build(deps): bump the python-dependencies group across 1 directory with 4 updates - #143
dependabot[bot] wants to merge 1 commit into
Conversation
…th 4 updates Updates the requirements on [mcp](https://github.com/modelcontextprotocol/python-sdk), [evdev](https://github.com/gvalkov/python-evdev), [playwright](https://github.com/microsoft/playwright-python) and [ruff](https://github.com/astral-sh/ruff) to permit the latest version. Updates `mcp` to 2.2.0 - [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases) - [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md) - [Commits](modelcontextprotocol/python-sdk@v2.1.1...v2.2.0) Updates `evdev` to 1.9.3 - [Changelog](https://github.com/gvalkov/python-evdev/blob/main/docs/changelog.rst) - [Commits](gvalkov/python-evdev@v1.7.0...v1.9.3) Updates `playwright` to 1.63.0 - [Release notes](https://github.com/microsoft/playwright-python/releases) - [Commits](microsoft/playwright-python@v1.62.0...v1.63.0) Updates `ruff` to 0.16.8 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.6...0.16.8) --- updated-dependencies: - dependency-name: mcp dependency-version: 2.2.0 dependency-type: direct:production dependency-group: python-dependencies - dependency-name: evdev dependency-version: 1.9.3 dependency-type: direct:production dependency-group: python-dependencies - dependency-name: playwright dependency-version: 1.63.0 dependency-type: direct:production dependency-group: python-dependencies - dependency-name: ruff dependency-version: 0.16.8 dependency-type: direct:development dependency-group: python-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: leandre755/gui_agent/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
PR author is in the excluded authors list. |
Governance summary
Branch protection and CODEOWNERS must enforce approval for sensitive paths. |
| "evdev>=1.7.0; sys_platform == 'linux'", | ||
| "playwright>=1.62.0", | ||
| "evdev>=1.9.3; sys_platform == 'linux'", | ||
| "playwright>=1.63.0", |
There was a problem hiding this comment.
🟠 High pyproject.toml:48
uv.lock still pins playwright 1.62.0 and ruff 0.16.7 and retains the old root requires-dist constraints, so uv sync --locked and uv run --locked reject this repository as out of date while --frozen workflows continue using versions excluded by pyproject.toml. Regenerate uv.lock after raising these lower bounds.
🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @pyproject.toml around line 48:
`uv.lock` still pins `playwright` 1.62.0 and `ruff` 0.16.7 and retains the old root `requires-dist` constraints, so `uv sync --locked` and `uv run --locked` reject this repository as out of date while `--frozen` workflows continue using versions excluded by `pyproject.toml`. Regenerate `uv.lock` after raising these lower bounds.
Evidence trail:
Reviewed commit 909c249: `pyproject.toml:48,53`; `uv.lock:694-711,1623-1626,2425-2428`. uv documentation: https://docs.astral.sh/uv/concepts/projects/sync/ (locked mode errors for stale metadata; frozen mode skips the check).
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This one-file dependency update changes production MCP, evdev, and Playwright floors, including MCP behavior affecting redirects, sessions, and authentication. The associated uv.lock remains stale for locked workflows, and the packaging file is owned by repository maintainers rather than the automated author. Not approved because:
Adjust the Minimum Blocking Severity for this repo — including turning it Off — in Settings. You can add or adjust custom eligibility rules. Learn more. |
Updates the requirements on mcp, evdev, playwright and ruff to permit the latest version.
Updates
mcpto 2.2.0Release notes
Sourced from mcp's releases.
... (truncated)
Commits
9972c21Replace RootModel wrappers with type aliases and TypeAdapter validation (#3470)fd66270docs: refresh translations, and translate pages in parallel (#3458)08a3bc8docs: ask for AI disclosure on comments too (#3459)7bb486adocs: stop presenting the in-memory client as the way to connect (#3443)0c91368Add AuthSettings.validate_token_resource to check a bearer token's resource (...9771e6bKeep following a relative redirect when the endpoint URL carries userinfo (#3...a925e55Bump the locked versions of eight dev and test dependencies (#3449)e8b9486Bump pymdown-extensions from 11.0 to 11.0.1 (#3285)c6762e8Follow redirects only within the MCP endpoint's origin (#3397)5fd3abcSkip automatic docs previews for fork PRs and drop the setup-uv retry steps (...Updates
evdevto 1.9.3Changelog
Sourced from evdev's changelog.
... (truncated)
Commits
a47b5b5Bump version: 1.9.2 → 1.9.3faf7bc9Drop support for Python 3.8 and raise setuptools version to 77.0fae2cf9Use an SPDX license60c6392CI fixes5227b16Fix memory leaksa5d8cf0Bump version: 1.9.1 → 1.9.28f45223Use Generic to set precise type for InputDevice.path (#241)3bc969bs/reproducibility/reproducible6b4e8efAdd a reproducibility option for building ecodes.c (#242)5f9fd2cfix utils.categorize return type (#240)Updates
playwrightto 1.63.0Release notes
Sourced from playwright's releases.
... (truncated)
Commits
8cb967bcherry-pick(#3200): devops(docker): move docker publishing to Azure Pipelinesab18c77chore: roll Playwright to 1.63.0 (#3198)0e66a09devops(pipeline): resolve pip and npm packages from DevDiv_PublicPackages fee...010a9ccPin GitHub Actions to full-length commit SHAs (#3176)154f67cfix(sync): wait for initialize before leaving enter (#3168)4af2fc6chore: roll Playwright to 1.62.1 (#3169)4d2e058fix(connection): register protocol callback only after successful send (#3167)eab2bcachore(deps): remove unused development dependencies (#3164)Updates
ruffto 0.16.8Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
... (truncated)
Commits
62914c4Bump version to 0.16.8 (#28648)c47e0cd[ty] Bound aliased intersection expansion during inference (#28546)ff4747brenovate: update uv hashes correctly with setup-uv (#28621)94efeaa[ty] Compact reachable binding and declaration histories (#28349)50020fb[ty] Avoid storing constraint nodes twice (#28375)446bb68[ty] Compare bound-method receivers before signatures (#28384)304ab86[flake8-type-checking] Prefer lazy imports overTYPE_CHECKINGon 3.15+ (`...d940b24[ty] Watch script dependencies in CLI watch mode (#28125)fe9f065[flake8-tidy-imports] Addextend-banned-api(#28644)31131db[ty] Supporttype[A & B](#27124)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsNote
Bump
mcpto 2.2.0,evdevto 1.9.3,playwrightto 1.63.0, andruffto 0.16.8mcp(2.1.1 → 2.2.0),evdevon Linux (1.7.0 → 1.9.3), andplaywright(1.62.0 → 1.63.0) in pyproject.tomlrufffrom 0.16.6 to 0.16.8📊 Macroscope summarized 909c249. 1 file reviewed, 1 issue evaluated, 0 issues filtered, 1 comment posted
🗂️ Filtered Issues