Repository navigation
Conversation
edwinyyyu
force-pushed
the
chore/dependency-refresh-speedkick
branch
from
September 9, 2026 17:30
d25b058 to
c2b890c
Compare
edwinyyyu
force-pushed
the
chore/dependency-refresh-speedkick
branch
3 times, most recently
from
September 9, 2026 19:05
09f8a9a to
72af7d6
Compare
The lock had drifted far behind: 30 of the 52 direct dependencies were behind their latest release, some by a major version. Refreshing it moves 104 locked packages, adds 6 and removes 2, with no downgrades. Nine are major bumps: complexipy 6 -> 8, cryptography 49 -> 50, fastmcp 3 -> 4 (and fastmcp-slim), mcp 1 -> 2, sentence-transformers 5 -> 6, setuptools 83 -> 84, websockets 16 -> 17, xxhash 3 -> 4. Direct dependencies that moved include fastapi 0.139.0 -> 0.141.1, instructor 1.15.4 -> 1.17.0, langchain-aws 1.6.2 -> 1.7.5, neo4j 6.2.0 -> 6.3.0, openai 2.45.0 -> 2.54.0, qdrant-client 1.18.0 -> 1.19.0, sqlalchemy 2.0.51 -> 2.0.52, ty 0.0.59 -> 0.0.79 and uvicorn 0.51.0 -> 0.52.4. Two specifiers had to change for the refresh to be honest: - litellm was capped at <1.85 when the provider was added (MemMachine#1386, which records no reason for the bound), and dependabot later widened it to <1.86. That range ends inside a stretch of releases -- 1.83.8 through 1.92.x -- that declare Requires-Python >=3.10,<3.14. uv ignores that upper bound and installed 1.85.7 anyway, but pip does not: on Python 3.14, `pip install memmachine-server[litellm]` resolved to 1.83.7, not the 1.85.7 in the lock. 1.93.0 is the first release that supports 3.14, so that is the floor now, and the lock moves to 1.100.0. litellm also requires openai<3, which is what holds the OpenAI SDK on the 2.x line; without the floor the resolver satisfies that by walking litellm backwards to 1.83.0 instead. - boto3-stubs was pinned exactly at 1.43.13 while boto3 resolved to 1.43.90, so the stubs no longer described the installed SDK. Two source changes the new versions require, and one cleanup: - ty 0.0.79 rejects assigning over a bound method, so the metrics-factory wiring test installs its fake engine with monkeypatch.setattr. - `list(vector.flat)` is a list of numpy scalars, not `list[float]`, which the newer numpy typing now reports at the assignment. The replay path converts explicitly. - The dev group listed complexipy twice. Left behind deliberately: nebula5-python (see the cap and its reason), openai 3.x (litellm requires openai<3, and instructor's jiter<0.15 pin holds openai below 3.11 regardless; 3.0 also swaps the transport to httpx2), and ruff, still pinned at 0.15.14 -- 0.16 formats Markdown code blocks, which would reformat six docs, and adds LOG004, which flags four `logger.exception` calls, two of them genuine misuses and two in a helper that is only ever called from an except block. All six ty jobs pass, as do `ruff check`, `ruff format --check`, `uv lock --check` and the unit suite. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01BcPSoGsQjnVJS8A5NkoGZN
Four entries in the server's dependency list are not requirements of this
package:
- boto3-stubs is a type-stub distribution sitting in the runtime list.
Nothing imports it, and `ty check --project packages/server` reports
the same "All checks passed" with the package uninstalled, so it was
buying neither runtime behaviour nor type coverage. (Base boto3-stubs
only types the boto3 entry points; per-service clients need the
mypy-boto3-* extras. If stronger boto3 typing is wanted later, that
belongs in the dev group with those extras.)
- regex belongs to memmachine-common, which declares it and imports it in
api/spec.py. Nothing in the server package uses it.
- The PyPI "dotenv" distribution ships no modules at all -- only
dist-info -- and exists to depend on python-dotenv.
`importlib.metadata.packages_distributions()["dotenv"]` is
`["python-dotenv"]`, so `from dotenv import load_dotenv` has always
been python-dotenv. Declare that instead.
- greenlet is what SQLAlchemy's asyncio extra installs, and this package
uses create_async_engine, so ask for `sqlalchemy[asyncio]` and let it
bring greenlet. That also covers the platforms SQLAlchemy's own
platform_machine marker on greenlet leaves out.
The lock loses boto3-stubs, botocore-stubs, types-s3transfer and dotenv.
greenlet and python-dotenv stay, now for stated reasons.
reranker_manager took `runtime_checkable` from typing_extensions, an
undeclared dependency it reached through pydantic. It has been in
`typing` since 3.8 and this package requires 3.12, so it comes from
`typing` now, next to the `Protocol` the file already imports there.
memmachine-common and memmachine-client keep their typing_extensions
dependency: they support 3.10, and `Self` and `Unpack` are 3.11.
Deliberately kept, though nothing imports them, because each is named in
the source or by the tests:
- asyncpg and aiosqlite are the SQLAlchemy drivers this package builds
URLs for. DatabaseBackend spells them out -- POSTGRES is
("postgres", SqlAlchemyConf, "postgresql", "asyncpg") -- SqlAlchemyConf
renders `{dialect}+{driver}://`, and database_manager hands that to
create_async_engine (and gates statement/connect timeouts on
`conf.driver == "asyncpg"`).
- tzdata on Windows. prompt_utilities builds `zoneinfo.ZoneInfo(tz)`, and
Windows ships no system tz database, so without it every lookup --
including the UTC fallback in the except branch -- raises
ZoneInfoNotFoundError.
- milvus-lite, which pymilvus does not declare. It is what serves a
file-backed Milvus URI, both for the local `path` deployment mode and
for test_milvus_vector_store, which opens
`MilvusClient(uri=tmp_path / "test_milvus.db")` behind
`pytest.importorskip("milvus_lite")` -- 22 tests in the default run.
All six ty jobs pass, as do `ruff check`, `ruff format --check`,
`uv lock --check` and the unit suite.
Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01BcPSoGsQjnVJS8A5NkoGZN
edwinyyyu
force-pushed
the
chore/dependency-refresh-speedkick
branch
from
September 10, 2026 16:53
72af7d6 to
c11a98e
Compare
This was referenced Sep 10, 2026
edwinyyyu
added a commit
to edwinyyyu/MemMachine
that referenced
this pull request
Sep 16, 2026
The lock had drifted far behind: 30 of the 52 direct dependencies were behind their latest release, some by a major version. Refreshing it moves 112 locked packages, adds 6 and removes 2, with no downgrades. Nine are major bumps: complexipy 6 -> 8, cryptography 49 -> 50, fastmcp 3 -> 4 (and fastmcp-slim), mcp 1 -> 2, sentence-transformers 5 -> 6, setuptools 83 -> 84, websockets 16 -> 17, xxhash 3 -> 4. Direct dependencies that moved include fastapi 0.139.0 -> 0.141.1, instructor 1.15.4 -> 1.17.0, langchain-aws 1.6.2 -> 1.7.6, neo4j 6.2.0 -> 6.3.1, openai 2.45.0 -> 2.54.0, qdrant-client 1.18.0 -> 1.19.0, sqlalchemy 2.0.51 -> 2.0.53, ty 0.0.59 -> 0.0.81 and uvicorn 0.51.0 -> 0.53.0. Two specifiers had to change for the refresh to be honest: - litellm was capped at <1.85 when the provider was added (MemMachine#1386, which records no reason for the bound), and dependabot later widened it to <1.86. That range ends inside a stretch of releases -- 1.83.8 through 1.92.x -- that declare Requires-Python <3.14. uv ignores that upper bound and installed 1.85.7 anyway, but pip does not: on Python 3.14, `pip install memmachine-server[litellm]` resolves to 1.83.7, not the 1.85.7 in the lock. 1.93.0 is the first release that supports 3.14, so that is the floor now, and the lock moves to 1.101.0. litellm also requires openai<3, which is what holds the OpenAI SDK on the 2.x line; without the floor the resolver satisfies that by walking litellm backwards to 1.83.0 instead. - boto3-stubs was pinned exactly at 1.43.13 while boto3 resolved to 1.43.47, so the stubs no longer described the installed SDK. One source change the new versions require, and one cleanup: - `list(vector.flat)` is a list of numpy scalars, not `list[float]`, which the newer numpy typing now reports at the assignment. The replay path converts explicitly. - The dev group listed complexipy twice. Left behind deliberately: nebula5-python (see the cap and its reason), openai 3.x (litellm requires openai<3, and instructor's jiter<0.15 pin holds openai below 3.11 regardless; 3.0 also swaps the transport to httpx2), and ruff, still pinned at 0.15.14 -- 0.16 formats Markdown code blocks, which would reformat six docs, and adds LOG004, which flags four `logger.exception` calls, two of them genuine misuses and two in a helper that is only ever called from an except block. Same change as the first half of MemMachine#1596 on speedkick, applied to main. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
edwinyyyu
added a commit
to edwinyyyu/MemMachine
that referenced
this pull request
Sep 16, 2026
Four entries in the server's dependency list are not requirements of this package: - boto3-stubs is a type-stub distribution sitting in the runtime list. Nothing imports it, and `ty check --project packages/server` reports the same "All checks passed" with the package uninstalled, so it was buying neither runtime behavior nor type coverage. (Base boto3-stubs only types the boto3 entry points; per-service clients need the mypy-boto3-* extras. If stronger boto3 typing is wanted later, that belongs in the dev group with those extras.) - regex belongs to memmachine-common, which declares it and imports it in api/spec.py. Nothing in the server package uses it. - The PyPI "dotenv" distribution ships no modules at all -- only dist-info -- and exists to depend on python-dotenv. `importlib.metadata.packages_distributions()["dotenv"]` is `["python-dotenv"]`, so `from dotenv import load_dotenv` has always been python-dotenv. Declare that instead. - greenlet is what SQLAlchemy's asyncio extra installs, and this package uses create_async_engine, so ask for `sqlalchemy[asyncio]` and let it bring greenlet. That also covers the platforms SQLAlchemy's own platform_machine marker on greenlet leaves out. The lock loses boto3-stubs, botocore-stubs, types-s3transfer and dotenv. reranker_manager also took runtime_checkable from typing_extensions, an undeclared dependency it reached through pydantic. It has been in typing since 3.8 and this package requires 3.12, so it now comes from typing, next to the Protocol the file already imports there. memmachine-common and memmachine-client keep their typing_extensions dependency: they support 3.10, and Self and Unpack are 3.11. Same change as the second half of MemMachine#1596 on speedkick, applied to main. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
malatewang
pushed a commit
that referenced
this pull request
Sep 17, 2026
…e ruff to 0.16 (#1646) * Bring the dependency lock up to date The lock had drifted far behind: 30 of the 52 direct dependencies were behind their latest release, some by a major version. Refreshing it moves 112 locked packages, adds 6 and removes 2, with no downgrades. Nine are major bumps: complexipy 6 -> 8, cryptography 49 -> 50, fastmcp 3 -> 4 (and fastmcp-slim), mcp 1 -> 2, sentence-transformers 5 -> 6, setuptools 83 -> 84, websockets 16 -> 17, xxhash 3 -> 4. Direct dependencies that moved include fastapi 0.139.0 -> 0.141.1, instructor 1.15.4 -> 1.17.0, langchain-aws 1.6.2 -> 1.7.6, neo4j 6.2.0 -> 6.3.1, openai 2.45.0 -> 2.54.0, qdrant-client 1.18.0 -> 1.19.0, sqlalchemy 2.0.51 -> 2.0.53, ty 0.0.59 -> 0.0.81 and uvicorn 0.51.0 -> 0.53.0. Two specifiers had to change for the refresh to be honest: - litellm was capped at <1.85 when the provider was added (#1386, which records no reason for the bound), and dependabot later widened it to <1.86. That range ends inside a stretch of releases -- 1.83.8 through 1.92.x -- that declare Requires-Python <3.14. uv ignores that upper bound and installed 1.85.7 anyway, but pip does not: on Python 3.14, `pip install memmachine-server[litellm]` resolves to 1.83.7, not the 1.85.7 in the lock. 1.93.0 is the first release that supports 3.14, so that is the floor now, and the lock moves to 1.101.0. litellm also requires openai<3, which is what holds the OpenAI SDK on the 2.x line; without the floor the resolver satisfies that by walking litellm backwards to 1.83.0 instead. - boto3-stubs was pinned exactly at 1.43.13 while boto3 resolved to 1.43.47, so the stubs no longer described the installed SDK. One source change the new versions require, and one cleanup: - `list(vector.flat)` is a list of numpy scalars, not `list[float]`, which the newer numpy typing now reports at the assignment. The replay path converts explicitly. - The dev group listed complexipy twice. Left behind deliberately: nebula5-python (see the cap and its reason), openai 3.x (litellm requires openai<3, and instructor's jiter<0.15 pin holds openai below 3.11 regardless; 3.0 also swaps the transport to httpx2), and ruff, still pinned at 0.15.14 -- 0.16 formats Markdown code blocks, which would reformat six docs, and adds LOG004, which flags four `logger.exception` calls, two of them genuine misuses and two in a helper that is only ever called from an except block. Same change as the first half of #1596 on speedkick, applied to main. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> * Drop dependencies nothing declares them for Four entries in the server's dependency list are not requirements of this package: - boto3-stubs is a type-stub distribution sitting in the runtime list. Nothing imports it, and `ty check --project packages/server` reports the same "All checks passed" with the package uninstalled, so it was buying neither runtime behavior nor type coverage. (Base boto3-stubs only types the boto3 entry points; per-service clients need the mypy-boto3-* extras. If stronger boto3 typing is wanted later, that belongs in the dev group with those extras.) - regex belongs to memmachine-common, which declares it and imports it in api/spec.py. Nothing in the server package uses it. - The PyPI "dotenv" distribution ships no modules at all -- only dist-info -- and exists to depend on python-dotenv. `importlib.metadata.packages_distributions()["dotenv"]` is `["python-dotenv"]`, so `from dotenv import load_dotenv` has always been python-dotenv. Declare that instead. - greenlet is what SQLAlchemy's asyncio extra installs, and this package uses create_async_engine, so ask for `sqlalchemy[asyncio]` and let it bring greenlet. That also covers the platforms SQLAlchemy's own platform_machine marker on greenlet leaves out. The lock loses boto3-stubs, botocore-stubs, types-s3transfer and dotenv. reranker_manager also took runtime_checkable from typing_extensions, an undeclared dependency it reached through pydantic. It has been in typing since 3.8 and this package requires 3.12, so it now comes from typing, next to the Protocol the file already imports there. memmachine-common and memmachine-client keep their typing_extensions dependency: they support 3.10, and Self and Unpack are 3.11. Same change as the second half of #1596 on speedkick, applied to main. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> * Log without a traceback where no exception is in flight openai_embedder's dimensionality check and amazon_bedrock_reranker's score-count check each call logger.exception() and then raise their own ExternalServiceAPIError. Nothing is being handled at that point: logger.exception is error(..., exc_info=True), and with no active exception it appends "NoneType: None" to the record. logger.error is what both sites mean; the raise that follows carries the message. ruff 0.16 reports both as LOG004 (`.exception()` call outside exception handlers). Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> * Re-raise the HTTPError the client's project-error helper is given _handle_get_project_http_error takes the caught HTTPError as a parameter, but its bare `raise` statements and logger.exception() calls ignored it and used the exception the *caller's* except block had active. That works only while the helper is called from inside that block, and ruff 0.16's LOG004 cannot see the call boundary, so it reports the two logging calls as .exception() outside a handler. The helper now uses what it is handed: logger.error(..., exc_info=error) attaches the same traceback logger.exception would have, and `raise error` re-raises the same object. Callers observe no difference: the exception identity, its original traceback and the 422 ValueError's __cause__ are unchanged (the helper's own frame is appended to the traceback, as it is for any re-raise from a callee). Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> * Move ruff to 0.16.8 ruff was held at 0.15.14 by the dependency refresh because 0.16 brings two things that touch committed content, and both now have their own commits ahead of this one: - LOG004 (`.exception()` outside an exception handler), selected via the LOG group. Its four findings are resolved by the two preceding commits, so `ruff check` is clean at this pin with no suppressions. - The formatter now formats Python code blocks inside Markdown. The six docs it touches are reformatted here, by `ruff format` and nothing else: USAGE.md, examples/v1/README.md, integrations/aws_strands_agent_sdk/README.md, integrations/langgraph/README.md, maintainers/build-pip-packages.md, packages/client/README.md. Trailing commas, collapsed argument lists, and column-aligned comments brought to two spaces; no words change. The lint workflow's ruff-action reads the pin from pyproject.toml, so CI enforces 0.16.8 from this commit on. No .py file is reformatted by the new version. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> * Explain only the litellm floor in the server's pyproject The litellm extra's comment also said litellm's openai<3 is what keeps the resolved OpenAI SDK on the 2.x line. That describes the universal lock, which resolves every extra, and not a requirement of this package: the server hands the SDK no httpx client, which is the only thing openai 3.0 changed, and its suite passes on openai 3.3.0 with the extra absent (1869 passed, 3 skipped, the same as on the lock). Installs without the extra may resolve openai 3.x. The comment now states only the floor, which is this package's own decision. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> --------- Co-authored-by: Claude Opus 5 (1M context) <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two commits: refresh the lock, then drop dependencies that are not requirements of these packages.
1. Bring the lock up to date
30 of the 52 direct dependencies were behind their latest release. The refresh moves 104 locked packages, adds 6, removes 2, and downgrades none.
Nine major bumps: complexipy 6→8, cryptography 49→50, fastmcp 3→4 (and fastmcp-slim), mcp 1→2, sentence-transformers 5→6, setuptools 83→84, websockets 16→17, xxhash 3→4. Direct dependencies moving include fastapi 0.139.0→0.141.1, instructor 1.15.4→1.17.0, langchain-aws 1.6.2→1.7.5, litellm 1.85.7→1.100.0, neo4j 6.2.0→6.3.0, openai 2.45.0→2.54.0, qdrant-client 1.18.0→1.19.0, ty 0.0.59→0.0.79, uvicorn 0.51.0→0.52.4.
litellm's upper bound had to go. It was introduced as
<1.85by the PR that added the provider (#1386, whose description states the dependency that way but records no reason for the bound); dependabot later widened it to<1.86. Either way the range ends inside a run of releases — 1.83.8 through 1.92.x — that declareRequires-Python >=3.10,<3.14. uv ignores that upper bound and installed 1.85.7 anyway; pip does not:So a pip user on 3.14 got 1.83.7 while the lockfile said 1.85.7. 1.93.0 is the first release supporting 3.14, so that is the floor now, and the lock moves to 1.100.0.
The floor also does work a cap would do badly. litellm requires
openai<3, which is what holds the OpenAI SDK on the 2.x line — and left uncapped, the resolver satisfiesopenai<3by walking litellm backwards to 1.83.0 (whoseopenai>=2.8.0has no upper bound) rather than holding openai back. Stating the litellm requirement keeps the constraint where it belongs, and it lifts itself the day litellm supports openai 3.Two source changes the new versions require: ty 0.0.79 rejects assigning over a bound method (the metrics-factory wiring test uses
monkeypatch.setattr), and newer numpy typing catcheslist(vector.flat)not beinglist[float](the replay path converts explicitly). The dev group also listedcomplexipytwice.2. Drop dependencies nothing declares them for
ty check --project packages/serverreports the sameAll checks passedwith it uninstalled, so it bought neither runtime behaviour nor type coverage. (Base boto3-stubs only types the boto3 entry points; per-service clients need themypy-boto3-*extras. If stronger boto3 typing is wanted, that belongs in the dev group with those extras.) It was also pinned exactly at 1.43.13 while boto3 ran to 1.43.90 — boto3-stubs mirrors boto3 release for release, so an exact pin goes stale within days.api/spec.py. Nothing in the server package uses it.dotenvdistribution ships no modules at all, only dist-info, and exists to depend on python-dotenv.importlib.metadata.packages_distributions()["dotenv"]is["python-dotenv"], sofrom dotenv import load_dotenvhas always been python-dotenv.sqlalchemy[asyncio]— greenlet is exactly what SQLAlchemy's asyncio extra installs, and this package usescreate_async_engine. Asking SQLAlchemy for it also covers the platforms SQLAlchemy's ownplatform_machinemarker on greenlet leaves out.The lock loses boto3-stubs, botocore-stubs, types-s3transfer and dotenv. greenlet and python-dotenv stay, now for stated reasons.
reranker_manageralso tookruntime_checkablefrom typing_extensions, an undeclared dependency it reached through pydantic. It has been intypingsince 3.8 and this package requires 3.12, so it now comes fromtyping, next to theProtocolthe file already imports there. memmachine-common and memmachine-client keep their typing_extensions dependency — they support 3.10, andSelfandUnpackare 3.11.Kept deliberately, though nothing imports them, because each is named in the source or by the tests:
DatabaseBackendspells them out —POSTGRES = ("postgres", SqlAlchemyConf, "postgresql", "asyncpg")—SqlAlchemyConfrenders{dialect}+{driver}://, anddatabase_managerhands that tocreate_async_engine(and gates statement/connect timeouts onconf.driver == "asyncpg").prompt_utilitiesbuildszoneinfo.ZoneInfo(tz), and Windows ships no system tz database, so without it every lookup — including the UTC fallback in theexceptbranch — raisesZoneInfoNotFoundError.pathdeployment mode and fortest_milvus_vector_store, which opensMilvusClient(uri=tmp_path / "test_milvus.db")behindpytest.importorskip("milvus_lite")— 22 tests in the default run.Deliberately left behind
<5.3in Fix the ty static checks (speedkick) #1595; 5.3 has no public async client.openai<3, and instructor'sjiter<0.15pin holds openai below 3.11 regardless, so the reachable version is 3.3.0. Taking it costs the litellm regression above, and 3.0 swaps the HTTP transport to httpx2. Worth its own PR.logger.exceptioncalls: two genuine misuses outside a handler, two in_handle_get_project_http_error, which is only ever called from inside anexceptblock. Adopting it means either changing correct code or suppressing the rule.packages/ts-client,integrations/openclaw) — a separate ecosystem with its own dependabot PRs; untouched here.Verification
All six
tyjobs,ruff check,ruff format --check,uv lock --check, and the unit suite pass after each commit.🤖 Generated with Claude Code
https://claude.ai/code/session_01BcPSoGsQjnVJS8A5NkoGZN