Skip to content

Validate SQLAlchemy 2.1 server compatibility - #1250

Merged
strickvl merged 3 commits into
developfrom
feat/sqlalchemy-21-compatibility
Oct 5, 2026
Merged

strickvl merged 3 commits into
developfrom
feat/sqlalchemy-21-compatibility

Conversation

@strickvl

@strickvl strickvl commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

The server extra can now install SQLAlchemy 2.1. The constraint keeps working 2.0 releases available and excludes only 2.1.0, whose source package has malformed extras metadata. The lock selects 2.1.1, which fixes that upstream packaging issue.

Updated single-entity query annotations for SQLAlchemy 2.1's result typing, declared the existing non-null replay grouping expression with NotNullable, and preserved the nullable heartbeat return type. The clean plugin artifact smoke now exercises the async runtime and prints its SQLAlchemy and greenlet versions.

Fixes #1199.

Reviewer Notes

The database queries and transaction settings retain their existing behavior. Focus on the query annotations and the retained [asyncio] extra. NotNullable is a runtime identity operation available before the retained 2.0.51 minimum.

Reproduction

Run the normal PostgreSQL core suite and migration check with the refreshed lock:

uv sync --frozen --all-extras --group fuzz
docker compose up -d db
KITARU_TEST_REQUIRE_POSTGRES=1 HYPOTHESIS_PROFILE=ci uv run --no-sync pytest --ignore=tests/cli --ignore=tests/mcp --ignore=tests/typescript
just migration-check
UV_NO_BINARY_PACKAGE=sqlalchemy just plugin-artifact-smoke

For the installed-wheel e2e path, follow the candidate-wheel installation steps in the quickstart-example CI job, install sqlalchemy[asyncio]==2.1.1 into the example environment, then run UV_NO_SYNC=1 .venv/bin/python scripts/run_ci_e2e.py from examples/python/pydantic_ai_ticket_resolver/. This exercises import, worker evaluation, investigation, annotation, and cohort creation without model-provider calls.

Validation

  • PostgreSQL-required core suite: 4,530 passed, 358 skipped.
  • Affected repository tests: 322 passed on each of SQLAlchemy 2.1.1 and 2.0.51.
  • Installed-wheel quickstart e2e on SQLAlchemy 2.1.1: passed.
  • just check, migration check, CLI artifact smoke, and all-package plugin artifact smoke with a forced SQLAlchemy source build: passed.
  • SQLAlchemy probe tests: 6 passed.

Branch refresh (October 2)

Merged current develop (77baa9919) and retained the SQLAlchemy 2.1.1 lock while incorporating PyJWT 2.15.0 and urllib3 2.8.0 from the shared security fix. No unrelated locked dependencies were upgraded.

  • just check and just audit: passed.
  • Full PostgreSQL-required suite under the CI Hypothesis profile: 5,566 passed, 32 skipped, 19 expected failures. Six cross-language tests initially failed during setup because Node dependencies were missing; after frozen pnpm installation, all 16 cross-language tests passed.
  • All-package plugin artifact smoke: passed, including an async SQLAlchemy 2.1.2 runtime installed through the wheel requirements.

CI is green on 197443def: all 38 checks completed without failures. The dependency audit passed with the security updates from develop.

@strickvl
strickvl requested a review from schustmi September 30, 2026 20:25
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T10:08:08.143745Z 310c1f4 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@socket-security

socket-security Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedpypi/​sqlalchemy@​2.1.197100100100100

View full report

@strickvl
strickvl requested a review from AlexejPenner October 1, 2026 05:34

@AlexejPenner AlexejPenner left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🦭

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 197443def9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread pyproject.toml
server = [
"fastapi>=0.139",
"sqlalchemy[asyncio]>=2.0.51,<2.1",
"sqlalchemy[asyncio]>=2.0.51,!=2.1.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Refresh the plugin workspace lock for SQLAlchemy 2.1

Regenerate plugins/uv.lock alongside this constraint change. The plugin CI job runs uv sync --project plugins --frozen (.github/workflows/ci.yml:378), and uv sync --help defines --frozen as syncing without updating the lock; the committed plugin lock still records >=2.0.51,<2.1 and selects 2.0.51 (plugins/uv.lock:1396,3202-3204). Consequently, the plugin suite continues exercising SQLAlchemy 2.0 rather than the newly supported 2.1 dependency, and the workspace lock no longer represents its editable Kitaru source metadata.

AGENTS.md reference: plugins/AGENTS.md:L23-L24

Useful? React with 👍 / 👎.

# Conflicts:
#	src/kitaru/server/adapters/db/repositories/task_repository.py
@strickvl
strickvl merged commit 720a529 into develop Oct 5, 2026
38 checks passed
@strickvl
strickvl deleted the feat/sqlalchemy-21-compatibility branch October 5, 2026 10:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validate SQLAlchemy 2.1 and remove the temporary server cap

3 participants