chore(deps): pin anyio to 4.15.1 across all lockfiles - #125
Merged
Merged
Conversation
Completes Dependabot's anyio upgrade. Dependabot merged PRs #120 and #121, updating 2 of 6 lockfiles but leaving four different anyio versions pinned (4.12.1 / 4.13.0 / 4.14.2 / 4.15.1). This converges all to 4.15.1, the current latest on PyPI. anyio is a transitive-only dependency (via httpx 0.28.1); no source files import it and no pyproject.toml declares it. typing-extensions 4.15.0 -> 4.16.0 rides along as anyio's own dependency. Generated with `uv lock --upgrade-package anyio==4.15.1` per directory. Generated with Amplifier Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
Diego Colombo (colombod)
force-pushed
the
chore/anyio-4.15.1-lockfiles
branch
from
September 18, 2026 23:46
c904078 to
d236632
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Finishes the
anyiodependency update that Dependabot started, and converges everylockfile in the repo on a single version. Dependabot had bumped only two of the six
lockfiles that resolve
anyio(#120, #121), leaving four different versions pinnedacross the repo —
4.12.1,4.13.0,4.14.2,4.15.1— so the module test jobs wereeach resolving a different
anyiothan the root suite. This pins all six at4.15.1(current latest on PyPI).
anyiois transitive only: it enters viahttpx 0.28.1in every lockfile that hasit. No source file in this repo imports
anyio, and nopyproject.tomldeclares it, sono declared constraint moved — this is a pure lock refresh.
Builds on #120 and #121 (both merged).
Versions before → after
uv.lockmodules/hook-context-intelligence/uv.lockmodules/tool-context-intelligence-query/uv.lockmodules/tool-context-intelligence-recover/uv.lockmodules/tool-context-intelligence-upload/uv.lockmodules/tool-server-data-ops/uv.locktyping-extensions 4.15.0 → 4.16.0rides along in four of the five changed lockfiles —it is
anyio's own dependency anduvre-resolved it as part of the upgrade. Disclosedrather than hidden: it is the only package other than
anyioin the diff.Scope / guardrails
uv.lockfiles, 32 insertions / 32 deletions. Nopyproject.toml, no source, no tests, no workflows, no bundle files.version/sdist/urlline inside theanyioortyping-extensionspackage block. Filtering the difffor any line not belonging to those two blocks returns 0 lines.
uv lock --upgrade-package anyio==4.15.1per directory — the surgicalform, not
uv lock --upgrade, so no unrelated package was allowed to drift.uv lock --checkreports LOCK CONSISTENT in all six directories.fanout.py/_DestinationDispatcher/logging_handler). This change is neither read-side nor write-side — it touches noPython at all.
bundle.dot/bundle.pngwere regenerated as a side effect of runningscripts/validate-full.shand deliberately reverted — bundle structure did notchange, and the validator itself reported
bundle_dot_status: fresh.Verification
Module tests pass — all 7 modules, run the way CI runs them
(
uv sync --frozenthenPYTHONPATH=<repo root> uv run --frozen pytest tests/ -q --ignore=tests/dtu):Top-level tests pass —
tests/— 856 passed in 15.97sruff check+ruff format --checkclean —All checks passed!/176 files already formattedpyrightclean —0 errors, 0 warnings, 0 informationsFull bundle validation — ran
scripts/validate-full.sh, which reportedvalidation_mode: full_no_buildon this machine, notfull.hatchling/pip wheelwere absent from the throwaway venv, so the package build checks wereskipped. Everything the run did execute is green: all hygiene / structure /
placement / freshness gates pass,
bundle_dot_status: fresh, and the lone modeunadvertised_but_referencedERROR is re-confirmed in-run as the documented FALSEPOSITIVE (per AGENTS.md — not "fixed"). Box left unchecked because the template
asks for
validation_mode: fulland I gotfull_no_build— flagging rather thanclaiming it. Given the diff contains no Python and no bundle file, the skipped
build checks have nothing in this change to act on.
The one failing test — pre-existing, environment-specific, not caused by this change
tests/test_ground_truth_parity.py::test_runtime_sweep_data_parityfails withjson.decoder.JSONDecodeError: Unterminated string starting at: line 1 column 358.That test sweeps the local machine's session corpus (
PROJECTS_ROOT) andpytest.skips when there is no corpus — which is why it is green in CI and red here: onesession in my local
~/.amplifier/projectshas a truncated JSONL line.Proven pre-existing rather than asserted: I stashed this branch's changes and ran the same
test on the unmodified base — identical failure, same exception, same offset:
Real evidence on seams (not mock-only)
N/A — no seam crossed.This change contains no Python, no tool/skill/configwiring, no client↔server boundary change, and no blob handling. It is six resolver
lockfiles pinning a transitive HTTP-stack dependency. The AGENTS.md gate that
applies here is "pure-internal → units +
validate-full.sh", not the DTU gate;there is no agent, skill, mode, tool, networking or auth edit to exercise.
One honest note on the runtime evidence available locally: the module test venvs install
the shared bundle from
@mainat the git rev pinned in each module lockfile, so a local--frozenrun withoutPYTHONPATHset fails to importCIClientError. That is thedocumented convention this repo already relies on (CI sets
PYTHONPATH: ${{ github.workspace }}for exactly this reason); the counts above were produced with
PYTHONPATHset, matchingCI. Not a finding — recorded so the numbers are reproducible.
Docs & diagrams
bundle.dot/bundle.png—N/A — bundle structure unchanged.Validator reportsbundle_dot_status: fresh; the incidental regeneration was reverted (seeScope / guardrails).
N/A — no tool or skill contract changed.N/A — no lasting lesson surfaced.ThePYTHONPATHconventionthis run leaned on is already documented in AGENTS.md and in
ci.yml's comments.Notes / follow-ups
modules/tool-context-intelligence-recover/uv.lockwas already at 4.15.1 and isuntouched by this PR — it is in the table above only so the "all six converge" claim can
be checked against the diff without confusion about why only five files changed.
github-actionshere..github/dependabot.ymldeclares asingle
package-ecosystem: "github-actions"entry with nouvecosystem — yet theanyioPRs (chore(deps): bump anyio from 4.14.0 to 4.14.2 in /modules/tool-context-intelligence-query #120, chore(deps): bump anyio from 4.13.0 to 4.14.2 #121) arrived asdependabot/uv/...branches. Worth reconciling:either the config is not the whole story for this repo, or the uv updates come from
somewhere else. If uv updates are wanted on a schedule, adding explicit
uventries(root plus each
modules/*directory) would stop this drift from re-accumulating —which is exactly the drift this PR is cleaning up by hand.