-
Notifications
You must be signed in to change notification settings - Fork 808
chore(deps-dev): bump the gha group across 1 directory with 8 updates #3334
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
chore(deps-dev): bump the gha group across 1 directory with 8 updates #3334
Conversation
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Note Free review on us!CodeRabbit is offering free reviews until Wed Oct 08 2025 to showcase some of the refinements we've made. Comment |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Important
Looks good to me! 👍
Reviewed everything up to 39ca809 in 2 minutes and 35 seconds. Click for details.
- Reviewed
26
lines of code in1
files - Skipped
1
files when reviewing. - Skipped posting
4
draft comments. View those below. - Modify your settings and rules to customize what types of comments Ellipsis leaves. And don't forget to react with 👍 or 👎 to teach Ellipsis.
1. packages/opentelemetry-instrumentation-openai/pyproject.toml:34
- Draft comment:
flake8 updated to 7.3.0 looks good. Consider using a caret operator (e.g.^7.3.0
) for consistency with other dependencies to allow patch updates automatically. - Reason this comment was not posted:
Decided after close inspection that this draft comment was likely wrong and/or not actionable: usefulness confidence = 0% vs. threshold = 50% While the comment is technically correct about inconsistency in version specification, it's about dependency management which is explicitly mentioned in the rules as something we should not comment on. The rules state "Do NOT comment on dependency changes, library versions that you don't recognize, or anything else related to dependencies." The suggestion would improve consistency in the codebase. Maybe dependency format standardization is important enough to warrant an exception to the rule? No, the rules are clear about not commenting on dependencies. This is exactly the kind of comment the rules are trying to prevent. The comment should be deleted as it violates the explicit rule against commenting on dependency-related matters.
2. packages/opentelemetry-instrumentation-openai/pyproject.toml:39
- Draft comment:
The vcrpy dependency now uses a range (>=6.0.1,<8.0.0) which allows 6.x and 7.x versions. Given the release notes mention upgrading from 6.0.2 to 7.0.0, please verify if the lower bound should be raised to 7.0.0 to enforce use of the new major release. - Reason this comment was not posted:
Decided after close inspection that this draft comment was likely wrong and/or not actionable: usefulness confidence = 0% vs. threshold = 50% This is a dependency version suggestion. According to the rules, we should NOT comment on dependency changes or library versions we don't recognize. The comment is speculative ("please verify if...") and asks the author to check something. Both of these are explicitly against the rules. The comment might be pointing out a legitimate compatibility issue between major versions that could cause problems. Even if there are compatibility concerns, the rules explicitly state not to comment on dependency changes. The author likely has their reasons for allowing both 6.x and 7.x versions. Delete this comment as it violates multiple rules: it's about dependencies, it's speculative, and it asks the author to verify something.
3. packages/opentelemetry-instrumentation-openai/pyproject.toml:41
- Draft comment:
openai has been updated to 1.101.0. Please ensure that any breaking changes in OpenAI’s API are properly handled by the instrumentation. - Reason this comment was not posted:
Comment did not seem useful. Confidence is useful =0%
<= threshold50%
This comment is about a dependency update and asks the PR author to ensure that breaking changes are handled. This violates the rule against commenting on dependency changes and asking the author to ensure behavior is intended.
4. packages/opentelemetry-instrumentation-openai/pyproject.toml:43
- Draft comment:
pytest-asyncio now uses the range ">=0.23.7,<1.2.0", which allows versions below 1.2.0, including 1.1.0. Note that the release notes mention updating from 0.23.8; consider if the lower bound should be bumped to 0.23.8 for consistency. - Reason this comment was not posted:
Decided after close inspection that this draft comment was likely wrong and/or not actionable: usefulness confidence = 10% vs. threshold = 50% According to the rules, we should NOT comment on dependency changes or library versions we don't recognize. The comment is purely about dependency versioning. There's no clear evidence that this change is required for functionality. It's a minor version bump suggestion that doesn't clearly impact code behavior. The comment might be pointing out a legitimate compatibility issue between versions. Maybe there's a known bug in version 0.23.7 that could cause problems. Without clear evidence of a critical issue, this falls under the rule about not commenting on dependency changes. The suggestion is speculative and not clearly necessary. Delete the comment as it violates the rule about not commenting on dependency changes and versions.
Workflow ID: wflow_Rh3aHAo89FIPXGyu
You can customize by changing your verbosity settings, reacting with 👍 or 👎, replying to comments, or adding code review rules.
