Upgrade dependencies: 400 advisories down to 69 - #194
Merged
Merged
Conversation
Everything reachable without a major-version migration. 151 packages
moved; LangChain, chromadb and torch deliberately did not, and each has
a reason recorded below.
Removed black and isort. ruff replaced both -- the README and ci.yml
already said so -- but they stayed in the dev group, and black carried
three advisories for a tool nothing invoked.
Two caps added, each because the upgrade broke something real:
transformers <5. transformers 5 requires torch>=2.5 and, finding the
pinned 2.4.1+cpu, disables PyTorch rather than failing:
[transformers] Disabling PyTorch because PyTorch >= 2.5 is required
get_embedding("huggingfacelocal", ...) then raises `NameError: name
'nn' is not defined` from inside sentence-transformers. Caught by
building that provider, not by the test suite, which never touches it.
Lifting the cap means moving torch first, which carries platform
markers and a custom CPU wheel source and belongs in its own change.
posthog <6. chromadb 0.6 calls posthog.capture(user_id, name, props)
positionally; posthog 6 takes capture(event, **kwargs). Nothing
breaks, because telemetry is off anyway, but chromadb logs the
failure at ERROR on every startup and every collection open. An error
log nobody can act on is one people learn to skip.
chainlit 2.0.602 -> 2.11.0 changed three signatures we implement, all
runtime breaks rather than typing noise:
- oauth_callback is now async and takes the OIDC id_token as a fifth
argument. The old sync four-argument version would have failed at
login, not at import.
- set_chat_profiles passes the current user.
- StorageClient.upload_file gained content_disposition, which is
forwarded rather than dropped: it is what makes an attachment
download under its original filename.
Also pyasn1 ^0.5.1 -> ^0.6.4 (8 advisories) and lxml ^5 -> ^6 (2).
A newer typeshed made ast.Constant.value `str | bytes | int | ...`
rather than Any, which found a real latent bug in
test_alliance_columns: " ".join over a list that could hold non-strings.
Verified beyond the gates, since none of the above is caught by them:
the chainlit app imports and registers its hooks; the RAG chain answers
a real question through both invoke and ainvoke; the huggingfacelocal
embedding provider builds; BeautifulSoup still parses with lxml 6.
What remains, and why: torch (23) needs 2.13 and a new wheel source;
the LangChain family and chromadb need 1.x, which is the next piece of
work and now unblocked by the retriever rewrite.
The macos-15-intel leg of poetry-check failed:
Unable to find installation candidates for onnxruntime (1.29.0)
onnxruntime stopped publishing macosx x86_64 wheels after 1.23.2; 1.24
onwards ship arm64 and Linux only. It is not imported here -- it
arrives via chromadb -- so the constraint exists purely so that leg can
resolve.
Split by marker rather than capped outright, the way torch already is
in this file, so the platform that actually ships is not held back by a
legacy CI runner. The lock now carries both: 1.23.2 for darwin/x86_64
and 1.29.0 everywhere else.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Everything reachable without a major-version migration. 151 packages moved; LangChain, chromadb and torch deliberately did not, and each has a reason.
Removed: black and isort
ruff replaced both — the README and
ci.ymlalready said so — but they stayed in the dev group.blackcarried three advisories for a tool nothing invokes.Two caps added, each because the upgrade broke something real
transformers <5. transformers 5 requirestorch>=2.5and, finding the pinned2.4.1+cpu, disables PyTorch rather than failing:get_embedding("huggingfacelocal", ...)then raisesNameError: name 'nn' is not definedfrom inside sentence-transformers. Caught by building that provider, not by the suite — which never touches it. Lifting the cap means moving torch first: platform markers, custom CPU wheel source, its own change.posthog <6. chromadb 0.6 callsposthog.capture(user_id, name, props)positionally; posthog 6 takescapture(event, **kwargs). Nothing breaks — telemetry is off anyway — but chromadb logs the failure at ERROR on every startup and every collection open. An error log nobody can act on is one people learn to skip.chainlit 2.0.602 → 2.11.0 changed three signatures we implement
All runtime breaks, not typing noise:
oauth_callbackis now async and takes the OIDCid_tokenas a fifth argument. The old sync four-argument version would have failed at login, not at import.set_chat_profilespasses the current user.StorageClient.upload_filegainedcontent_disposition— forwarded, not dropped: it is what makes an attachment download under its original filename.Also
pyasn1^0.5.1 → ^0.6.4 (8 advisories),lxml^5 → ^6 (2).A newer typeshed made
ast.Constant.valuestr | bytes | int | ...rather thanAny, which found a real latent bug intest_alliance_columns:" ".joinover a list that could hold non-strings.Verified beyond the gates
None of the above is caught by ruff/mypy/pytest, so:
invokeandainvokehuggingfacelocalembedding provider builds186 tests pass, mypy clean, ruff clean.
What remains, and why
torch(23) needs 2.13 and a new wheel source. The LangChain family and chromadb need 1.x — that is the next piece of work, and it is now unblocked by the retriever rewrite, which is what the rewrite was for.