Consolidate Dependabot dependency updates - #7445
Conversation
--- updated-dependencies: - dependency-name: AgentMemory dependency-version: 1.3.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.0 to 4.37.3. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...e4fba86) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.3.2 to 9.0.0. - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@11f9893...c771a70) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.0 to 4.37.3. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...e4fba86) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@27d5ce7...55cc834) --- updated-dependencies: - dependency-name: actions/cache dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 7.0.1. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@de0fac2...3d3c42e) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.3.2 to 9.0.0. - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@11f9893...c771a70) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ty](https://github.com/astral-sh/ty) from 0.0.60 to 0.0.64. - [Release notes](https://github.com/astral-sh/ty/releases) - [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md) - [Commits](astral-sh/ty@0.0.60...0.0.64) --- updated-dependencies: - dependency-name: ty dependency-version: 0.0.65 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [prek](https://github.com/j178/prek) from 0.4.10 to 0.4.11. - [Release notes](https://github.com/j178/prek/releases) - [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md) - [Commits](j178/prek@v0.4.10...v0.4.11) --- updated-dependencies: - dependency-name: prek dependency-version: 0.4.11 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [uv](https://github.com/astral-sh/uv) from 0.11.29 to 0.11.32. - [Release notes](https://github.com/astral-sh/uv/releases) - [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md) - [Commits](astral-sh/uv@0.11.29...0.11.32) --- updated-dependencies: - dependency-name: uv dependency-version: 0.12.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.15.22 to 0.16.0. - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.15.22...0.16.0) --- updated-dependencies: - dependency-name: ruff dependency-version: 0.16.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
--- updated-dependencies: - dependency-name: uv-build dependency-version: 0.12.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Automated Code Review
Reviewers: 5 | Confidence: 68%
✓ Correctness
No correctness issues found in the provided dependency, workflow, lockfile, documentation-formating, or test-suppression changes.
✓ Security Reliability
This is a dependency-pin refresh (GitHub Actions SHAs, Python dev tooling, .NET sample package versions) plus Ruff/ty compatibility formatting in Markdown and test-only type suppressions. No production code, no new trust boundaries, no secrets, and no deserialization or resource-handling changes are introduced, so the security surface is limited to supply-chain pinning hygiene. All actions remain SHA-pinned, which is the right posture. The only issue I can confirm from the diff text alone is an internally inconsistent version comment on the
actions/cachepin: the identical commit SHA55cc8345863c7cc4c66a329aec7e433d2d1c52a9is annotated# v5in.github/workflows/python-code-quality.ymlbut# v6.1.0in.github/workflows/python-integration-tests.ymland.github/workflows/python-merge-tests.yml. Since these comments are the only human-readable signal for what a pinned SHA actually is, a stale# v5label hides a major-version upgrade from reviewers. Note: my file-read and search tooling returned permission errors during this session, so I limited findings strictly to what the diff itself proves and omitted anything requiring repository verification.
✓ Test Coverage
No substantive test-coverage gaps found. Changes are dependency/tooling updates, formatting adjustments, and test-only type suppressions without new runtime behavior.
✓ Failure Modes
This is a pure dependency/pin bump PR (GitHub Action SHAs, Python dev tooling versions, uv.lock refresh, .NET sample package versions) plus formatting-only Markdown changes and additional
# ty: ignore[...]suppressions in tests. There is no runtime logic in the diff, so there are no new error-handling, cancellation, rollback, or partial-write failure paths introduced. Note: my environment blocked all file-read/search/CLI tooling for this review, so I limited findings strictly to what is directly provable from the diff text itself and omitted anything requiring repository verification (e.g. whether setup-uv v9.0.0 or actions/cache v6 changed input semantics forversion-file,version: "0.11.x", or cache key handling — those are worth a maintainer sanity check on a green CI run before merge). The one thing visible purely within the diff is an inconsistent version annotation for a single pinned SHA.
✓ Design Approach
This is a dependency-consolidation PR: pinned action SHAs, Python tool version bumps, lockfile refresh, a .NET sample package bump, and Ruff/ty-driven formatting and suppression updates. Note: my tooling (grep/glob/view/bash) was blocked in this session with permission errors, so I could not perform the usual context pass in the checked-out repo; I therefore limited findings strictly to what is self-evident within the diff itself and withheld anything requiring file verification. The only issue visible purely from the diff is an inconsistent version comment on the newly pinned actions/cache SHA: the same commit 55cc8345863c7cc4c66a329aec7e433d2d1c52a9 is annotated '# v5' in one workflow and '# v6.1.0' in two others. Since the version comment is the only human-readable signal for a pinned SHA, the mismatch is misleading for future Dependabot/review passes. This is non-blocking.
Suggestions
- Align the version comment on the new actions/cache pin (55cc8345863c7cc4c66a329aec7e433d2d1c52a9): it is labeled '# v5' in .github/workflows/python-code-quality.yml:45 but '# v6.1.0' in .github/workflows/python-integration-tests.yml:195 and .github/workflows/python-merge-tests.yml:302. Only one can be correct.
Automated review by moonbox3's agents
There was a problem hiding this comment.
Pull request overview
Consolidates multiple Dependabot-driven dependency bumps across the repo (GitHub Actions, Python tooling/lockfile, and a .NET sample) and applies the minimal follow-up edits required for the updated Python tooling to keep docs/tests compatible.