0d246a1
to
d7a60b7
Compare
d54a85f
to
49e77d5
Compare
fa59214
to
46486d3
Compare
46486d3
to
5bc2aca
Compare
Bumps the gha group with 8 updates in the /packages/opentelemetry-instrumentation-openai directory: | Package | From | To | | --- | --- | --- | | [flake8](https://github.com/pycqa/flake8) | `7.0.0` | `7.3.0` | | [pytest](https://github.com/pytest-dev/pytest) | `8.3.3` | `8.4.1` | | [pytest-sugar](https://github.com/Teemu/pytest-sugar) | `1.0.0` | `1.1.0` | | [vcrpy](https://github.com/kevin1024/vcrpy) | `6.0.2` | `7.0.0` | | [pytest-recording](https://github.com/kiwicom/pytest-recording) | `0.13.2` | `0.13.4` | | [openai](https://github.com/openai/openai-python) | `1.99.7` | `1.101.0` | | [pytest-asyncio](https://github.com/pytest-dev/pytest-asyncio) | `0.23.8` | `1.1.0` | | [requests](https://github.com/psf/requests) | `2.32.4` | `2.32.5` | Updates `flake8` from 7.0.0 to 7.3.0 - [Commits](PyCQA/flake8@7.0.0...7.3.0) Updates `pytest` from 8.3.3 to 8.4.1 - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst) - [Commits](pytest-dev/pytest@8.3.3...8.4.1) Updates `pytest-sugar` from 1.0.0 to 1.1.0 - [Release notes](https://github.com/Teemu/pytest-sugar/releases) - [Changelog](https://github.com/Teemu/pytest-sugar/blob/main/CHANGES.rst) - [Commits](Teemu/pytest-sugar@v1.0.0...v1.1.0) Updates `vcrpy` from 6.0.2 to 7.0.0 - [Release notes](https://github.com/kevin1024/vcrpy/releases) - [Changelog](https://github.com/kevin1024/vcrpy/blob/master/docs/changelog.rst) - [Commits](kevin1024/vcrpy@v6.0.2...v7.0.0) Updates `pytest-recording` from 0.13.2 to 0.13.4 - [Release notes](https://github.com/kiwicom/pytest-recording/releases) - [Changelog](https://github.com/kiwicom/pytest-recording/blob/master/docs/changelog.rst) - [Commits](kiwicom/pytest-recording@v0.13.2...v0.13.4) Updates `openai` from 1.99.7 to 1.101.0 - [Release notes](https://github.com/openai/openai-python/releases) - [Changelog](https://github.com/openai/openai-python/blob/main/CHANGELOG.md) - [Commits](openai/openai-python@v1.99.7...v1.101.0) Updates `pytest-asyncio` from 0.23.8 to 1.1.0 - [Release notes](https://github.com/pytest-dev/pytest-asyncio/releases) - [Commits](pytest-dev/pytest-asyncio@v0.23.8...v1.1.0) Updates `requests` from 2.32.4 to 2.32.5 - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.32.4...v2.32.5) --- updated-dependencies: - dependency-name: flake8 dependency-version: 7.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: gha - dependency-name: pytest dependency-version: 8.4.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: gha - dependency-name: pytest-sugar dependency-version: 1.1.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: gha - dependency-name: vcrpy dependency-version: 7.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: gha - dependency-name: pytest-recording dependency-version: 0.13.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: gha - dependency-name: openai dependency-version: 1.101.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: gha - dependency-name: pytest-asyncio dependency-version: 1.1.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: gha - dependency-name: requests dependency-version: 2.32.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: gha ... Signed-off-by: dependabot[bot] <[email protected]>
5bc2aca
to
755aa34
Compare
Bumps the gha group with 8 updates in the /packages/opentelemetry-instrumentation-openai directory:
7.0.0
7.3.0
8.3.3
8.4.1
1.0.0
1.1.0
6.0.2
7.0.0
0.13.2
0.13.4
1.99.7
1.101.0
0.23.8
1.1.0
2.32.4
2.32.5
Updates
flake8
from 7.0.0 to 7.3.0Commits
c48217e
Release 7.3.0f9e0f33
Merge pull request #1986 from PyCQA/document-f5426bcdb62
document F54270a15b8
Merge pull request #1985 from PyCQA/upgrade-deps4941a3e
upgrade pyflakes / pycodestyle23e4005
Merge pull request #1983 from PyCQA/py314019424b
add support for t-strings6b6f3d5
Merge pull request #1980 from PyCQA/asottile-patch-18dfa669
add rtd sphinx configce34111
Merge pull request #1976 from PyCQA/document-f824Updates
pytest
from 8.3.3 to 8.4.1Release notes
Sourced from pytest's releases.
... (truncated)
Commits
8d99211
Prepare release version 8.4.15dc5880
docs: update pytest.ini addopts example to use separate -p entries (#13529) (...d0c7ed0
Reintroduce PytestReturnNotNoneWarning (#13495) (#13527)a1b3a78
Fix compatibility with Twisted 25 (#13502) (#13531)4c161ab
pytester: avoid unraisableexception gc collects in inline runs to speed up te...a86ee09
Fix typo in parametrize.rst (#13514) (#13516)1a0581b
Remove outdated warning about faulthandler_timeout on Windows (#13492) (#13493)4e631a7
Merge pull request #13486 from hosmir/fixtypo (#13487)b49745e
fix: support TerminalReporter.isatty being called (#13462) (#13483)cc5ceed
RELEASING: remove pytest mailing list (#13472) (#13473)Updates
pytest-sugar
from 1.0.0 to 1.1.0Release notes
Sourced from pytest-sugar's releases.
Changelog
Sourced from pytest-sugar's changelog.
Commits
43bbdd0
Release pytest-sugar 1.1.0855d661
Feature - Playwright Support for Trace Zip Mapping (#296)2a5862a
Merge pull request #293 from cgoldberg/add-py313ca26d98
Add support for Python 3.1369989eb
Clarify license as BSD 3-Clause License3c86a5c
Merge pull request #289 from deronnax/remove-packaging-depc123be0
remove 'packaging' packageefafd9c
Merge pull request #282 from penguinpee/main536c1a8
Fix license stringUpdates
vcrpy
from 6.0.2 to 7.0.0Release notes
Sourced from vcrpy's releases.
Changelog
Sourced from vcrpy's changelog.
... (truncated)
Commits
3278619
Release v7.0.03fb62e0
fix: correctly handle asyncio.run when loop exists8197865
build(deps): update sphinx requirement from <8 to <9be651bd
pre-commit: Autoupdatea6698ed
Fix aiohttp tests48d0a2e
Fixed missingversion_string
attribute when used with urllib3>=2.3.05b858b1
Fix lintc8d99a9
Fix ruff configurationce27c63
Merge pull request #736 from kevin1024/drop-python38ab8944d
Drop python 3.8 supportUpdates
pytest-recording
from 0.13.2 to 0.13.4Release notes
Sourced from pytest-recording's releases.
Changelog
Sourced from pytest-recording's changelog.
Commits
c2d2db7
chore: Release 0.13.4cf919c9
test: Run tests on Windowsb8b45b7
fix: Use fallback for max filename length on Windows8a7e19f
docs: Update README.rst3ad7910
chore: Release 0.13.39a6e12c
docs: Add a note for package maintainersa70532b
chore: Revert "test: Disable pretty plugin in pytest"6b84832
chore(deps): update codecov/codecov-action action to v5.4.2460a7f9
test: Add long_cassette_name test9822a50
fix: Checkdefault_cassette
to prevent it from being too long.Updates
openai
from 1.99.7 to 1.101.0Release notes
Sourced from openai's releases.
... (truncated)
Changelog
Sourced from openai's changelog.
... (truncated)
Commits
4e28a42
release: 1.101.0 (#2577)e328fb4
release: 1.100.372e0ad6
chore(internal/ci): setup breaking change detection4ada66f
release: 1.100.2a94bd5b
chore(api): accurately represent shape for verbosity on Chat Completionsf889071
release: 1.100.1b3547d6
fix(types): revert response text config deletionadb1af8
release: 1.100.00843a11
feat(api): add new text parameters, expiration options34014ae
release: 1.99.9Updates
pytest-asyncio
from 0.23.8 to 1.1.0Release notes
Sourced from pytest-asyncio's releases.
... (truncated)
Commits
ce06c07
chore: Prepare release of v1.1.0.d9a8dcc
ci: Workaround missing Tag annotation during release.d66e12f
[pre-commit.ci] pre-commit autoupdate9e5e25f
Build(deps): Bump certifi in /dependencies/docs0e63423
Build(deps): Bump hypothesis in /dependencies/defaultbd4551c
Build(deps): Bump ncipollo/release-action from 1.16.0 to 1.18.08e20305
Build(deps): Bump hypothesis in /dependencies/defaultb7a8ab5
Build(deps): Bump coverage from 7.9.1 to 7.9.2 in /dependencies/default8cc378d
Build(deps): Bump typing-extensions in /dependencies/defaultfb6bfbf
[pre-commit.ci] pre-commit autoupdateUpdates
requests
from 2.32.4 to 2.32.5Release notes
Sourced from requests's releases.
Changelog
Sourced from requests's changelog.
Commits
b25c87d
v2.32.5131e506
Merge pull request #7010 from psf/dependabot/github_actions/actions/checkout-...b336cb2
Bump actions/checkout from 4.2.0 to 5.0.046e939b
Update publish workflow to useartifact-id
instead ofname
4b9c546
Merge pull request #6999 from psf/dependabot/github_actions/step-security/har...7618dbe
Bump step-security/harden-runner from 2.12.0 to 2.13.02edca11
Add support for Python 3.14 and drop support for Python 3.8 (#6993)fec96cd
Update Makefile rules (#6996)d58d8aa
docs: clarify timeout parameter uses seconds in Session.request (#6994)91a3eab
Bump github/codeql-action from 3.28.5 to 3.29.0You can trigger a rebase of this PR by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditionsImportant
Bumps development dependencies in
pyproject.toml
foropentelemetry-instrumentation-openai
to latest versions.flake8
updated from 7.0.0 to 7.3.0.pytest
updated from 8.3.3 to 8.4.1.pytest-sugar
updated from 1.0.0 to 1.1.0.vcrpy
updated from 6.0.2 to 7.0.0.pytest-recording
updated from 0.13.2 to 0.13.4.openai
updated from 1.99.7 to 1.101.0.pytest-asyncio
updated from 0.23.8 to 1.1.0.requests
updated from 2.32.4 to 2.32.5.This description was created by
for 39ca809. You can customize this summary. It will automatically update as commits are pushed.