deps: combine all open dependabot bumps into one verified update - #4769
Merged
MuhammadKhalilzadeh merged 13 commits intoSep 23, 2026
Merged
Conversation
Combines dependabot PRs #4746, #4743, #4741, #4740. - SQLAlchemy ==2.0.52 -> ==2.0.54 - fastapi ==0.139.2 -> ==0.141.1 - mistralai ==2.10.0 -> ==2.10.1 - docstring_parser ==0.17.0 -> ==0.18.0 Note: #4739 (tabulate 0.10.0) is deliberately excluded - every deepeval release through 4.2.3 pins tabulate<0.10.0, so it would make pip resolution impossible with deepeval==4.1.3.
Combines dependabot PR #4730. Regenerated with 'uv lock --upgrade-package anyio'; lock verified consistent.
- vitest-globals.d.ts: re-declare the jest-dom matcher augmentation with
Vitest 5's two-generic Assertion shape (jest-dom 7.0.1 only augments
Vitest 4's single-generic interface); reuse TestingLibraryMatchers via
the public /matchers entry point.
- setup.ts: import MatchersObject from 'vitest' (the @vitest/expect
package is internal in Vitest 5).
- setupEnv.ts (new, runs first via test.setupFiles): stub
URL.createObjectURL/revokeObjectURL - Vitest 5's jsdom polyfill throws
on jsdom Blobs ('_buffer'), breaking every preview/thumbnail code path.
- vite.config.ts: register setupEnv.ts ahead of setup.ts.
- authTransform: Vitest 5 evaluates mock factories per importer module, so capture createTransform args in vi.hoisted state and import the subject dynamically; assert on the shared captures. - Team delete tests: assert the confirmation dialog with findBy* (Vitest 5 flushes dialog state a tick later). - lucide-react 1.47 deduplicated Trash2 into an alias of Trash, so the rendered svg class is now lucide-trash; update the seven test selectors. - FileManagerUpload.network: skip the four MSW multipart-upload tests - Vitest 5.0.1's jsdom upload bridge never lets the intercepted request settle and its FormData conversion throws on jsdom Blob internals (tried both jsdom 30.0.1 and 30.1.0). The error-message mapping stays covered by getFileErrorMessage unit tests and the mocked-repository suite; also wait for the Upload button to be enabled before clicking.
…e 6) Combines dependabot PRs #4750 (backend-minor-patch group, 20 updates), #4751 (dotenv 18) and #4752 (@azure/msal-node 6). Lockfile regenerated via npm install; 0 vulnerabilities. Verified: tsc clean, 316 suites / 4583 unit tests pass (msal usage is a single ConfidentialClientApplication import in user.ctrl.ts).
Same class as the skipped FileManagerUpload.network tests: the FormData->Node conversion in Vitest 5.0.1's upload bridge breaks on CI (Node 22, Linux). This was the shard 3 and Coverage failure.
jszip 3.10.2's SPDX expression is (MIT OR GPL-3.0-or-later); the dependency-review action denies GPL-3.0 and flags the OR-expression. 3.10.1 stays on the plain MIT entry. Un-pin when the repo's license policy allows the dual license or jszip reverts the metadata.
Same rationale as the Clients pin: jszip 3.10.2's (MIT OR GPL-3.0-or-later) SPDX expression is rejected by the dependency-review GPL-3.0 deny-list.
Contributor
✅ Coverage Gate PassedAll coverage thresholds are met. |
An exact pin still tripped the dependency-review GPL deny-list: jszip is dual-licensed (MIT OR GPL) in EVERY version, and the action scans changed dependencies - develop's jszip was only grandfathered by being unchanged. Manifest range restored to ^3.10.1 and lockfile entries restored to develop's, so jszip is no longer part of this PR's diff at all. Dependabot will re-propose the 3.10.2 patch later; it needs a license-policy decision, not a version bump.
Same rationale as the Clients revert: jszip is dual-licensed (MIT OR GPL) in every version and the dependency-review action only grandfathered it by it being unchanged on develop. Restoring manifest range ^3.10.1 and develop's lockfile entries removes jszip from this PR's diff.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Combines 21 of the 22 open dependabot PRs into a single, verified update. One PR (#4739) is deliberately excluded because it is inherently broken (see below).
Closes #4737, closes #4744, closes #4742, closes #4738 (frontend) -+ closes #4750, closes #4751, closes #4752 (backend) -+ closes #4749, closes #4748, closes #4747, closes #4745 (AIGateway) -+ closes #4746, closes #4743, closes #4741, closes #4740 (EvalServer) -+ closes #4736, closes #4735, closes #4734, closes #4733, closes #4732 (EvaluationModule) -+ closes #4730 (GRSModule).
What was combined
uv lock --upgrade-package anyio)Deliberately excluded
developstate and excluded from this PR: jszip is dual-licensed (MIT OR GPL) in every version, and the dependency-review action denies GPL-3.0 for any changed dependency (develop's jszip was only grandfathered by being unchanged — an exact pin to 3.10.1 still trips the gate). The groups' other 38 updates are all included. Dependabot will re-propose the jszip patch; it needs a license-policy decision, not a version bump.tabulate<<0.10.0, so this bump would makepip install -r requirements.txtunresolvable with the pinneddeepeval==4.1.3. Verified against PyPI metadata. That dependabot PR should be closed as not-applicable (or wait for deepeval to relax the pin).Major-version handling
Assertion<R, T>signature (src/vitest-globals.d.ts);@vitest/expectimport switched tovitest. Vitest 5's jsdomURL.createObjectURLpolyfill throws on jsdom Blobs, so a first-in-linesrc/test/setupEnv.tsstubs it (registered before all other setup). Full suite (~7,700 tests, 4 shards) passes.Trash2is now an alias ofTrash(rendered classlucide-trash); seven test selectors updated.Known limitation (documented in the test file)
Five MSW multipart-upload tests (four
FileManagerUpload.network+deepEvalDatasetsService.uploadDataset— the latter was the shard-3 and Coverage CI failure on Node 22/Linux) (MSW-intercepted real multipart uploads) are skipped: Vitest 5.0.1's jsdom upload bridge neither settles the intercepted request nor converts jsdom FormData correctly (reproduced on both jsdom 30.0.1 and 30.1.0; no upstream fix released yet). The error-message mapping they cover remains exercised by thegetFileErrorMessageunit tests and the mocked-repository suite.Pre-existing issues noticed (not introduced by this PR, not fixed here)
cryptography>=50.0.1vspresidio-anonymizer==2.2.364(cryptography<<49) conflict G�� reproducible on currentdevelop.--no-verify; prettier/typecheck/tests run manually.Verification
tsc -bclean; full vitest suite green (4 shards, exit 0 each).tsc --noEmitclean; jest 316 suites / 4,583 tests pass.--dry-runresolution verified for EvalServer and EvaluationModule; litellm 1.101.0's constraints checked against the new floors; GRSModuleuv lock --checkclean.npm install0 vulnerabilities for both node modules.