Changes:
- Updated Python dev tooling pins (uv/ruff/ty/prek), refreshed
uv.lock, and wideneduv_buildconstraints in select packages. - Adjusted Python docs/examples formatting and added targeted
tyignores in tests to match updated type-checker behavior. - Updated pinned GitHub Actions SHAs (checkout/cache/setup-uv/codeql) and bumped AgentMemory packages in a .NET sample.
Reviewed changes
Copilot reviewed 37 out of 39 changed files in this pull request and generated 26 comments.
Show a summary per file
| File | Description |
|---|---|
python/uv.lock |
Refreshes the workspace lockfile to reflect updated Python tooling pins. |
python/pyproject.toml |
Updates root Python dev dependency-group pins (uv/ruff/ty/prek). |
python/packages/ollama/pyproject.toml |
Widens uv_build upper bound to allow newer uv-build versions. |
python/packages/ollama/AGENTS.md |
Minor Markdown formatting adjustment in examples. |
python/packages/mistral/pyproject.toml |
Widens uv_build upper bound to allow newer uv-build versions. |
python/packages/lab/pyproject.toml |
Updates Lab dev pins to stay aligned with the shared lockfile/tooling. |
python/packages/core/tests/core/test_observability.py |
Adds ty ignore suppressions needed under the updated type checker. |
python/packages/ag-ui/README.md |
Reflows Markdown examples to satisfy updated formatter behavior. |
python/packages/ag-ui/getting_started/README.md |
Small example formatting update for compatibility with Markdown formatting. |
python/packages/ag-ui/AGENTS.md |
Minor Markdown formatting adjustment in examples. |
python/packages/ag-ui/agent_framework_ag_ui_examples/README.md |
Reflows example snippets (state schema/config) for formatter compatibility. |
dotnet/samples/02-agents/AgentWithMemory/AgentWithMemory_Step06_MemoryUsingAgentMemory/AgentWithMemory_Step06_MemoryUsingAgentMemory.csproj |
Bumps AgentMemory package references to 1.3.0. |
.github/workflows/stale-issue-pr-ping.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/python-tests.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/python-test-coverage.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/python-test-coverage-report.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/python-sample-validation.yml |
Updates pinned actions/checkout SHA across sample-validation jobs. |
.github/workflows/python-release.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/python-merge-tests.yml |
Updates pinned actions/checkout SHA and bumps actions/cache for Ollama model caching. |
.github/workflows/python-lab-tests.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/python-integration-tests.yml |
Updates pinned actions/checkout SHA and bumps actions/cache for Ollama model caching. |
.github/workflows/python-docs.yml |
Updates pinned actions/checkout SHA and bumps astral-sh/setup-uv to v9. |
.github/workflows/python-dependency-maintenance.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/python-code-quality.yml |
Updates pinned actions/checkout SHA and bumps actions/cache. |
.github/workflows/markdown-link-check.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/limit-community-prs.yml |
Updates pinned actions/checkout SHA for script checkouts. |
.github/workflows/label-title-prefix.yml |
Updates pinned actions/checkout SHA for script checkout. |
.github/workflows/label-pr.yml |
Updates pinned actions/checkout SHA for script checkout. |
.github/workflows/label-issues.yml |
Updates pinned actions/checkout SHA for automation checkout. |
.github/workflows/issue-triage.yml |
Updates pinned actions/checkout SHA and bumps astral-sh/setup-uv to v9. |
.github/workflows/integration-tests-manual.yml |
Updates pinned actions/checkout SHA for helpers checkout. |
.github/workflows/github-automation-tests.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/dotnet-verify-samples.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/dotnet-integration-tests.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/dotnet-format.yml |
Updates pinned actions/checkout SHA. |
.github/workflows/dotnet-build-and-test.yml |
Updates pinned actions/checkout SHA across jobs. |
.github/workflows/devflow-pr-review.yml |
Updates pinned actions/checkout SHA and bumps astral-sh/setup-uv to v9. |
.github/workflows/codeql-analysis.yml |
Updates pinned actions/checkout SHA and bumps CodeQL action SHAs. |
.github/actions/python-setup/action.yml |
Bumps astral-sh/setup-uv to v9 in the reusable Python setup action. |
Comments suppressed due to low confidence (1)
.github/workflows/python-code-quality.yml:45
- This workflow pins actions/cache to the v6.1.0 SHA, but the inline comment still says "# v5". Please update the comment to match the pinned version to avoid confusion during audits.
- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v5
|
Addressed the automated review feedback in a2ade58: all actions/checkout annotations now match v7.0.1, and the python-code-quality actions/cache annotation now matches v6.1.0. All 26 inline threads have been replied to and resolved. |
Motivation & Context
Consolidate the current open Dependabot updates into one compatible, reviewable change. Several Python tool updates need to land together because the root and Lab development pins share one workspace lockfile, and the newer Ruff and ty releases require small compatibility updates to existing Markdown examples and test-only suppressions.
Description & Review Guide
Related Issue
Supersedes:
Contribution Checklist
breaking changelabel (or add "[BREAKING]" to the title prefix, before or after any language prefix) — a workflow keeps the label and title prefix in sync automatically.