-
Notifications
You must be signed in to change notification settings - Fork 834
chore(deps-dev): bump the gha group across 1 directory with 8 updates #3334
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
chore(deps-dev): bump the gha group across 1 directory with 8 updates #3334
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Comment |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Important
Looks good to me! 👍
Reviewed everything up to 39ca809 in 2 minutes and 35 seconds. Click for details.
- Reviewed
26lines of code in1files - Skipped
1files when reviewing. - Skipped posting
4draft comments. View those below. - Modify your settings and rules to customize what types of comments Ellipsis leaves. And don't forget to react with 👍 or 👎 to teach Ellipsis.
1. packages/opentelemetry-instrumentation-openai/pyproject.toml:34
- Draft comment:
flake8 updated to 7.3.0 looks good. Consider using a caret operator (e.g.^7.3.0) for consistency with other dependencies to allow patch updates automatically. - Reason this comment was not posted:
Decided after close inspection that this draft comment was likely wrong and/or not actionable: usefulness confidence = 0% vs. threshold = 50% While the comment is technically correct about inconsistency in version specification, it's about dependency management which is explicitly mentioned in the rules as something we should not comment on. The rules state "Do NOT comment on dependency changes, library versions that you don't recognize, or anything else related to dependencies." The suggestion would improve consistency in the codebase. Maybe dependency format standardization is important enough to warrant an exception to the rule? No, the rules are clear about not commenting on dependencies. This is exactly the kind of comment the rules are trying to prevent. The comment should be deleted as it violates the explicit rule against commenting on dependency-related matters.
2. packages/opentelemetry-instrumentation-openai/pyproject.toml:39
- Draft comment:
The vcrpy dependency now uses a range (>=6.0.1,<8.0.0) which allows 6.x and 7.x versions. Given the release notes mention upgrading from 6.0.2 to 7.0.0, please verify if the lower bound should be raised to 7.0.0 to enforce use of the new major release. - Reason this comment was not posted:
Decided after close inspection that this draft comment was likely wrong and/or not actionable: usefulness confidence = 0% vs. threshold = 50% This is a dependency version suggestion. According to the rules, we should NOT comment on dependency changes or library versions we don't recognize. The comment is speculative ("please verify if...") and asks the author to check something. Both of these are explicitly against the rules. The comment might be pointing out a legitimate compatibility issue between major versions that could cause problems. Even if there are compatibility concerns, the rules explicitly state not to comment on dependency changes. The author likely has their reasons for allowing both 6.x and 7.x versions. Delete this comment as it violates multiple rules: it's about dependencies, it's speculative, and it asks the author to verify something.
3. packages/opentelemetry-instrumentation-openai/pyproject.toml:41
- Draft comment:
openai has been updated to 1.101.0. Please ensure that any breaking changes in OpenAI’s API are properly handled by the instrumentation. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%<= threshold50%This comment is about a dependency update and asks the PR author to ensure that breaking changes are handled. This violates the rule against commenting on dependency changes and asking the author to ensure behavior is intended.
4. packages/opentelemetry-instrumentation-openai/pyproject.toml:43
- Draft comment:
pytest-asyncio now uses the range ">=0.23.7,<1.2.0", which allows versions below 1.2.0, including 1.1.0. Note that the release notes mention updating from 0.23.8; consider if the lower bound should be bumped to 0.23.8 for consistency. - Reason this comment was not posted:
Decided after close inspection that this draft comment was likely wrong and/or not actionable: usefulness confidence = 10% vs. threshold = 50% According to the rules, we should NOT comment on dependency changes or library versions we don't recognize. The comment is purely about dependency versioning. There's no clear evidence that this change is required for functionality. It's a minor version bump suggestion that doesn't clearly impact code behavior. The comment might be pointing out a legitimate compatibility issue between versions. Maybe there's a known bug in version 0.23.7 that could cause problems. Without clear evidence of a critical issue, this falls under the rule about not commenting on dependency changes. The suggestion is speculative and not clearly necessary. Delete the comment as it violates the rule about not commenting on dependency changes and versions.
Workflow ID: wflow_Rh3aHAo89FIPXGyu
You can customize by changing your verbosity settings, reacting with 👍 or 👎, replying to comments, or adding code review rules.
