build(deps): bump the uv group across 2 directories with 2 updates - #1359
Conversation
Bumps the uv group with 1 update in the / directory: [google-cloud-aiplatform](https://github.com/googleapis/python-aiplatform). Bumps the uv group with 1 update in the /docs/knowledge_prototypes/mcp-servers/mcp_youtube-0.2.0 directory: [cryptography](https://github.com/pyca/cryptography). Updates `google-cloud-aiplatform` from 1.91.0 to 1.133.0 - [Release notes](https://github.com/googleapis/python-aiplatform/releases) - [Changelog](https://github.com/googleapis/python-aiplatform/blob/main/CHANGELOG.md) - [Commits](googleapis/python-aiplatform@v1.91.0...v1.133.0) Updates `cryptography` from 48.0.0 to 50.0.0 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@48.0.0...50.0.0) --- updated-dependencies: - dependency-name: google-cloud-aiplatform dependency-version: 1.133.0 dependency-type: direct:production dependency-group: uv - dependency-name: cryptography dependency-version: 50.0.0 dependency-type: indirect dependency-group: uv ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Dependency ReviewThe following issues were found:
Snapshot WarningsEnsure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice. License Issuesrequirements.txt
uv.lock
OpenSSF Scorecard
Scanned Files
|
Agent Completion Truth Gate: NOT_APPLICABLEEvidence agrees. Machine-readable verdict{
"details": {},
"reasons": [],
"verdict": "not_applicable"
} |
Remediation scan — terminal state:
|
Review — dependency bump assessment (automated shepherd)Verdict: safe on content; the only blocker is the PR Governance contract, which is a human gate. Scope — pure dependency/lockfile change, 4 files, no source edits:
Compatibility — the codebase's CI (head Blocker (1): To land it, a maintainer should either (a) fill in the governance sections + link a canonical issue on the PR body, or (b) merge via policy/admin override: Terminal state: Generated by Claude Code |
Automated review — ready for your merge decisionScope: dependency-metadata only — Upgrades:
Risk assessment: Low for this codebase. The only CI (head Recommendation: Green and low-risk; the CVE fix is a reason to merge promptly. Held for human sign-off because Generated by Claude Code |
Oldest-first scan of all 65 open PRs against the PR Remediation & Publish Runbook. Same terminal conclusion as the 2026-07-31 run: no autonomous merge path exists; remaining work is human-only (PUBLISH GATE is human by default, auto_merge_policy unset). Material change since last run: 4 non-draft PRs (#1311, #1358, #1359, #1366) are now green and mergeable, awaiting only a human ready/merge decision. Also corrects the 2026-07-31 run's "gate faulting" framing of the agent-completion/truth-gate invalid_payload result: the collected verdicts (#1370, #1356) show it is a legitimate fail-closed verdict for a missing agent-completion contract (no linked canonical issue + no trusted-publisher provenance manifest), not a workflow bug. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019hqExzDLDCCbRLdofRxcn1
Bumps the uv group with 1 update in the / directory: google-cloud-aiplatform.
Bumps the uv group with 1 update in the /docs/knowledge_prototypes/mcp-servers/mcp_youtube-0.2.0 directory: cryptography.
Updates
google-cloud-aiplatformfrom 1.91.0 to 1.133.0Release notes
Sourced from google-cloud-aiplatform's releases.
... (truncated)
Changelog
Sourced from google-cloud-aiplatform's changelog.
... (truncated)
Commits
78f2bddchore(main): release 1.133.0 (#6211)c8c0f0ffix: Add None check for agent_info in evals.py9952b97chore: rollback83f4076fix: Replace asyncio.run with create_task in ADK async thread mains.937d5afCopybara import of the project:aaaf902chore: bump google-auth lower bound to 2.47.0 in GenAI and Vertex SDKs8c876effix: Replace asyncio.run with create_task in ADK async thread mains.5448f06fix: Require uri or staging bucket configuration for saving model to Vertex E...65717fafeat: GenAI SDK client(memory): Add enable_third_person_memoriesbe2eaaafix: GenAI client(evals) - Fix TypeError in _build_generate_content_configUpdates
cryptographyfrom 48.0.0 to 50.0.0Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
dcb7050Prepare for 50.0.0 release (#15372)53fccd9Don't leak how PKCS#7 encryptedKey decryption failed (#15369)d472f97Addfrom __future__ import annotationsto all src/ Python files (#15371)908773dBump downstream dependencies in CI (#15368)2cc07ccBump BoringSSL, OpenSSL, AWS-LC in CI (#15367)c94ede9chore(deps): bump ruff from 0.16.0 to 0.16.1 (#15366)67a8308chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (#15365)95018ffRelease the GIL in one-shot AEAD encrypt/decrypt (#15361)6954733Release the GIL during DH and DSA parameter generation (#15364)6893b94Import _serialization instead of serialization in x509/extensions (#15363)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.