Skip to content

Consolidate Dependabot dependency updates - #7445

Open
moonbox3 wants to merge 17 commits into
microsoft:mainfrom
moonbox3:codex/consolidate-dependabot-20260731-e39a8a2
Open

Consolidate Dependabot dependency updates#7445
moonbox3 wants to merge 17 commits into
microsoft:mainfrom
moonbox3:codex/consolidate-dependabot-20260731-e39a8a2

Conversation

@moonbox3

Copy link
Copy Markdown
Contributor

Motivation & Context

Consolidate the current open Dependabot updates into one compatible, reviewable change. Several Python tool updates need to land together because the root and Lab development pins share one workspace lockfile, and the newer Ruff and ty releases require small compatibility updates to existing Markdown examples and test-only suppressions.

Description & Review Guide

  • What are the major changes? Updates the selected GitHub Actions, Python development/build tools, and .NET AgentMemory packages; refreshes the Python lockfile and duplicate Lab tool pins; and applies the minimal formatting and test-typing compatibility changes required by Ruff 0.16 and ty 0.0.64.
  • What is the impact of these changes? CI actions and development tooling use the requested newer versions, the Python workspace remains resolvable, and the AgentMemory sample builds against version 1.3.0 of both packages. There are no public API or runtime behavior changes.
  • What do you want reviewers to focus on? Confirm that each superseded dependency update is represented and that the Python compatibility follow-ups remain narrowly scoped to the new tool behavior.

Related Issue

Supersedes:

Contribution Checklist

  • The code builds clean without any errors or warnings
  • All unit tests pass, and I have added new tests where possible
  • The PR follows the Contribution Guidelines
  • This PR is linked to an issue and there is no other open PR for this issue (see Related Issue above).
  • This is not a breaking change. If it is a breaking change, add the breaking change label (or add "[BREAKING]" to the title prefix, before or after any language prefix) — a workflow keeps the label and title prefix in sync automatically.

dependabot Bot and others added 16 commits July 31, 2026 08:26
---
updated-dependencies:
- dependency-name: AgentMemory
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.0 to 4.37.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@99df26d...e4fba86)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.3.2 to 9.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@11f9893...c771a70)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.0 to 4.37.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@99df26d...e4fba86)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@27d5ce7...55cc834)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@de0fac2...3d3c42e)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.3.2 to 9.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@11f9893...c771a70)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ty](https://github.com/astral-sh/ty) from 0.0.60 to 0.0.64.
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.60...0.0.64)

---
updated-dependencies:
- dependency-name: ty
  dependency-version: 0.0.65
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [prek](https://github.com/j178/prek) from 0.4.10 to 0.4.11.
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](j178/prek@v0.4.10...v0.4.11)

---
updated-dependencies:
- dependency-name: prek
  dependency-version: 0.4.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [uv](https://github.com/astral-sh/uv) from 0.11.29 to 0.11.32.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.11.29...0.11.32)

---
updated-dependencies:
- dependency-name: uv
  dependency-version: 0.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.15.22 to 0.16.0.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.22...0.16.0)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
---
updated-dependencies:
- dependency-name: uv-build
  dependency-version: 0.12.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI review requested due to automatic review settings July 30, 2026 23:49
@moonbox3
moonbox3 temporarily deployed to github-app-auth July 30, 2026 23:49 — with GitHub Actions Inactive
@moonbox3
moonbox3 temporarily deployed to github-app-auth July 30, 2026 23:49 — with GitHub Actions Inactive
@moonbox3
moonbox3 temporarily deployed to github-app-auth July 30, 2026 23:49 — with GitHub Actions Inactive
@agent-framework-automation agent-framework-automation Bot added documentation Usage: [Issues, PRs], Target: documentation in the code base and learn docs python Usage: [Issues, PRs], Target: Python .NET Usage: [Issues, PRs], Target: .Net lab Usage: [Issues, PRs], Target: lab packages labels Jul 30, 2026
@github-actions github-actions Bot changed the title Consolidate Dependabot dependency updates Python: Consolidate Dependabot dependency updates Jul 30, 2026
@github-actions github-actions Bot changed the title Python: Consolidate Dependabot dependency updates .NET: Consolidate Dependabot dependency updates Jul 30, 2026
@github-actions

github-actions Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Python Test Coverage

Python Test Coverage Report •
FileStmtsMissCoverMissing
TOTAL47343452990% 
report-only-changed-files is enabled. No files were changed during this commit :)

Python Unit Test Overview

Tests Skipped Failures Errors Time
9742 34 💤 0 ❌ 0 🔥 2m 38s ⏱️

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated Code Review

Reviewers: 5 | Confidence: 68%

✓ Correctness

No correctness issues found in the provided dependency, workflow, lockfile, documentation-formating, or test-suppression changes.

✓ Security Reliability

This is a dependency-pin refresh (GitHub Actions SHAs, Python dev tooling, .NET sample package versions) plus Ruff/ty compatibility formatting in Markdown and test-only type suppressions. No production code, no new trust boundaries, no secrets, and no deserialization or resource-handling changes are introduced, so the security surface is limited to supply-chain pinning hygiene. All actions remain SHA-pinned, which is the right posture. The only issue I can confirm from the diff text alone is an internally inconsistent version comment on the actions/cache pin: the identical commit SHA 55cc8345863c7cc4c66a329aec7e433d2d1c52a9 is annotated # v5 in .github/workflows/python-code-quality.yml but # v6.1.0 in .github/workflows/python-integration-tests.yml and .github/workflows/python-merge-tests.yml. Since these comments are the only human-readable signal for what a pinned SHA actually is, a stale # v5 label hides a major-version upgrade from reviewers. Note: my file-read and search tooling returned permission errors during this session, so I limited findings strictly to what the diff itself proves and omitted anything requiring repository verification.

✓ Test Coverage

No substantive test-coverage gaps found. Changes are dependency/tooling updates, formatting adjustments, and test-only type suppressions without new runtime behavior.

✓ Failure Modes

This is a pure dependency/pin bump PR (GitHub Action SHAs, Python dev tooling versions, uv.lock refresh, .NET sample package versions) plus formatting-only Markdown changes and additional # ty: ignore[...] suppressions in tests. There is no runtime logic in the diff, so there are no new error-handling, cancellation, rollback, or partial-write failure paths introduced. Note: my environment blocked all file-read/search/CLI tooling for this review, so I limited findings strictly to what is directly provable from the diff text itself and omitted anything requiring repository verification (e.g. whether setup-uv v9.0.0 or actions/cache v6 changed input semantics for version-file, version: "0.11.x", or cache key handling — those are worth a maintainer sanity check on a green CI run before merge). The one thing visible purely within the diff is an inconsistent version annotation for a single pinned SHA.

✓ Design Approach

This is a dependency-consolidation PR: pinned action SHAs, Python tool version bumps, lockfile refresh, a .NET sample package bump, and Ruff/ty-driven formatting and suppression updates. Note: my tooling (grep/glob/view/bash) was blocked in this session with permission errors, so I could not perform the usual context pass in the checked-out repo; I therefore limited findings strictly to what is self-evident within the diff itself and withheld anything requiring file verification. The only issue visible purely from the diff is an inconsistent version comment on the newly pinned actions/cache SHA: the same commit 55cc8345863c7cc4c66a329aec7e433d2d1c52a9 is annotated '# v5' in one workflow and '# v6.1.0' in two others. Since the version comment is the only human-readable signal for a pinned SHA, the mismatch is misleading for future Dependabot/review passes. This is non-blocking.

Suggestions

  • Align the version comment on the new actions/cache pin (55cc8345863c7cc4c66a329aec7e433d2d1c52a9): it is labeled '# v5' in .github/workflows/python-code-quality.yml:45 but '# v6.1.0' in .github/workflows/python-integration-tests.yml:195 and .github/workflows/python-merge-tests.yml:302. Only one can be correct.

Automated review by moonbox3's agents

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Consolidates multiple Dependabot-driven dependency bumps across the repo (GitHub Actions, Python tooling/lockfile, and a .NET sample) and applies the minimal follow-up edits required for the updated Python tooling to keep docs/tests compatible.

Changes:

  • Updated Python dev tooling pins (uv/ruff/ty/prek), refreshed uv.lock, and widened uv_build constraints in select packages.
  • Adjusted Python docs/examples formatting and added targeted ty ignores in tests to match updated type-checker behavior.
  • Updated pinned GitHub Actions SHAs (checkout/cache/setup-uv/codeql) and bumped AgentMemory packages in a .NET sample.

Reviewed changes

Copilot reviewed 37 out of 39 changed files in this pull request and generated 26 comments.

