chore(deps): combine passing Dependabot updates - #711
Conversation
Bumps [litellm](https://github.com/BerriAI/litellm) from 1.95.0 to 1.96.2. - [Release notes](https://github.com/BerriAI/litellm/releases) - [Commits](BerriAI/litellm@v1.95.0...v1.96.2) --- updated-dependencies: - dependency-name: litellm dependency-version: 1.96.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rojopolis/spellcheck-github-actions](https://github.com/rojopolis/spellcheck-github-actions) from 0.64.0 to 0.66.0. - [Release notes](https://github.com/rojopolis/spellcheck-github-actions/releases) - [Changelog](https://github.com/rojopolis/spellcheck-github-actions/blob/master/CHANGELOG.md) - [Commits](rojopolis/spellcheck-github-actions@26a39cd...c1934c5) --- updated-dependencies: - dependency-name: rojopolis/spellcheck-github-actions dependency-version: 0.66.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pylint](https://github.com/pylint-dev/pylint) from 4.0.6 to 4.0.7. - [Release notes](https://github.com/pylint-dev/pylint/releases) - [Commits](pylint-dev/pylint@v4.0.6...v4.0.7) --- updated-dependencies: - dependency-name: pylint dependency-version: 4.0.7 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 9.0.0 to 10.0.0. - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@c771a70...ae62891) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 10.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [fastmcp](https://github.com/PrefectHQ/fastmcp) from 3.4.6 to 3.4.7. - [Release notes](https://github.com/PrefectHQ/fastmcp/releases) - [Changelog](https://github.com/PrefectHQ/fastmcp/blob/main/docs/changelog.mdx) - [Commits](PrefectHQ/fastmcp@v3.4.6...v3.4.7) --- updated-dependencies: - dependency-name: fastmcp dependency-version: 3.4.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) from 8.66.0 to 8.67.0. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.67.0/packages/typescript-eslint) --- updated-dependencies: - dependency-name: typescript-eslint dependency-version: 8.67.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [graphiti-core](https://github.com/getzep/graphiti) from 0.29.2 to 0.29.3. - [Release notes](https://github.com/getzep/graphiti/releases) - [Commits](getzep/graphiti@v0.29.2...v0.29.3) --- updated-dependencies: - dependency-name: graphiti-core dependency-version: 0.29.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@hookform/resolvers](https://github.com/react-hook-form/resolvers) from 5.4.0 to 5.7.1. - [Release notes](https://github.com/react-hook-form/resolvers/releases) - [Commits](react-hook-form/resolvers@v5.4.0...v5.7.1) --- updated-dependencies: - dependency-name: "@hookform/resolvers" dependency-version: 5.7.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [recharts](https://github.com/recharts/recharts) from 2.15.4 to 3.10.1. - [Release notes](https://github.com/recharts/recharts/releases) - [Changelog](https://github.com/recharts/recharts/blob/main/CHANGELOG.md) - [Commits](recharts/recharts@v2.15.4...v3.10.1) --- updated-dependencies: - dependency-name: recharts dependency-version: 3.10.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) from 1.24.0 to 1.31.0. - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.31.0/packages/lucide-react) --- updated-dependencies: - dependency-name: lucide-react dependency-version: 1.31.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [globals](https://github.com/sindresorhus/globals) from 17.7.0 to 17.11.0. - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.7.0...v17.11.0) --- updated-dependencies: - dependency-name: globals dependency-version: 17.11.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Completed Working on "Code Review"✅ Review publishing completed successfully. Review submitted: COMMENT. Total comments: 2 across 2 files. ✅ Workflow completed successfully. |
|
🚅 Deployed to the QueryWeaver-pr-711 environment in queryweaver
|
Dependency ReviewThe following issues were found:
OpenSSF ScorecardScorecard details
Scanned Files
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (6)
Included review availability: Your plan includes up to 4 reviews per rolling hour; 1 remains after this review. 📝 WalkthroughWalkthroughThe pull request updates pinned GitHub Actions revisions across CI workflows and upgrades selected frontend dependencies in ChangesDependency updates
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to This PR consolidates dependency updates and the clean frontend production build passes; no actionable merge-blocking risk remains beyond normal checks and review. Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Final Review Summary
Findings posted: 2 total (2 MAJOR) across 2 files.
Affected files:
uv.lockapp/package.json
Key themes observed:
- Dependency upgrades introduced potential runtime behavior risk (new transitive backend config dependency).
- Major frontend library version jump (
recharts2.x → 3.x) without explicit regression validation.
Actionable next steps:
- Run backend startup/integration validation in CI with the updated lockfile (
uv sync --frozen) to verify LiteLLM configuration paths remain stable. - Add targeted chart regression coverage (or a documented manual verification checklist) for all Recharts-based UI flows before merge.
No blocker/critical issues were identified, but the above major risks should be addressed to reduce regression likelihood.
| { name = "jsonschema" }, | ||
| { name = "openai" }, | ||
| { name = "pydantic" }, | ||
| { name = "pydantic-settings" }, |
There was a problem hiding this comment.
[major]: The lock update adds a new hard dependency (pydantic-settings) under litellm, which can change runtime config loading behavior and fail startup if its transitive constraints are not resolved in all environments. Please run backend startup/integration tests in CI against the updated lock to validate configuration parsing paths used in production.
| "react-resizable-panels": "^4.12.2", | ||
| "react-router": "^8.3.0", | ||
| "recharts": "^2.15.4", | ||
| "recharts": "^3.10.1", |
There was a problem hiding this comment.
[major]: recharts is being upgraded from 2.x to 3.x, which is a major runtime/UI library jump and can introduce breaking API or rendering behavior changes even when the build succeeds. This PR only notes a production build pass, but does not include chart-focused regression validation for existing dashboards/components.
There was a problem hiding this comment.
Pull request overview
This PR consolidates several passing Dependabot updates into a single dependency-rollup change set across the Python (uv) environment, the React/TypeScript frontend, and GitHub Actions workflows.
Changes:
- Bump Python/uv-locked dependencies (notably LiteLLM, FastMCP, Graphiti Core, and Pylint) via
uv.lockupdates. - Bump frontend dependencies/devDependencies (notably Recharts, lucide-react, @hookform/resolvers, globals, and typescript-eslint).
- Update GitHub Actions workflow pins for
astral-sh/setup-uvand the spellcheck action.
Reviewed changes
Copilot reviewed 6 out of 8 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
uv.lock |
Updates locked Python dependencies for the backend/tooling environment. |
app/package.json |
Updates direct frontend dependency versions to the new ranges. |
app/package-lock.json |
Updates the resolved frontend dependency tree to match the new direct versions. |
.github/workflows/tests.yml |
Pins astral-sh/setup-uv to v10.0.0 commit SHA in test workflows. |
.github/workflows/pylint.yml |
Pins astral-sh/setup-uv to v10.0.0 commit SHA for lint workflow. |
.github/workflows/publish-pypi.yml |
Pins astral-sh/setup-uv to v10.0.0 commit SHA for publishing workflow. |
.github/workflows/playwright.yml |
Pins astral-sh/setup-uv to v10.0.0 commit SHA for E2E workflow. |
.github/workflows/spellcheck.yml |
Pins spellcheck action to 0.66.0 commit SHA. |
Files not reviewed (1)
- app/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "version": "0.3.1", | ||
| "dependencies": { | ||
| "@falkordb/canvas": "^0.0.45", | ||
| "@hookform/resolvers": "^5.4.0", | ||
| "@hookform/resolvers": "^5.7.1", | ||
| "@radix-ui/react-accordion": "^1.2.20", |
Summary
Combines the currently passing Dependabot updates into one PR:
Excludes #702 because its dependency-review check is failing.
Validation
Summary by CodeRabbit