chore: bump astral-sh/setup-uv from 8.0.0 to 8.1.0#96
Conversation
33569f8 to
ad82d81
Compare
Security Vulnerabilities — Partial Fix Appliedaieng-bot applied partial security fixes from pip-audit findings. ✅ Fixed
❌ Cannot Auto-Fix — Dependency Conflict
Why these cannot be auto-fixedFixing these vulnerabilities requires Recommended next steps
This PR cannot be auto-merged until the remaining vulnerabilities are resolved. |
Security Vulnerabilities — Cannot Auto-Fix Due to Irresolvable Dependency Conflictaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because applying the patches creates an irresolvable dependency conflict:
Why this cannot be auto-fixedAll three fixes require upgrading Conflict chain:
Recommended next steps
This PR will not be auto-merged until the conflict is resolved. |
Security Vulnerabilities — Cannot Be Auto-Fixed Due to Dependency Conflictaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because the patches conflict with an existing dependency constraint in this project:
Why this cannot be auto-fixedAll three fixes require bumping
The only pre-release that might resolve this is Recommended next steps
This PR cannot be auto-merged until the vulnerability is resolved. Human review required. |
Security Vulnerabilities — Cannot Auto-Fix Due to Dependency Conflictaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because applying the fixes creates an unresolvable dependency conflict.
Why this cannot be auto-fixedAll three fixes require upgrading from the langchain 0.x to langchain 1.x ecosystem. This upgrade causes an unresolvable numpy version conflict: Upgrade chain:
Root cause
Recommended next steps
This PR will not be auto-merged until the vulnerability conflict is resolved. |
Security Vulnerabilities — Fix Creates Unsatisfiable Dependency Conflictaieng-bot found the following security vulnerabilities reported by pip-audit. Patched versions exist on PyPI, but applying them creates an irreconcilable dependency conflict in this project.
Why this cannot be auto-fixedAll three fixes require bumping to LangChain 1.x (
There is no version combination of these packages that satisfies both Dependency chain visualizationRecommended next steps
This PR cannot be auto-merged until the dependency conflict is resolved upstream. |
Security Vulnerability — Cannot Auto-Fix Due to Dependency Conflictaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot apply the fixes automatically because they require a major version upgrade of the langchain ecosystem that creates an irresolvable dependency conflict. Vulnerabilities Found
Why This Cannot Be Auto-FixedThe fixes require upgrading
Recommended Next Steps
This PR will not be auto-merged until the vulnerability is resolved. Investigated by aieng-bot on 2026-04-25 |
Security Vulnerabilities — Cannot Be Auto-Fixed (Dependency Conflict)aieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because applying the patches creates an irresolvable dependency conflict:
Why this cannot be auto-fixed: Dependency ConflictAll three fixes require bumping There is no combination of package versions that satisfies both What's needed to unblock thisThe conflict will resolve when one of the following happens:
Once any of the above is resolved, aieng-bot can re-run and apply the security updates automatically. This PR will not be auto-merged. The vulnerability requires human review to resolve the upstream dependency conflict. |
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.0.0 to 8.1.0. - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@cec2083...0880764) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 8.1.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
91f3750 to
e1c3b01
Compare
Bumps astral-sh/setup-uv from 8.0.0 to 8.1.0.
Release notes
Sourced from astral-sh/setup-uv's releases.
Commits
0880764fix: grant contents:write to validate-release job (#860)717d6abAdd a release-gate step to the release workflow (#859)5a911ebDraft commitish releases (#858)080c31eAdd action-types.yml to instructions (#857)b3e97d2Add input no-project in combination with activate-environment (#856)7dd591dchore(deps): bump release-drafter/release-drafter from 7.1.1 to 7.2.0 (#855)1541b77chore: update known checksums for 0.11.7 (#853)cdfb2eeRefactor version resolving (#852)cb84d12chore: update known checksums for 0.11.6 (#850)1912cc6chore: update known checksums for 0.11.5 (#845)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)