0d246a1 to
d7a60b7
Compare
d54a85f to
49e77d5
Compare
fa59214 to
46486d3
Compare
46486d3 to
5bc2aca
Compare
5bc2aca to
755aa34
Compare
30d0544 to
fa2bc68
Compare
fa2bc68 to
5cc764d
Compare
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
Bumps the gha group with 8 updates in the /packages/opentelemetry-instrumentation-openai directory: | Package | From | To | | --- | --- | --- | | [flake8](https://github.com/pycqa/flake8) | `7.0.0` | `7.3.0` | | [pytest](https://github.com/pytest-dev/pytest) | `8.3.3` | `8.4.1` | | [pytest-sugar](https://github.com/Teemu/pytest-sugar) | `1.0.0` | `1.1.0` | | [vcrpy](https://github.com/kevin1024/vcrpy) | `6.0.2` | `7.0.0` | | [pytest-recording](https://github.com/kiwicom/pytest-recording) | `0.13.2` | `0.13.4` | | [openai](https://github.com/openai/openai-python) | `1.99.7` | `1.101.0` | | [pytest-asyncio](https://github.com/pytest-dev/pytest-asyncio) | `0.23.8` | `1.1.0` | | [requests](https://github.com/psf/requests) | `2.32.4` | `2.32.5` | Updates `flake8` from 7.0.0 to 7.3.0 - [Commits](PyCQA/flake8@7.0.0...7.3.0) Updates `pytest` from 8.3.3 to 8.4.1 - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst) - [Commits](pytest-dev/pytest@8.3.3...8.4.1) Updates `pytest-sugar` from 1.0.0 to 1.1.0 - [Release notes](https://github.com/Teemu/pytest-sugar/releases) - [Changelog](https://github.com/Teemu/pytest-sugar/blob/main/CHANGES.rst) - [Commits](Teemu/pytest-sugar@v1.0.0...v1.1.0) Updates `vcrpy` from 6.0.2 to 7.0.0 - [Release notes](https://github.com/kevin1024/vcrpy/releases) - [Changelog](https://github.com/kevin1024/vcrpy/blob/master/docs/changelog.rst) - [Commits](kevin1024/vcrpy@v6.0.2...v7.0.0) Updates `pytest-recording` from 0.13.2 to 0.13.4 - [Release notes](https://github.com/kiwicom/pytest-recording/releases) - [Changelog](https://github.com/kiwicom/pytest-recording/blob/master/docs/changelog.rst) - [Commits](kiwicom/pytest-recording@v0.13.2...v0.13.4) Updates `openai` from 1.99.7 to 1.101.0 - [Release notes](https://github.com/openai/openai-python/releases) - [Changelog](https://github.com/openai/openai-python/blob/main/CHANGELOG.md) - [Commits](openai/openai-python@v1.99.7...v1.101.0) Updates `pytest-asyncio` from 0.23.8 to 1.1.0 - [Release notes](https://github.com/pytest-dev/pytest-asyncio/releases) - [Commits](pytest-dev/pytest-asyncio@v0.23.8...v1.1.0) Updates `requests` from 2.32.4 to 2.32.5 - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.32.4...v2.32.5) --- updated-dependencies: - dependency-name: flake8 dependency-version: 7.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: gha - dependency-name: pytest dependency-version: 8.4.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: gha - dependency-name: pytest-sugar dependency-version: 1.1.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: gha - dependency-name: vcrpy dependency-version: 7.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: gha - dependency-name: pytest-recording dependency-version: 0.13.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: gha - dependency-name: openai dependency-version: 1.101.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: gha - dependency-name: pytest-asyncio dependency-version: 1.1.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: gha - dependency-name: requests dependency-version: 2.32.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: gha ... Signed-off-by: dependabot[bot] <[email protected]>
5cc764d to
28c7d9d
Compare
Bumps the gha group with 8 updates in the /packages/opentelemetry-instrumentation-openai directory:
7.0.07.3.08.3.38.4.11.0.01.1.06.0.27.0.00.13.20.13.41.99.71.101.00.23.81.1.02.32.42.32.5Updates
flake8from 7.0.0 to 7.3.0Commits
c48217eRelease 7.3.0f9e0f33Merge pull request #1986 from PyCQA/document-f5426bcdb62document F54270a15b8Merge pull request #1985 from PyCQA/upgrade-deps4941a3eupgrade pyflakes / pycodestyle23e4005Merge pull request #1983 from PyCQA/py314019424badd support for t-strings6b6f3d5Merge pull request #1980 from PyCQA/asottile-patch-18dfa669add rtd sphinx configce34111Merge pull request #1976 from PyCQA/document-f824Updates
pytestfrom 8.3.3 to 8.4.1Release notes
Sourced from pytest's releases.
... (truncated)
Commits
8d99211Prepare release version 8.4.15dc5880docs: update pytest.ini addopts example to use separate -p entries (#13529) (...d0c7ed0Reintroduce PytestReturnNotNoneWarning (#13495) (#13527)a1b3a78Fix compatibility with Twisted 25 (#13502) (#13531)4c161abpytester: avoid unraisableexception gc collects in inline runs to speed up te...a86ee09Fix typo in parametrize.rst (#13514) (#13516)1a0581bRemove outdated warning about faulthandler_timeout on Windows (#13492) (#13493)4e631a7Merge pull request #13486 from hosmir/fixtypo (#13487)b49745efix: support TerminalReporter.isatty being called (#13462) (#13483)cc5ceedRELEASING: remove pytest mailing list (#13472) (#13473)Updates
pytest-sugarfrom 1.0.0 to 1.1.0Release notes
Sourced from pytest-sugar's releases.
Changelog
Sourced from pytest-sugar's changelog.
Commits
43bbdd0Release pytest-sugar 1.1.0855d661Feature - Playwright Support for Trace Zip Mapping (#296)2a5862aMerge pull request #293 from cgoldberg/add-py313ca26d98Add support for Python 3.1369989ebClarify license as BSD 3-Clause License3c86a5cMerge pull request #289 from deronnax/remove-packaging-depc123be0remove 'packaging' packageefafd9cMerge pull request #282 from penguinpee/main536c1a8Fix license stringUpdates
vcrpyfrom 6.0.2 to 7.0.0Release notes
Sourced from vcrpy's releases.
Changelog
Sourced from vcrpy's changelog.
... (truncated)
Commits
3278619Release v7.0.03fb62e0fix: correctly handle asyncio.run when loop exists8197865build(deps): update sphinx requirement from <8 to <9be651bdpre-commit: Autoupdatea6698edFix aiohttp tests48d0a2eFixed missingversion_stringattribute when used with urllib3>=2.3.05b858b1Fix lintc8d99a9Fix ruff configurationce27c63Merge pull request #736 from kevin1024/drop-python38ab8944dDrop python 3.8 supportUpdates
pytest-recordingfrom 0.13.2 to 0.13.4Release notes
Sourced from pytest-recording's releases.
Changelog
Sourced from pytest-recording's changelog.
Commits
c2d2db7chore: Release 0.13.4cf919c9test: Run tests on Windowsb8b45b7fix: Use fallback for max filename length on Windows8a7e19fdocs: Update README.rst3ad7910chore: Release 0.13.39a6e12cdocs: Add a note for package maintainersa70532bchore: Revert "test: Disable pretty plugin in pytest"6b84832chore(deps): update codecov/codecov-action action to v5.4.2460a7f9test: Add long_cassette_name test9822a50fix: Checkdefault_cassetteto prevent it from being too long.Updates
openaifrom 1.99.7 to 1.101.0Release notes
Sourced from openai's releases.
... (truncated)
Changelog
Sourced from openai's changelog.
... (truncated)
Commits
4e28a42release: 1.101.0 (#2577)e328fb4release: 1.100.372e0ad6chore(internal/ci): setup breaking change detection4ada66frelease: 1.100.2a94bd5bchore(api): accurately represent shape for verbosity on Chat Completionsf889071release: 1.100.1b3547d6fix(types): revert response text config deletionadb1af8release: 1.100.00843a11feat(api): add new text parameters, expiration options34014aerelease: 1.99.9Updates
pytest-asynciofrom 0.23.8 to 1.1.0Release notes
Sourced from pytest-asyncio's releases.
... (truncated)
Commits
ce06c07chore: Prepare release of v1.1.0.d9a8dccci: Workaround missing Tag annotation during release.d66e12f[pre-commit.ci] pre-commit autoupdate9e5e25fBuild(deps): Bump certifi in /dependencies/docs0e63423Build(deps): Bump hypothesis in /dependencies/defaultbd4551cBuild(deps): Bump ncipollo/release-action from 1.16.0 to 1.18.08e20305Build(deps): Bump hypothesis in /dependencies/defaultb7a8ab5Build(deps): Bump coverage from 7.9.1 to 7.9.2 in /dependencies/default8cc378dBuild(deps): Bump typing-extensions in /dependencies/defaultfb6bfbf[pre-commit.ci] pre-commit autoupdateUpdates
requestsfrom 2.32.4 to 2.32.5Release notes
Sourced from requests's releases.
Changelog
Sourced from requests's changelog.
Commits
b25c87dv2.32.5131e506Merge pull request #7010 from psf/dependabot/github_actions/actions/checkout-...b336cb2Bump actions/checkout from 4.2.0 to 5.0.046e939bUpdate publish workflow to useartifact-idinstead ofname4b9c546Merge pull request #6999 from psf/dependabot/github_actions/step-security/har...7618dbeBump step-security/harden-runner from 2.12.0 to 2.13.02edca11Add support for Python 3.14 and drop support for Python 3.8 (#6993)fec96cdUpdate Makefile rules (#6996)d58d8aadocs: clarify timeout parameter uses seconds in Session.request (#6994)91a3eabBump github/codeql-action from 3.28.5 to 3.29.0You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsImportant
Bumps development dependencies in
pyproject.tomlforopentelemetry-instrumentation-openaito latest versions.flake8updated from 7.0.0 to 7.3.0.pytestupdated from 8.3.3 to 8.4.1.pytest-sugarupdated from 1.0.0 to 1.1.0.vcrpyupdated from 6.0.2 to 7.0.0.pytest-recordingupdated from 0.13.2 to 0.13.4.openaiupdated from 1.99.7 to 1.101.0.pytest-asyncioupdated from 0.23.8 to 1.1.0.requestsupdated from 2.32.4 to 2.32.5.This description was created by
for 39ca809. You can customize this summary. It will automatically update as commits are pushed.