Show a summary per file
File Description
python/uv.lock Refreshes the workspace lockfile to reflect updated Python tooling pins.
python/pyproject.toml Updates root Python dev dependency-group pins (uv/ruff/ty/prek).
python/packages/ollama/pyproject.toml Widens uv_build upper bound to allow newer uv-build versions.
python/packages/ollama/AGENTS.md Minor Markdown formatting adjustment in examples.
python/packages/mistral/pyproject.toml Widens uv_build upper bound to allow newer uv-build versions.
python/packages/lab/pyproject.toml Updates Lab dev pins to stay aligned with the shared lockfile/tooling.
python/packages/core/tests/core/test_observability.py Adds ty ignore suppressions needed under the updated type checker.
python/packages/ag-ui/README.md Reflows Markdown examples to satisfy updated formatter behavior.
python/packages/ag-ui/getting_started/README.md Small example formatting update for compatibility with Markdown formatting.
python/packages/ag-ui/AGENTS.md Minor Markdown formatting adjustment in examples.
python/packages/ag-ui/agent_framework_ag_ui_examples/README.md Reflows example snippets (state schema/config) for formatter compatibility.
dotnet/samples/02-agents/AgentWithMemory/AgentWithMemory_Step06_MemoryUsingAgentMemory/AgentWithMemory_Step06_MemoryUsingAgentMemory.csproj Bumps AgentMemory package references to 1.3.0.
.github/workflows/stale-issue-pr-ping.yml Updates pinned actions/checkout SHA.
.github/workflows/python-tests.yml Updates pinned actions/checkout SHA.
.github/workflows/python-test-coverage.yml Updates pinned actions/checkout SHA.
.github/workflows/python-test-coverage-report.yml Updates pinned actions/checkout SHA.
.github/workflows/python-sample-validation.yml Updates pinned actions/checkout SHA across sample-validation jobs.
.github/workflows/python-release.yml Updates pinned actions/checkout SHA.
.github/workflows/python-merge-tests.yml Updates pinned actions/checkout SHA and bumps actions/cache for Ollama model caching.
.github/workflows/python-lab-tests.yml Updates pinned actions/checkout SHA.
.github/workflows/python-integration-tests.yml Updates pinned actions/checkout SHA and bumps actions/cache for Ollama model caching.
.github/workflows/python-docs.yml Updates pinned actions/checkout SHA and bumps astral-sh/setup-uv to v9.
.github/workflows/python-dependency-maintenance.yml Updates pinned actions/checkout SHA.
.github/workflows/python-code-quality.yml Updates pinned actions/checkout SHA and bumps actions/cache.
.github/workflows/markdown-link-check.yml Updates pinned actions/checkout SHA.
.github/workflows/limit-community-prs.yml Updates pinned actions/checkout SHA for script checkouts.
.github/workflows/label-title-prefix.yml Updates pinned actions/checkout SHA for script checkout.
.github/workflows/label-pr.yml Updates pinned actions/checkout SHA for script checkout.
.github/workflows/label-issues.yml Updates pinned actions/checkout SHA for automation checkout.
.github/workflows/issue-triage.yml Updates pinned actions/checkout SHA and bumps astral-sh/setup-uv to v9.
.github/workflows/integration-tests-manual.yml Updates pinned actions/checkout SHA for helpers checkout.
.github/workflows/github-automation-tests.yml Updates pinned actions/checkout SHA.
.github/workflows/dotnet-verify-samples.yml Updates pinned actions/checkout SHA.
.github/workflows/dotnet-integration-tests.yml Updates pinned actions/checkout SHA.
.github/workflows/dotnet-format.yml Updates pinned actions/checkout SHA.
.github/workflows/dotnet-build-and-test.yml Updates pinned actions/checkout SHA across jobs.
.github/workflows/devflow-pr-review.yml Updates pinned actions/checkout SHA and bumps astral-sh/setup-uv to v9.
.github/workflows/codeql-analysis.yml Updates pinned actions/checkout SHA and bumps CodeQL action SHAs.
.github/actions/python-setup/action.yml Bumps astral-sh/setup-uv to v9 in the reusable Python setup action.
Comments suppressed due to low confidence (1)

.github/workflows/python-code-quality.yml:45

  • This workflow pins actions/cache to the v6.1.0 SHA, but the inline comment still says "# v5". Please update the comment to match the pinned version to avoid confusion during audits.
      - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v5

Comment thread .github/workflows/python-code-quality.yml Outdated
Comment thread .github/workflows/stale-issue-pr-ping.yml Outdated
Comment thread .github/workflows/python-tests.yml Outdated
Comment thread .github/workflows/python-test-coverage.yml Outdated
Comment thread .github/workflows/python-test-coverage-report.yml Outdated
Comment thread .github/workflows/dotnet-format.yml Outdated
Comment thread .github/workflows/dotnet-build-and-test.yml Outdated
Comment thread .github/workflows/dotnet-integration-tests.yml Outdated
Comment thread .github/workflows/codeql-analysis.yml Outdated
Comment thread .github/workflows/devflow-pr-review.yml Outdated
@moonbox3 moonbox3 changed the title .NET: Consolidate Dependabot dependency updates Consolidate Dependabot dependency updates Jul 31, 2026
@moonbox3
moonbox3 temporarily deployed to github-app-auth July 31, 2026 01:08 — with GitHub Actions Inactive
@moonbox3
moonbox3 temporarily deployed to github-app-auth July 31, 2026 01:19 — with GitHub Actions Inactive
@moonbox3
moonbox3 deployed to integration July 31, 2026 01:19 — with GitHub Actions Active
@moonbox3

Copy link
Copy Markdown
Contributor Author

Addressed the automated review feedback in a2ade58: all actions/checkout annotations now match v7.0.1, and the python-code-quality actions/cache annotation now matches v6.1.0. All 26 inline threads have been replied to and resolved.

@moonbox3
moonbox3 marked this pull request as ready for review July 31, 2026 01:36
@moonbox3
moonbox3 temporarily deployed to github-app-auth July 31, 2026 01:37 — with GitHub Actions Inactive

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated Code Review

Reviewers: 5 | Confidence: 57% | Result: All clear

Reviewed: Correctness, Security Reliability, Test Coverage, Failure Modes, Design Approach


Automated review by moonbox3's agents

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Usage: [Issues, PRs], Target: documentation in the code base and learn docs lab Usage: [Issues, PRs], Target: lab packages .NET Usage: [Issues, PRs], Target: .Net python Usage: [Issues, PRs], Target: Python

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants