Skip to content

Batch the open Dependabot updates - #688

Merged
josephjclark merged 4 commits into
release/nextfrom
dependency-updates
Sep 18, 2026
Merged

josephjclark merged 4 commits into
release/nextfrom
dependency-updates

Conversation

@hanna-paasivirta

@hanna-paasivirta hanna-paasivirta commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Short Description

Batches the open Dependabot PRs into one branch to test once.

Implementation Details

Cut from release/next and targets it.

All four can be closed once this lands.

dependabot Bot and others added 3 commits September 17, 2026 18:09
Bumps the python-minor-patch group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |
| [langchain-core](https://github.com/langchain-ai/langchain) | `1.5.1` | `1.6.3` |
| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.4.1` | `1.6.2` |
| [nltk](https://github.com/nltk/nltk) | `3.10.0` | `3.10.3` |
| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.66.1` | `2.69.1` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` |
| [langfuse](https://github.com/langfuse/langfuse) | `4.14.1` | `4.15.2` |
| [opentelemetry-instrumentation-anthropic](https://github.com/traceloop/openllmetry) | `0.62.1` | `0.62.3` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.0` | `0.16.7` |



Updates `python-dotenv` from 1.2.2 to 1.2.3
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.2...v1.2.3)

Updates `langchain-core` from 1.5.1 to 1.6.3
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-core==1.5.1...langchain-core==1.6.3)

Updates `langchain-openai` from 1.4.1 to 1.6.2
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-openai==1.4.1...langchain-openai==1.6.2)

Updates `nltk` from 3.10.0 to 3.10.3
- [Release notes](https://github.com/nltk/nltk/releases)
- [Changelog](https://github.com/nltk/nltk/blob/develop/ChangeLog)
- [Commits](nltk/nltk@v3.10.0...v3.10.3)

Updates `sentry-sdk` from 2.66.1 to 2.69.1
- [Release notes](https://github.com/getsentry/sentry-python/releases)
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-python@2.66.1...2.69.1)

Updates `psycopg2-binary` from 2.9.12 to 2.9.13
- [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS)
- [Commits](psycopg/psycopg2@2.9.12...2.9.13)

Updates `langfuse` from 4.14.1 to 4.15.2
- [Release notes](https://github.com/langfuse/langfuse/releases)
- [Commits](https://github.com/langfuse/langfuse/commits)

Updates `opentelemetry-instrumentation-anthropic` from 0.62.1 to 0.62.3
- [Release notes](https://github.com/traceloop/openllmetry/releases)
- [Changelog](https://github.com/traceloop/openllmetry/blob/main/CHANGELOG.md)
- [Commits](traceloop/openllmetry@0.62.1...0.62.3)

Updates `ruff` from 0.16.0 to 0.16.7
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.0...0.16.7)

---
updated-dependencies:
- dependency-name: python-dotenv
  dependency-version: 1.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: langchain-core
  dependency-version: 1.6.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: langchain-openai
  dependency-version: 1.6.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: nltk
  dependency-version: 3.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: sentry-sdk
  dependency-version: 2.69.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: psycopg2-binary
  dependency-version: 2.9.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: langfuse
  dependency-version: 4.15.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: opentelemetry-instrumentation-anthropic
  dependency-version: 0.62.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: ruff
  dependency-version: 0.16.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [docker/login-action](https://github.com/docker/login-action) from 4 to 4.5.2.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v4...v4.5.2)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.5.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@hanna-paasivirta
hanna-paasivirta marked this pull request as ready for review September 17, 2026 18:33
@hanna-paasivirta

Copy link
Copy Markdown
Contributor Author

@josephjclark I have tested these, am I ok to merge these into your release branch?

@josephjclark

Copy link
Copy Markdown
Collaborator

Perfect, I was going to exaclty this. Thanks!

@josephjclark
josephjclark merged commit 5f38c24 into release/next Sep 18, 2026
3 checks passed
@josephjclark
josephjclark deleted the dependency-updates branch September 18, 2026 07:10
josephjclark added a commit that referenced this pull request Sep 23, 2026
* embed_docsite: rewrite to use git clone (#685)

* embed_docsite: download docsite via git clone instead of GitHub contents API (#627)

* feat: download docsite via git clone instead of the GitHub contents API

* perf: clone the docsite blobless and sparse

* fix: raise ApolloError on empty docs checkout and skip unreadable files

* refactor: drop private underscores and memoize the docs sync with functools.cache

* refactor: fold docs_repo into github_utils with public API at the top

* test: assert corpus invariants instead of exact docsite file counts

* changeset

---------

Co-authored-by: Isaac <ong.izo.zh@gmail.com>

* Batch the open Dependabot updates (#688)

* Bump the python-minor-patch group across 1 directory with 9 updates

Bumps the python-minor-patch group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |
| [langchain-core](https://github.com/langchain-ai/langchain) | `1.5.1` | `1.6.3` |
| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.4.1` | `1.6.2` |
| [nltk](https://github.com/nltk/nltk) | `3.10.0` | `3.10.3` |
| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.66.1` | `2.69.1` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` |
| [langfuse](https://github.com/langfuse/langfuse) | `4.14.1` | `4.15.2` |
| [opentelemetry-instrumentation-anthropic](https://github.com/traceloop/openllmetry) | `0.62.1` | `0.62.3` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.0` | `0.16.7` |



Updates `python-dotenv` from 1.2.2 to 1.2.3
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.2...v1.2.3)

Updates `langchain-core` from 1.5.1 to 1.6.3
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-core==1.5.1...langchain-core==1.6.3)

Updates `langchain-openai` from 1.4.1 to 1.6.2
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-openai==1.4.1...langchain-openai==1.6.2)

Updates `nltk` from 3.10.0 to 3.10.3
- [Release notes](https://github.com/nltk/nltk/releases)
- [Changelog](https://github.com/nltk/nltk/blob/develop/ChangeLog)
- [Commits](nltk/nltk@v3.10.0...v3.10.3)

Updates `sentry-sdk` from 2.66.1 to 2.69.1
- [Release notes](https://github.com/getsentry/sentry-python/releases)
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-python@2.66.1...2.69.1)

Updates `psycopg2-binary` from 2.9.12 to 2.9.13
- [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS)
- [Commits](psycopg/psycopg2@2.9.12...2.9.13)

Updates `langfuse` from 4.14.1 to 4.15.2
- [Release notes](https://github.com/langfuse/langfuse/releases)
- [Commits](https://github.com/langfuse/langfuse/commits)

Updates `opentelemetry-instrumentation-anthropic` from 0.62.1 to 0.62.3
- [Release notes](https://github.com/traceloop/openllmetry/releases)
- [Changelog](https://github.com/traceloop/openllmetry/blob/main/CHANGELOG.md)
- [Commits](traceloop/openllmetry@0.62.1...0.62.3)

Updates `ruff` from 0.16.0 to 0.16.7
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.0...0.16.7)

---
updated-dependencies:
- dependency-name: python-dotenv
  dependency-version: 1.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: langchain-core
  dependency-version: 1.6.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: langchain-openai
  dependency-version: 1.6.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: nltk
  dependency-version: 3.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: sentry-sdk
  dependency-version: 2.69.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: psycopg2-binary
  dependency-version: 2.9.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: langfuse
  dependency-version: 4.15.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: opentelemetry-instrumentation-anthropic
  dependency-version: 0.62.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: ruff
  dependency-version: 0.16.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* Bump docker/login-action from 4 to 4.5.2

Bumps [docker/login-action](https://github.com/docker/login-action) from 4 to 4.5.2.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v4...v4.5.2)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.5.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

* Bump aiohttp to 3.14.3

* Add changeset

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Add postgres support to docsite services (#687)

* feat: parameterize chunk size in DocsiteProcessor

* fix: revert unauthorized nltk import and _accumulate_chunks changes to match brief spec

* feat: rewrite DocsiteIndexer for Postgres batch lifecycle

* feat: rewire main() to the Postgres batch lifecycle

* feat: rewrite DocsiteSearch for Postgres hybrid search, preserve legacy Pinecone path

* fix: order keyword CTE by rank before limiting in hybrid search

* feat: backend-flagged docsite search with Postgres shadow-mode comparison

* fix: correct shadow-mode docstrings and test import placement

* feat: add offline golden-query recall/latency eval script

* fix: remove orphaned threshold arg and revert unrequested noqa suppressions

* fix: Restore back threshold to 0.8

* fix: apply the 0.7 relevance gate to both search_documentation backends

* refactor: remove shadow-mode Postgres comparison from job_chat

* fix: cast hybrid RRF score to float8 so results stay JSON-serializable

* fix: use semantic strategy on Postgres so the relevance gate survives cutover

* feat: add per-request backend selection to search_docsite

* feat: restore Pinecone write path behind embed_docsite target param

* fix: add type annotations to embed_docsite's new helper functions

* feat: add versioned migration runner for the docsite schema

* feat: report backend agreement in the offline docsite eval

* docs: correct stale LegacyPineconeDocsiteSearch docstring

* refactor: revert unrelated churn in docsite_processor

* refactor: revert import and formatting churn in docsite consumers

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* refactor: drop type annotations from internal helpers

* refactor: extract shared docsite backend resolver

* docs: focus docsite comments on invariants

* fix: run docsite migrations from the indexer, not every connection

* Remove openai key test

* fix: return a clear 503 when the docsite schema is not initialised

* fix: bind docsite embeddings as pgvector Vector

* fix: commit before toggling autocommit, and mark failed batches

* test: add Postgres docsite roundtrip integration suite

* fix: don't let a pruning failure invalidate the batch just promoted

* fix: change integration test to use 127.0.0.1 instead of localhost to speedup

* fix: update env example to support docsite backend and postgres test url for integration testing

* fix: run_eval compares postgres semantic, and loads dotenv

* Add results from running golden queries

* fix: import ordering and streamline comments

* lint: fix B008 and B904 linting issues

* lint: fix B905, RUF059, edited docs in helpers

* fix: lint F401 and docsite name accepting in pinecone

* feat: add results for each query for run_eval.py

* refactor: use a timestamped migration filename

* test: expand golden query set to 30 categorised queries

* feat: report eval recall per query category

* feat: resolve docsite eval batches by chunk size

* feat: compare semantic and hybrid across chunk sizes in the eval

* docs: update comments in roundtrip test

* changeset

* remove unused tests

* move test into legacy

---------

Co-authored-by: IZO-Ong <ong.izo.zh@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* versions

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Isaac <ong.izo.zh@gmail.com>
Co-authored-by: Hanna Paasivirta <hanna@openfn.org>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants