Skip to content

Consolidate Dependabot dependency updates - #7445

Merged
Evan Mattson (moonbox3) merged 18 commits into
microsoft:mainfrom
moonbox3:codex/consolidate-dependabot-20260731-e39a8a2
Aug 4, 2026
Merged

Consolidate Dependabot dependency updates#7445
Evan Mattson (moonbox3) merged 18 commits into
microsoft:mainfrom
moonbox3:codex/consolidate-dependabot-20260731-e39a8a2

Conversation

@moonbox3

Copy link
Copy Markdown
Contributor

Motivation & Context

Consolidate the current open Dependabot updates into one compatible, reviewable change. Several Python tool updates need to land together because the root and Lab development pins share one workspace lockfile, and the newer Ruff and ty releases require small compatibility updates to existing Markdown examples and test-only suppressions.

Description & Review Guide

  • What are the major changes? Updates the selected GitHub Actions, Python development/build tools, and .NET AgentMemory packages; refreshes the Python lockfile and duplicate Lab tool pins; and applies the minimal formatting and test-typing compatibility changes required by Ruff 0.16 and ty 0.0.64.
  • What is the impact of these changes? CI actions and development tooling use the requested newer versions, the Python workspace remains resolvable, and the AgentMemory sample builds against version 1.3.0 of both packages. There are no public API or runtime behavior changes.
  • What do you want reviewers to focus on? Confirm that each superseded dependency update is represented and that the Python compatibility follow-ups remain narrowly scoped to the new tool behavior.

Related Issue

Supersedes:

Contribution Checklist

  • The code builds clean without any errors or warnings
  • All unit tests pass, and I have added new tests where possible
  • The PR follows the Contribution Guidelines
  • This PR is linked to an issue and there is no other open PR for this issue (see Related Issue above).
  • This is not a breaking change. If it is a breaking change, add the breaking change label (or add "[BREAKING]" to the title prefix, before or after any language prefix) — a workflow keeps the label and title prefix in sync automatically.

dependabotBotand others added 16 commits July 31, 2026 08:26
---
updated-dependencies:
- dependency-name: AgentMemory
dependency-version: 1.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.0 to 4.37.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@99df26d...e4fba86)
---
updated-dependencies:
- dependency-name: github/codeql-action/init
dependency-version: 4.37.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.3.2 to 9.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@11f9893...c771a70)
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 9.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.0 to 4.37.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@99df26d...e4fba86)
---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@27d5ce7...55cc834)
---
updated-dependencies:
- dependency-name: actions/cache
dependency-version: 6.1.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@de0fac2...3d3c42e)
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.3.2 to 9.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@11f9893...c771a70)
---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
dependency-version: 9.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ty](https://github.com/astral-sh/ty) from 0.0.60 to 0.0.64.
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.60...0.0.64)
---
updated-dependencies:
- dependency-name: ty
dependency-version: 0.0.65
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [prek](https://github.com/j178/prek) from 0.4.10 to 0.4.11.
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](j178/prek@v0.4.10...v0.4.11)
---
updated-dependencies:
- dependency-name: prek
dependency-version: 0.4.11
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [uv](https://github.com/astral-sh/uv) from 0.11.29 to 0.11.32.
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.11.29...0.11.32)
---
updated-dependencies:
- dependency-name: uv
dependency-version: 0.12.0
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.15.22 to 0.16.0.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.22...0.16.0)
---
updated-dependencies:
- dependency-name: ruff
dependency-version: 0.16.0
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
---
updated-dependencies:
- dependency-name: uv-build
dependency-version: 0.12.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
CopilotAI review requested due to automatic review settings July 30, 2026 23:49
@agent-framework-automationagent-framework-automationBot added documentation Usage: [Issues, PRs], Target: documentation in the code base and learn docs python Usage: [Issues, PRs], Target: Python .NET Usage: [Issues, PRs], Target: .Net lab Usage: [Issues, PRs], Target: lab packages labels Jul 30, 2026
@github-actionsgithub-actionsBot changed the title Consolidate Dependabot dependency updatesPython: Consolidate Dependabot dependency updatesJul 30, 2026
@github-actionsgithub-actionsBot changed the title Python: Consolidate Dependabot dependency updates.NET: Consolidate Dependabot dependency updatesJul 30, 2026
@github-actions

github-actionsBot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Python Test Coverage

Python Test Coverage Report •
FileStmtsMissCoverMissing
TOTAL44466411290%
report-only-changed-files is enabled. No files were changed during this commit :)

Python Unit Test Overview

TestsSkippedFailuresErrorsTime
910934 💤0 ❌0 🔥2m 32s ⏱️

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated Code Review

Reviewers: 5 | Confidence: 68%

✓ Correctness

No correctness issues found in the provided dependency, workflow, lockfile, documentation-formating, or test-suppression changes.

✓ Security Reliability

This is a dependency-pin refresh (GitHub Actions SHAs, Python dev tooling, .NET sample package versions) plus Ruff/ty compatibility formatting in Markdown and test-only type suppressions. No production code, no new trust boundaries, no secrets, and no deserialization or resource-handling changes are introduced, so the security surface is limited to supply-chain pinning hygiene. All actions remain SHA-pinned, which is the right posture. The only issue I can confirm from the diff text alone is an internally inconsistent version comment on the actions/cache pin: the identical commit SHA 55cc8345863c7cc4c66a329aec7e433d2d1c52a9 is annotated # v5 in .github/workflows/python-code-quality.yml but # v6.1.0 in .github/workflows/python-integration-tests.yml and .github/workflows/python-merge-tests.yml. Since these comments are the only human-readable signal for what a pinned SHA actually is, a stale # v5 label hides a major-version upgrade from reviewers. Note: my file-read and search tooling returned permission errors during this session, so I limited findings strictly to what the diff itself proves and omitted anything requiring repository verification.

✓ Test Coverage

No substantive test-coverage gaps found. Changes are dependency/tooling updates, formatting adjustments, and test-only type suppressions without new runtime behavior.

✓ Failure Modes

This is a pure dependency/pin bump PR (GitHub Action SHAs, Python dev tooling versions, uv.lock refresh, .NET sample package versions) plus formatting-only Markdown changes and additional # ty: ignore[...] suppressions in tests. There is no runtime logic in the diff, so there are no new error-handling, cancellation, rollback, or partial-write failure paths introduced. Note: my environment blocked all file-read/search/CLI tooling for this review, so I limited findings strictly to what is directly provable from the diff text itself and omitted anything requiring repository verification (e.g. whether setup-uv v9.0.0 or actions/cache v6 changed input semantics for version-file, version: "0.11.x", or cache key handling — those are worth a maintainer sanity check on a green CI run before merge). The one thing visible purely within the diff is an inconsistent version annotation for a single pinned SHA.

✓ Design Approach

This is a dependency-consolidation PR: pinned action SHAs, Python tool version bumps, lockfile refresh, a .NET sample package bump, and Ruff/ty-driven formatting and suppression updates. Note: my tooling (grep/glob/view/bash) was blocked in this session with permission errors, so I could not perform the usual context pass in the checked-out repo; I therefore limited findings strictly to what is self-evident within the diff itself and withheld anything requiring file verification. The only issue visible purely from the diff is an inconsistent version comment on the newly pinned actions/cache SHA: the same commit 55cc8345863c7cc4c66a329aec7e433d2d1c52a9 is annotated '# v5' in one workflow and '# v6.1.0' in two others. Since the version comment is the only human-readable signal for a pinned SHA, the mismatch is misleading for future Dependabot/review passes. This is non-blocking.

Suggestions

  • Align the version comment on the new actions/cache pin (55cc8345863c7cc4c66a329aec7e433d2d1c52a9): it is labeled '# v5' in .github/workflows/python-code-quality.yml:45 but '# v6.1.0' in .github/workflows/python-integration-tests.yml:195 and .github/workflows/python-merge-tests.yml:302. Only one can be correct.

Automated review by moonbox3's agents

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Consolidates multiple Dependabot-driven dependency bumps across the repo (GitHub Actions, Python tooling/lockfile, and a .NET sample) and applies the minimal follow-up edits required for the updated Python tooling to keep docs/tests compatible.

Changes:

  • Updated Python dev tooling pins (uv/ruff/ty/prek), refreshed uv.lock, and widened uv_build constraints in select packages.
  • Adjusted Python docs/examples formatting and added targeted ty ignores in tests to match updated type-checker behavior.
  • Updated pinned GitHub Actions SHAs (checkout/cache/setup-uv/codeql) and bumped AgentMemory packages in a .NET sample.

Reviewed changes

Copilot reviewed 37 out of 39 changed files in this pull request and generated 26 comments.

Show a summary per file
FileDescription
python/uv.lockRefreshes the workspace lockfile to reflect updated Python tooling pins.
python/pyproject.tomlUpdates root Python dev dependency-group pins (uv/ruff/ty/prek).
python/packages/ollama/pyproject.tomlWidens uv_build upper bound to allow newer uv-build versions.
python/packages/ollama/AGENTS.mdMinor Markdown formatting adjustment in examples.
python/packages/mistral/pyproject.tomlWidens uv_build upper bound to allow newer uv-build versions.
python/packages/lab/pyproject.tomlUpdates Lab dev pins to stay aligned with the shared lockfile/tooling.
python/packages/core/tests/core/test_observability.pyAdds ty ignore suppressions needed under the updated type checker.
python/packages/ag-ui/README.mdReflows Markdown examples to satisfy updated formatter behavior.
python/packages/ag-ui/getting_started/README.mdSmall example formatting update for compatibility with Markdown formatting.
python/packages/ag-ui/AGENTS.mdMinor Markdown formatting adjustment in examples.
python/packages/ag-ui/agent_framework_ag_ui_examples/README.mdReflows example snippets (state schema/config) for formatter compatibility.
dotnet/samples/02-agents/AgentWithMemory/AgentWithMemory_Step06_MemoryUsingAgentMemory/AgentWithMemory_Step06_MemoryUsingAgentMemory.csprojBumps AgentMemory package references to 1.3.0.
.github/workflows/stale-issue-pr-ping.ymlUpdates pinned actions/checkout SHA.
.github/workflows/python-tests.ymlUpdates pinned actions/checkout SHA.
.github/workflows/python-test-coverage.ymlUpdates pinned actions/checkout SHA.
.github/workflows/python-test-coverage-report.ymlUpdates pinned actions/checkout SHA.
.github/workflows/python-sample-validation.ymlUpdates pinned actions/checkout SHA across sample-validation jobs.
.github/workflows/python-release.ymlUpdates pinned actions/checkout SHA.
.github/workflows/python-merge-tests.ymlUpdates pinned actions/checkout SHA and bumps actions/cache for Ollama model caching.
.github/workflows/python-lab-tests.ymlUpdates pinned actions/checkout SHA.
.github/workflows/python-integration-tests.ymlUpdates pinned actions/checkout SHA and bumps actions/cache for Ollama model caching.
.github/workflows/python-docs.ymlUpdates pinned actions/checkout SHA and bumps astral-sh/setup-uv to v9.
.github/workflows/python-dependency-maintenance.ymlUpdates pinned actions/checkout SHA.
.github/workflows/python-code-quality.ymlUpdates pinned actions/checkout SHA and bumps actions/cache.
.github/workflows/markdown-link-check.ymlUpdates pinned actions/checkout SHA.
.github/workflows/limit-community-prs.ymlUpdates pinned actions/checkout SHA for script checkouts.
.github/workflows/label-title-prefix.ymlUpdates pinned actions/checkout SHA for script checkout.
.github/workflows/label-pr.ymlUpdates pinned actions/checkout SHA for script checkout.
.github/workflows/label-issues.ymlUpdates pinned actions/checkout SHA for automation checkout.
.github/workflows/issue-triage.ymlUpdates pinned actions/checkout SHA and bumps astral-sh/setup-uv to v9.
.github/workflows/integration-tests-manual.ymlUpdates pinned actions/checkout SHA for helpers checkout.
.github/workflows/github-automation-tests.ymlUpdates pinned actions/checkout SHA.
.github/workflows/dotnet-verify-samples.ymlUpdates pinned actions/checkout SHA.
.github/workflows/dotnet-integration-tests.ymlUpdates pinned actions/checkout SHA.
.github/workflows/dotnet-format.ymlUpdates pinned actions/checkout SHA.
.github/workflows/dotnet-build-and-test.ymlUpdates pinned actions/checkout SHA across jobs.
.github/workflows/devflow-pr-review.ymlUpdates pinned actions/checkout SHA and bumps astral-sh/setup-uv to v9.
.github/workflows/codeql-analysis.ymlUpdates pinned actions/checkout SHA and bumps CodeQL action SHAs.
.github/actions/python-setup/action.ymlBumps astral-sh/setup-uv to v9 in the reusable Python setup action.
Comments suppressed due to low confidence (1)

.github/workflows/python-code-quality.yml:45

  • This workflow pins actions/cache to the v6.1.0 SHA, but the inline comment still says "# v5". Please update the comment to match the pinned version to avoid confusion during audits.
 - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v5

Comment thread.github/workflows/python-code-quality.yml Outdated
Comment thread.github/workflows/stale-issue-pr-ping.yml Outdated
Comment thread.github/workflows/python-tests.yml Outdated
Comment thread.github/workflows/python-test-coverage.yml Outdated
Comment thread.github/workflows/python-test-coverage-report.yml Outdated
Comment thread.github/workflows/dotnet-format.yml Outdated
Comment thread.github/workflows/dotnet-build-and-test.yml Outdated
Comment thread.github/workflows/dotnet-integration-tests.yml Outdated
Comment thread.github/workflows/codeql-analysis.yml Outdated
Comment thread.github/workflows/devflow-pr-review.yml Outdated
@moonbox3Evan Mattson (moonbox3) changed the title .NET: Consolidate Dependabot dependency updatesConsolidate Dependabot dependency updatesJul 31, 2026
@moonbox3

Copy link
Copy Markdown
ContributorAuthor

Addressed the automated review feedback in a2ade58: all actions/checkout annotations now match v7.0.1, and the python-code-quality actions/cache annotation now matches v6.1.0. All 26 inline threads have been replied to and resolved.

@moonbox3
Evan Mattson (moonbox3) marked this pull request as ready for review July 31, 2026 01:36

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated Code Review

Reviewers: 5 | Confidence: 57% | Result: All clear

Reviewed: Correctness, Security Reliability, Test Coverage, Failure Modes, Design Approach


Automated review by moonbox3's agents

…ependabot-20260731-e39a8a2
# Conflicts:
#	.github/workflows/dotnet-build-and-test.yml
#	.github/workflows/python-integration-tests.yml
#	.github/workflows/python-merge-tests.yml
@moonbox3
Evan Mattson (moonbox3) added this pull request to the merge queueAug 4, 2026
Merged via the queue into microsoft:main with commit 84d5a5eAug 4, 2026
53 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationUsage: [Issues, PRs], Target: documentation in the code base and learn docslabUsage: [Issues, PRs], Target: lab packages.NETUsage: [Issues, PRs], Target: .NetpythonUsage: [Issues, PRs], Target: Python

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@moonbox3@giles17@peibekwe