Bump pandas from 2.3.3 to 3.0.6 - #209
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [pandas](https://github.com/pandas-dev/pandas) from 2.3.3 to 3.0.6. - [Release notes](https://github.com/pandas-dev/pandas/releases) - [Commits](pandas-dev/pandas@v2.3.3...v3.0.6) --- updated-dependencies: - dependency-name: pandas dependency-version: 3.0.6 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]>
villelaitila
left a comment
There was a problem hiding this comment.
Flagging a couple of concerns before this gets merged — the diff itself is a one-liner, but it's a major-version bump (2.3.3 → 3.0.6) and deserves more scrutiny than a typical Dependabot patch:
1. Python version conflict. Pandas' own release notes (quoted in this PR's description) state: "Pandas 3.0 supports Python 3.11 and higher." This repo's setup.cfg still declares python_requires = >=3.8 and lists classifiers for Python 3.8, 3.9, and 3.10. Pinning pandas==3.0.6 in requirements.txt means pip install -r requirements.txt (the documented dev setup in CLAUDE.md) will fail outright on Python 3.8–3.10, even though the package metadata still claims to support them. Either the Python floor needs to be raised to 3.11 across setup.cfg/classifiers/docs, or this bump should be held until 3.8–3.10 support is formally dropped.
2. No CI safety net for this bump. The only workflow in .github/workflows/ is ai-codereviewer.yml — there's no automated pytest run gating this PR. Pandas 3.0 has real breaking changes (Copy-on-Write is now always on, a new default string dtype replaces object for text columns, several deprecated APIs were removed), and the codebase does exercise pandas fairly directly (src/sgraph/cypher.py's _extract_subgraph/_dataframe_to_serializable, and src/sgraph/attributes/attributequeries.py's read_attrs/read_csv_attrs, including .transpose() and df.to_dict() on CSV-loaded frames). None of that gets exercised automatically before merge, so this should be validated by running the test suite locally against pandas 3.0.6 rather than merged on the strength of the compatibility badge alone.
Given both points, I'd hold off auto-merging this one until someone confirms the test suite passes under 3.0.6 and the Python-version support story is resolved.
Generated by Claude Code
Bumps pandas from 2.3.3 to 3.0.6.
Release notes
Sourced from pandas's releases.
... (truncated)
Commits
2905718RLS: 3.0.63188ced[backport 3.0.x] BUG: read_csv(sep=None) raised TypeError instead of falling...f097905DOC: cleanup 3.0.6 whatsnew + mention Python 3.15 support (#68965) (#68969)4f68223[backport 3.0.x] BUG: fix setting with bool column mask into 1-column DataFra...e3df0e8[backport 3.0.x] BUG: full-slice setitem into a pyarrow-backed array shared m...b7735f6Backport PR #66117 on branch 3.0.x (BUG: interpolate leaving NAs unfilled for...bca0b77[backport 3.0.x] BUG: read_csv leaked the string-intern table when a column f...bca1e5d[backport 3.0.x] BUG: prevent external mutation of RangeIndex._data (CoW) (#6...c95b42c[3.0.x] CI: skip cython-lint on pre-commit.ci (#68910)9cbd884[backport 3.0.x] Backport of some already merged regression fixes (#68447)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)