Skip to content

chore: refresh dependencies and relax Python lower bounds - #82

Merged
peter-gy merged 1 commit into
mainfrom
t3/upgrade-lockfiles-lowerbounds
Oct 7, 2026
Merged

peter-gy merged 1 commit into
mainfrom
t3/upgrade-lockfiles-lowerbounds

Conversation

@peter-gy

@peter-gy peter-gy commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Picks up the eligible part of #75 and refreshes both lockfiles.

Toolchain

  • pnpm 12.9.1 (packageManager, set through Corepack) and Node 24.21.0 (devEngines)
  • oxlint and @oxlint/plugins 1.87.0, oxlint-tsgolint 7.0.2003

Lockfiles

  • pnpm -r update within the catalog ranges
  • uv lock --upgrade, with ty held at 0.0.79. ty 0.0.85 reports new JsonValue invariance errors that belong in their own change.

Published Python floors

Dependency Before After
cryptography >=50.0.1 >=42
idna >=3.19 >=3.7
packaging >=26.3 >=22

These floors came from converting exact pins into >= constraints. The new ones match what the code uses: Ed25519 signing and serialization for marimo's cache, idna.encode and idna.decode with UTS 46 (3.7 includes the CVE-2024-3651 fix), and SpecifierSet and Version in the bundled skill. The suite passes on Python 3.10 with every direct dependency at its declared minimum.

The rest of #75 (mermaid 12.1.0, portless 0.15.7, hyparquet 1.31.2, vega-embed 7.3.0, @types/node 24.19, the vitepress>vite override) is still inside the workspace's 14-day minimumReleaseAge. Renovate can land it once those releases age in.

Move the workspace to pnpm 12.9.1 and Node 24.21.0, bump oxlint,
@oxlint/plugins, and oxlint-tsgolint, and refresh pnpm-lock.yaml and
uv.lock within the declared ranges. ty stays at 0.0.79 in the lock.

Lower the published floors for cryptography, idna, and packaging to the
oldest releases that provide the APIs marimo-export and marimo's cache
signing use, so applications with older pins can install marimo-export.
Copilot AI balanced review requested due to automatic review settings October 7, 2026 10:24

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 5 files

Re-trigger cubic

@peter-gy
peter-gy merged commit 64eda17 into main Oct 7, 2026
21 checks passed
@peter-gy
peter-gy deleted the t3/upgrade-lockfiles-lowerbounds branch October 7, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants