Skip to content

Upgrade dependencies: 400 advisories down to 69 - #194

Merged
adamjohnwright merged 2 commits into
mainfrom
deps/safe-upgrades
Sep 9, 2026
Merged

adamjohnwright merged 2 commits into
mainfrom
deps/safe-upgrades

Conversation

@adamjohnwright

Copy link
Copy Markdown
Contributor

Everything reachable without a major-version migration. 151 packages moved; LangChain, chromadb and torch deliberately did not, and each has a reason.

advisories
before 400 across 43 packages
after 69 across 17 packages

Removed: black and isort

ruff replaced both — the README and ci.yml already said so — but they stayed in the dev group. black carried three advisories for a tool nothing invokes.

Two caps added, each because the upgrade broke something real

transformers <5. transformers 5 requires torch>=2.5 and, finding the pinned 2.4.1+cpu, disables PyTorch rather than failing:

[transformers] Disabling PyTorch because PyTorch >= 2.5 is required but found 2.4.1+cpu

get_embedding("huggingfacelocal", ...) then raises NameError: name 'nn' is not defined from inside sentence-transformers. Caught by building that provider, not by the suite — which never touches it. Lifting the cap means moving torch first: platform markers, custom CPU wheel source, its own change.

posthog <6. chromadb 0.6 calls posthog.capture(user_id, name, props) positionally; posthog 6 takes capture(event, **kwargs). Nothing breaks — telemetry is off anyway — but chromadb logs the failure at ERROR on every startup and every collection open. An error log nobody can act on is one people learn to skip.

chainlit 2.0.602 → 2.11.0 changed three signatures we implement

All runtime breaks, not typing noise:

  • oauth_callback is now async and takes the OIDC id_token as a fifth argument. The old sync four-argument version would have failed at login, not at import.
  • set_chat_profiles passes the current user.
  • StorageClient.upload_file gained content_disposition — forwarded, not dropped: it is what makes an attachment download under its original filename.

Also

pyasn1 ^0.5.1 → ^0.6.4 (8 advisories), lxml ^5 → ^6 (2).

A newer typeshed made ast.Constant.value str | bytes | int | ... rather than Any, which found a real latent bug in test_alliance_columns: " ".join over a list that could hold non-strings.

Verified beyond the gates

None of the above is caught by ruff/mypy/pytest, so:

  • the chainlit app imports and registers its hooks
  • the RAG chain answers a real question through both invoke and ainvoke
  • the huggingfacelocal embedding provider builds
  • BeautifulSoup still parses with lxml 6

186 tests pass, mypy clean, ruff clean.

What remains, and why

torch (23) needs 2.13 and a new wheel source. The LangChain family and chromadb need 1.x — that is the next piece of work, and it is now unblocked by the retriever rewrite, which is what the rewrite was for.

Everything reachable without a major-version migration. 151 packages
moved; LangChain, chromadb and torch deliberately did not, and each has
a reason recorded below.

Removed black and isort. ruff replaced both -- the README and ci.yml
already said so -- but they stayed in the dev group, and black carried
three advisories for a tool nothing invoked.

Two caps added, each because the upgrade broke something real:

  transformers <5. transformers 5 requires torch>=2.5 and, finding the
  pinned 2.4.1+cpu, disables PyTorch rather than failing:
    [transformers] Disabling PyTorch because PyTorch >= 2.5 is required
  get_embedding("huggingfacelocal", ...) then raises `NameError: name
  'nn' is not defined` from inside sentence-transformers. Caught by
  building that provider, not by the test suite, which never touches it.
  Lifting the cap means moving torch first, which carries platform
  markers and a custom CPU wheel source and belongs in its own change.

  posthog <6. chromadb 0.6 calls posthog.capture(user_id, name, props)
  positionally; posthog 6 takes capture(event, **kwargs). Nothing
  breaks, because telemetry is off anyway, but chromadb logs the
  failure at ERROR on every startup and every collection open. An error
  log nobody can act on is one people learn to skip.

chainlit 2.0.602 -> 2.11.0 changed three signatures we implement, all
runtime breaks rather than typing noise:

  - oauth_callback is now async and takes the OIDC id_token as a fifth
    argument. The old sync four-argument version would have failed at
    login, not at import.
  - set_chat_profiles passes the current user.
  - StorageClient.upload_file gained content_disposition, which is
    forwarded rather than dropped: it is what makes an attachment
    download under its original filename.

Also pyasn1 ^0.5.1 -> ^0.6.4 (8 advisories) and lxml ^5 -> ^6 (2).

A newer typeshed made ast.Constant.value `str | bytes | int | ...`
rather than Any, which found a real latent bug in
test_alliance_columns: " ".join over a list that could hold non-strings.

Verified beyond the gates, since none of the above is caught by them:
the chainlit app imports and registers its hooks; the RAG chain answers
a real question through both invoke and ainvoke; the huggingfacelocal
embedding provider builds; BeautifulSoup still parses with lxml 6.

What remains, and why: torch (23) needs 2.13 and a new wheel source;
the LangChain family and chromadb need 1.x, which is the next piece of
work and now unblocked by the retriever rewrite.
The macos-15-intel leg of poetry-check failed:

    Unable to find installation candidates for onnxruntime (1.29.0)

onnxruntime stopped publishing macosx x86_64 wheels after 1.23.2; 1.24
onwards ship arm64 and Linux only. It is not imported here -- it
arrives via chromadb -- so the constraint exists purely so that leg can
resolve.

Split by marker rather than capped outright, the way torch already is
in this file, so the platform that actually ships is not held back by a
legacy CI runner. The lock now carries both: 1.23.2 for darwin/x86_64
and 1.29.0 everywhere else.
@adamjohnwright
adamjohnwright merged commit c8043b5 into main Sep 9, 2026
10 checks passed
@adamjohnwright
adamjohnwright deleted the deps/safe-upgrades branch September 9, 2026 17:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant