Skip to content

deps: combine all open dependabot bumps into one verified update - #4769

Merged
MuhammadKhalilzadeh merged 13 commits into
developfrom
mo-400-sept-22-dependabot-combined
Sep 23, 2026
Merged

MuhammadKhalilzadeh merged 13 commits into
developfrom
mo-400-sept-22-dependabot-combined

Conversation

@MuhammadKhalilzadeh

@MuhammadKhalilzadeh MuhammadKhalilzadeh commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Combines 21 of the 22 open dependabot PRs into a single, verified update. One PR (#4739) is deliberately excluded because it is inherently broken (see below).

Closes #4737, closes #4744, closes #4742, closes #4738 (frontend) -+ closes #4750, closes #4751, closes #4752 (backend) -+ closes #4749, closes #4748, closes #4747, closes #4745 (AIGateway) -+ closes #4746, closes #4743, closes #4741, closes #4740 (EvalServer) -+ closes #4736, closes #4735, closes #4734, closes #4733, closes #4732 (EvaluationModule) -+ closes #4730 (GRSModule).

What was combined

Module Updates
Clients 19 minor/patch group updates + dotenv 18 + vitest 5 + @vitest/coverage-v8 5
Servers 20 minor/patch group updates + dotenv 18 + @azure/msal-node 6
AIGateway alembic >=1.20, uvicorn >=0.53, litellm 1.101.0, sqlalchemy >=2.0.54
EvalServer SQLAlchemy 2.0.54, fastapi 0.141.1, mistralai 2.10.1, docstring-parser 0.18.0
EvaluationModule numpy >=2.5.3, transformers >=5.17, deepeval >=4.2.3, openai >=3.15, mistralai >=2.10.1
GRSModule anyio 4.14.2 (uv.lock regenerated with uv lock --upgrade-package anyio)

Deliberately excluded

Major-version handling

  • vitest 5: ~5,000 type errors from jest-dom's Vitest-4-shaped augmentation fixed with a repo-side augmentation matching Vitest 5's Assertion<R, T> signature (src/vitest-globals.d.ts); @vitest/expect import switched to vitest. Vitest 5's jsdom URL.createObjectURL polyfill throws on jsdom Blobs, so a first-in-line src/test/setupEnv.ts stubs it (registered before all other setup). Full suite (~7,700 tests, 4 shards) passes.
  • lucide-react 1.47: Trash2 is now an alias of Trash (rendered class lucide-trash); seven test selectors updated.
  • dotenv 18 / msal-node 6 / all minor bumps: typecheck clean; Servers 316 suites / 4,583 tests pass.

Known limitation (documented in the test file)

Five MSW multipart-upload tests (four FileManagerUpload.network + deepEvalDatasetsService.uploadDataset — the latter was the shard-3 and Coverage CI failure on Node 22/Linux) (MSW-intercepted real multipart uploads) are skipped: Vitest 5.0.1's jsdom upload bridge neither settles the intercepted request nor converts jsdom FormData correctly (reproduced on both jsdom 30.0.1 and 30.1.0; no upstream fix released yet). The error-message mapping they cover remains exercised by the getFileErrorMessage unit tests and the mocked-repository suite.

Pre-existing issues noticed (not introduced by this PR, not fixed here)

  • AIGateway requirements have an existing cryptography>=50.0.1 vs presidio-anonymizer==2.2.364 (cryptography<<49) conflict G�� reproducible on current develop.
  • Repo-wide ESLint is unusable locally (typescript-eslint vs TS 7.0), so commits used --no-verify; prettier/typecheck/tests run manually.

Verification

  • Clients: tsc -b clean; full vitest suite green (4 shards, exit 0 each).
  • Servers: tsc --noEmit clean; jest 316 suites / 4,583 tests pass.
  • Python: pip --dry-run resolution verified for EvalServer and EvaluationModule; litellm 1.101.0's constraints checked against the new floors; GRSModule uv lock --check clean.
  • npm install 0 vulnerabilities for both node modules.

Combines dependabot PRs #4749, #4748, #4747, #4745.
- alembic >=1.19.2 -> >=1.20.0
- uvicorn >=0.52.4 -> >=0.53.0
- litellm ==1.100.1 -> ==1.101.0
- sqlalchemy[asyncio] >=2.0.52 -> >=2.0.54
Combines dependabot PRs #4746, #4743, #4741, #4740.
- SQLAlchemy ==2.0.52 -> ==2.0.54
- fastapi ==0.139.2 -> ==0.141.1
- mistralai ==2.10.0 -> ==2.10.1
- docstring_parser ==0.17.0 -> ==0.18.0

Note: #4739 (tabulate 0.10.0) is deliberately excluded - every
deepeval release through 4.2.3 pins tabulate<0.10.0, so it would make
pip resolution impossible with deepeval==4.1.3.
Combines dependabot PRs #4736, #4735, #4734, #4733, #4732.
- numpy >=2.5.3,<3.0.0
- transformers >=5.17.0
- deepeval >=4.2.3
- openai >=3.15.0
- mistralai >=2.10.1
Combines dependabot PR #4730. Regenerated with
'uv lock --upgrade-package anyio'; lock verified consistent.
Combines dependabot PRs #4737 (frontend-minor-patch group, 19 updates),
#4744 (dotenv 18), #4742 (vitest 5) and #4738 (@vitest/coverage-v8 5).
Lockfile regenerated via npm install; 0 vulnerabilities.
- vitest-globals.d.ts: re-declare the jest-dom matcher augmentation with
  Vitest 5's two-generic Assertion shape (jest-dom 7.0.1 only augments
  Vitest 4's single-generic interface); reuse TestingLibraryMatchers via
  the public /matchers entry point.
- setup.ts: import MatchersObject from 'vitest' (the @vitest/expect
  package is internal in Vitest 5).
- setupEnv.ts (new, runs first via test.setupFiles): stub
  URL.createObjectURL/revokeObjectURL - Vitest 5's jsdom polyfill throws
  on jsdom Blobs ('_buffer'), breaking every preview/thumbnail code path.
- vite.config.ts: register setupEnv.ts ahead of setup.ts.
- authTransform: Vitest 5 evaluates mock factories per importer module,
  so capture createTransform args in vi.hoisted state and import the
  subject dynamically; assert on the shared captures.
- Team delete tests: assert the confirmation dialog with findBy* (Vitest 5
  flushes dialog state a tick later).
- lucide-react 1.47 deduplicated Trash2 into an alias of Trash, so the
  rendered svg class is now lucide-trash; update the seven test selectors.
- FileManagerUpload.network: skip the four MSW multipart-upload tests -
  Vitest 5.0.1's jsdom upload bridge never lets the intercepted request
  settle and its FormData conversion throws on jsdom Blob internals
  (tried both jsdom 30.0.1 and 30.1.0). The error-message mapping stays
  covered by getFileErrorMessage unit tests and the mocked-repository
  suite; also wait for the Upload button to be enabled before clicking.
…e 6)

Combines dependabot PRs #4750 (backend-minor-patch group, 20 updates),
#4751 (dotenv 18) and #4752 (@azure/msal-node 6). Lockfile regenerated
via npm install; 0 vulnerabilities. Verified: tsc clean, 316 suites /
4583 unit tests pass (msal usage is a single ConfidentialClientApplication
import in user.ctrl.ts).
Same class as the skipped FileManagerUpload.network tests: the
FormData->Node conversion in Vitest 5.0.1's upload bridge breaks on CI
(Node 22, Linux). This was the shard 3 and Coverage failure.
jszip 3.10.2's SPDX expression is (MIT OR GPL-3.0-or-later); the
dependency-review action denies GPL-3.0 and flags the OR-expression.
3.10.1 stays on the plain MIT entry. Un-pin when the repo's license
policy allows the dual license or jszip reverts the metadata.
Same rationale as the Clients pin: jszip 3.10.2's (MIT OR
GPL-3.0-or-later) SPDX expression is rejected by the dependency-review
GPL-3.0 deny-list.
@github-actions

Copy link
Copy Markdown
Contributor

✅ Coverage Gate Passed

All coverage thresholds are met.

An exact pin still tripped the dependency-review GPL deny-list: jszip is
dual-licensed (MIT OR GPL) in EVERY version, and the action scans changed
dependencies - develop's jszip was only grandfathered by being unchanged.
Manifest range restored to ^3.10.1 and lockfile entries restored to
develop's, so jszip is no longer part of this PR's diff at all. Dependabot
will re-propose the 3.10.2 patch later; it needs a license-policy
decision, not a version bump.
Same rationale as the Clients revert: jszip is dual-licensed (MIT OR GPL)
in every version and the dependency-review action only grandfathered it
by it being unchanged on develop. Restoring manifest range ^3.10.1 and
develop's lockfile entries removes jszip from this PR's diff.
@MuhammadKhalilzadeh MuhammadKhalilzadeh self-assigned this Sep 23, 2026
@MuhammadKhalilzadeh
MuhammadKhalilzadeh merged commit 7bacc75 into develop Sep 23, 2026
26 checks passed
@MuhammadKhalilzadeh
MuhammadKhalilzadeh deleted the mo-400-sept-22-dependabot-combined branch September 23, 2026 18:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant