bundle_dot_status: fresh.

Verification

  • Module tests pass — all 7 modules, run the way CI runs them
    (uv sync --frozen then PYTHONPATH=<repo root> uv run --frozen pytest tests/ -q --ignore=tests/dtu):

    hook-context-intelligence              700 passed
    hook-server-data-ops-lockdown           28 passed
    tool-context-intelligence-query        195 passed
    tool-context-intelligence-recover       29 passed
    tool-context-intelligence-transcript    20 passed
    tool-context-intelligence-upload       553 passed, 1 failed  (pre-existing, see below)
    tool-server-data-ops                    65 passed
    
  • Top-level tests pass — tests/ — 856 passed in 15.97s

  • ruff check + ruff format --check clean — All checks passed! /
    176 files already formatted

  • pyright clean — 0 errors, 0 warnings, 0 informations

  • Full bundle validation — ran scripts/validate-full.sh, which reported
    validation_mode: full_no_build on this machine, not full. hatchling /
    pip wheel were absent from the throwaway venv, so the package build checks were
    skipped. Everything the run did execute is green: all hygiene / structure /
    placement / freshness gates pass, bundle_dot_status: fresh, and the lone mode
    unadvertised_but_referenced ERROR is re-confirmed in-run as the documented FALSE
    POSITIVE (per AGENTS.md — not "fixed"). Box left unchecked because the template
    asks for validation_mode: full and I got full_no_build
    — flagging rather than
    claiming it. Given the diff contains no Python and no bundle file, the skipped
    build checks have nothing in this change to act on.

The one failing test — pre-existing, environment-specific, not caused by this change

tests/test_ground_truth_parity.py::test_runtime_sweep_data_parity fails with
json.decoder.JSONDecodeError: Unterminated string starting at: line 1 column 358.

That test sweeps the local machine's session corpus (PROJECTS_ROOT) and
pytest.skips when there is no corpus — which is why it is green in CI and red here: one
session in my local ~/.amplifier/projects has a truncated JSONL line.

Proven pre-existing rather than asserted: I stashed this branch's changes and ran the same
test on the unmodified base — identical failure, same exception, same offset:

=== single test ON BASE (no anyio change) ===
json.decoder.JSONDecodeError: Unterminated string starting at: line 1 column 358 (char 357)
FAILED tests/test_ground_truth_parity.py::test_runtime_sweep_data_parity
1 failed in 108.60s

Real evidence on seams (not mock-only)

  • N/A — no seam crossed. This change contains no Python, no tool/skill/config
    wiring, no client↔server boundary change, and no blob handling. It is six resolver
    lockfiles pinning a transitive HTTP-stack dependency. The AGENTS.md gate that
    applies here is "pure-internal → units + validate-full.sh", not the DTU gate;
    there is no agent, skill, mode, tool, networking or auth edit to exercise.

One honest note on the runtime evidence available locally: the module test venvs install
the shared bundle from @main at the git rev pinned in each module lockfile, so a local
--frozen run without PYTHONPATH set fails to import CIClientError. That is the
documented convention this repo already relies on (CI sets PYTHONPATH: ${{ github.workspace }}
for exactly this reason); the counts above were produced with PYTHONPATH set, matching
CI. Not a finding — recorded so the numbers are reproducible.

Docs & diagrams

  • bundle.dot / bundle.png — N/A — bundle structure unchanged. Validator reports
    bundle_dot_status: fresh; the incidental regeneration was reverted (see
    Scope / guardrails).
  • README / SKILLs / agent files — N/A — no tool or skill contract changed.
  • Convention files — N/A — no lasting lesson surfaced. The PYTHONPATH convention
    this run leaned on is already documented in AGENTS.md and in ci.yml's comments.

Notes / follow-ups

  • modules/tool-context-intelligence-recover/uv.lock was already at 4.15.1 and is
    untouched by this PR — it is in the table above only so the "all six converge" claim can
    be checked against the diff without confusion about why only five files changed.
  • Dependabot only watches github-actions here. .github/dependabot.yml declares a
    single package-ecosystem: "github-actions" entry with no uv ecosystem — yet the
    anyio PRs (chore(deps): bump anyio from 4.14.0 to 4.14.2 in /modules/tool-context-intelligence-query #120, chore(deps): bump anyio from 4.13.0 to 4.14.2 #121) arrived as dependabot/uv/... branches. Worth reconciling:
    either the config is not the whole story for this repo, or the uv updates come from
    somewhere else. If uv updates are wanted on a schedule, adding explicit uv entries
    (root plus each modules/* directory) would stop this drift from re-accumulating —
    which is exactly the drift this PR is cleaning up by hand.

Completes Dependabot's anyio upgrade. Dependabot merged PRs #120 and #121,
updating 2 of 6 lockfiles but leaving four different anyio versions pinned
(4.12.1 / 4.13.0 / 4.14.2 / 4.15.1). This converges all to 4.15.1, the
current latest on PyPI.

anyio is a transitive-only dependency (via httpx 0.28.1); no source files
import it and no pyproject.toml declares it. typing-extensions 4.15.0 -> 4.16.0
rides along as anyio's own dependency. Generated with
`uv lock --upgrade-package anyio==4.15.1` per directory.

Generated with Amplifier

Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
@colombod
Diego Colombo (colombod) merged commit 9a8dc2d into main Sep 19, 2026
12 checks passed
@colombod
Diego Colombo (colombod) deleted the chore/anyio-4.15.1-lockfiles branch September 19, 2026 00:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant