Uh oh!
There was an error while loading. Please reload this page.
Bump google-cloud-aiplatform to force upgrade of litellm - #66632
Conversation
c5cc4c7 to
f0074afComparepotiuk
commented
May 9, 2026
It is pretty strange with 8.1.8 though.. Let me take a look |
It is litellm which exactly pins this version :-( --> https://github.com/BerriAI/litellm/blob/v1.83.7-stable/pyproject.toml#L32 mhm... on un-released "main" they have releaxed meanwhile... https://github.com/BerriAI/litellm/blob/litellm_internal_staging/pyproject.toml#L24 (and pin is even still existing on RC1 of 1.84) |
15858cd to
561815eCompare
potiuk
left a comment
There was a problem hiding this comment.
Since they are going to relax soon - It looks fine :)
61eea23 to
13f5b56Comparejscheffl
commented
May 14, 2026
b696744 to
95d0de4Comparejscheffl
commented
May 17, 2026
Note: PR will fail in UV needs upgrading until cooldown is reached in ~24h Then needs a rebase and UV to be updated here. |
jscheffl
commented
May 23, 2026
Still not working as the litellm version that is relaxing click dependency is not in the allowed range for |
95d0de4 to
64d24a7Compareshahar1
commented
May 28, 2026
Please note the signing CLA is necessary to get this merged |
jscheffl
commented
May 28, 2026
Clicked on it but looking a current CI errors seems I need to amend to have a conventional commit :-D |
64d24a7 to
4dced04Comparejscheffl
commented
Jun 3, 2026
Uh oh!
There was an error while loading. Please reload this page.
Backport failed to create: v3-2-test. View the failure log Run detailsNote: As of Merging PRs targeted for Airflow 3.X In matter of doubt please ask in #release-management Slack channel.
You can attempt to backport this manually by running: cherry_picker 78039ba v3-2-testThis should apply the commit to the v3-2-test branch and leave the commit in conflict state marking After you have resolved the conflicts, you can continue the backport process by running: cherry_picker --continueIf you don't have cherry-picker installed, see the installation guide. |
jscheffl
commented
Jun 3, 2026
Ah, would not backport, pyproject-toml changes are unrelevant for v3.2.test |


Sine a while we carry the transitive litellm vulnerability in Dependabot. This PR attempts to bump google-cloud-aiplatform in order to ensure a non vulnerable transitive dependency is enforced.
Not sure why but as a trade we need to lower the click dependency from >=8.3.0 to >=8.1.8 - is this acceptable as a trade?
This refers to to upgrade in click by @eladkal in #61613
Let's see if CI turns green...
Was generative AI tooling used to co-author this PR?
{pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.