Skip to content

Update dependencies to clear Dependabot alerts - #106

Merged
cpmpercussion merged 2 commits into
mainfrom
dependency-updates
Sep 26, 2026
Merged

cpmpercussion merged 2 commits into
mainfrom
dependency-updates

Conversation

@cpmpercussion

Copy link
Copy Markdown
Owner

Replaces the four open Dependabot PRs (#92, #93, #94, #95) and clears all 13 open Dependabot alerts.

Python (poetry update, within the existing pyproject.toml constraints)

  • keras 3.14.1 → 3.15.1: fixes alerts #454–#461 (5 high, 3 medium/low).
  • setuptools 82.0.1 → 84.0.0: fixes #452.
  • Routine updates: ai-edge-litert 2.2.0, ml-dtypes 0.6.0, grpcio 1.84.0, protobuf 7.36.2, click 8.5.0, flake8 7.4.1 / pyflakes 4.0.0, pytest 9.1.1, and others.

Docs (bundle update --conservative json concurrent-ruby)

  • json 2.19.4 → 2.21.2: fixes #453.
  • concurrent-ruby 1.3.6 → 1.3.8: fixes #449–#451.

Checked locally

  • The full test suite passes (192 tests).
  • The conformance vectors still match (python -m impsy.conformance --check), including model.json on ai-edge-litert 2.2.0.
  • CI's flake8 command passes.
  • jekyll build succeeds.

One new test warning: Click 8.5 deprecates CliRunner.isolated_filesystem, which tests/test_commands.py uses. It isn't a problem while Click is pinned below 9.

🤖 Generated with Claude Code

poetry update within the existing pyproject constraints: keras
3.14.1 -> 3.15.1 and setuptools 82.0.1 -> 84.0.0 fix the open alerts,
along with routine updates (ai-edge-litert 2.2.0, ml-dtypes 0.6.0,
click 8.5.0, flake8 7.4.1, pytest 9.1.1, ...).

docs: json 2.19.4 -> 2.21.2 and concurrent-ruby 1.3.6 -> 1.3.8
(bundle update --conservative).

Co-Authored-By: Claude Opus 5.5 <[email protected]>
Copilot AI lite review requested due to automatic review settings September 26, 2026 05:54

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

The conversion tests wrote over the session fixture's .tflite, which
earlier tests may still have loaded. On Windows that fails with
EINVAL because the file is memory-mapped, which started with
ai-edge-litert 2.2.0. Each test now writes to its own tmp_path.

This also fixes the optimised test comparing a file with itself: the
optimised and plain models were saved to the same path.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@cpmpercussion
cpmpercussion merged commit c38d518 into main Sep 26, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants