Repository navigation
chore: refresh dependencies and relax Python lower bounds - #82
Merged
Merged
Conversation
Move the workspace to pnpm 12.9.1 and Node 24.21.0, bump oxlint, @oxlint/plugins, and oxlint-tsgolint, and refresh pnpm-lock.yaml and uv.lock within the declared ranges. ty stays at 0.0.79 in the lock. Lower the published floors for cryptography, idna, and packaging to the oldest releases that provide the APIs marimo-export and marimo's cache signing use, so applications with older pins can install marimo-export.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Picks up the eligible part of #75 and refreshes both lockfiles.
Toolchain
packageManager, set through Corepack) and Node 24.21.0 (devEngines)@oxlint/plugins1.87.0, oxlint-tsgolint 7.0.2003Lockfiles
pnpm -r updatewithin the catalog rangesuv lock --upgrade, with ty held at 0.0.79. ty 0.0.85 reports newJsonValueinvariance errors that belong in their own change.Published Python floors
cryptography>=50.0.1>=42idna>=3.19>=3.7packaging>=26.3>=22These floors came from converting exact pins into
>=constraints. The new ones match what the code uses: Ed25519 signing and serialization for marimo's cache,idna.encodeandidna.decodewith UTS 46 (3.7 includes the CVE-2024-3651 fix), andSpecifierSetandVersionin the bundled skill. The suite passes on Python 3.10 with every direct dependency at its declared minimum.The rest of #75 (mermaid 12.1.0, portless 0.15.7, hyparquet 1.31.2, vega-embed 7.3.0,
@types/node24.19, thevitepress>viteoverride) is still inside the workspace's 14-dayminimumReleaseAge. Renovate can land it once those releases age in.