deps(python): Update uvicorn[standard] requirement from >=0.50.0 to >=0.51.0#9648
Merged
Merged
Conversation
MarkusNeusinger
enabled auto-merge (squash)
July 23, 2026 21:59
MarkusNeusinger
disabled auto-merge
July 23, 2026 22:10
Contributor
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
MarkusNeusinger
enabled auto-merge (squash)
July 23, 2026 22:11
MarkusNeusinger
added a commit
that referenced
this pull request
Jul 24, 2026
…illed (#9772) ## What happened On **2026-07-24, ~16:05–16:26 UTC** GitHub's API browned out — HTTP 502 on the workflow-dispatch endpoint, HTTP 504 on GraphQL, HTTP 429 on codeload. Four `radar-basic` PRs fell out of the pipeline and stayed out, because the calls that hand work to the next workflow had no retry: | PR | Library | State it was left in | Call that died | |---|---|---|---| | #9742 | seaborn | `ai-approved` q90 | `impl-merge` → `gh pr view` → **504** | | #9744 | pygal | `ai-rejected` q87 | repair dispatch → **504**; `ai-attempt-1` also lost | | #9749 | makie | `ai-rejected` q88 | repair dispatch → **502** | | #9751 | highcharts | `ai-rejected` q88 | repair dispatch → **502** | `impl-review`'s verdict step is the pipeline's **only hand-off point** — every downstream workflow starts from a call made there. So an unretried blip doesn't merely fail a step; it leaves a PR carrying a verdict label with nothing listening. All four have since been recovered manually and merged; this PR stops it recurring. ## Changes **`impl-review.yml` — the verdict step** - every API call retries 3× with linear backoff (same shape as the existing `Extract PR info` retry, added 2026-05-06 for this same class of failure) - the repair is **dispatched before** the attempt label is added, and the label can no longer gate it. Losing the label costs one over-strict review; losing the dispatch costs the whole PR - if the dispatch still exhausts its retries, the step drops `ai-rejected` on the way out: `ai-rejected` + `ai-attempt-N` matches **no** watchdog case (Case 2 excludes any verdict label, Case 4 excludes PRs that already have an attempt label), while the label-less state is exactly Case 2 — which re-dispatches the repair at the attempt number the remaining label still encodes - the label read tracks success explicitly instead of inferring it from empty output, and a successful read with no verdict label now fails loudly instead of ending the step green **Two bugs found while verifying the above** - **`ai-attempt-4` never existed as a label.** The attempt label encodes the cascading threshold (90 → 80 → 70 → 60 → 50), but the repo only has `ai-attempt-1..3`, so on the 4th repair the add failed every time and `|| true` swallowed it — #7268 and #7039 both reached "Repair Attempt 4/4" carrying only `ai-attempt-1..3`. Every 4th review therefore re-applied the ≥ 90 attempt-0 bar, and the attempts-exhausted branch (close PR, remove stale implementation) could never be reached. Labels are now created on demand. *This also means my first draft of this PR was a hard blocker:* with the label add fatal, the 4th repair would never have been dispatched at all. - **That newly-reachable branch rendered a literal `$SCORE/100`** — quoted heredoc. Now expands, with the markdown backticks escaped so they can't become command substitution. **`impl-merge.yml`** - the 5× merge retry re-reads PR state first. A merge that succeeded server-side but lost its HTTP response used to fail four more times with "already merged" and exit 1 — and because every post-merge step is gated on `should_run == 'true'` (implicit `success()`), that skipped GCS promotion, the `impl:{lib}:done` label, closing the issue and the Postgres sync. A merged PR with none of its bookkeeping: exactly the silent partial completion CLAUDE.md warns about **`auto-update-pr-branches.yml` — Dependabot PRs could never merge while the pipeline ran** - the workflow called `update-branch` on Dependabot PRs. That push is authored by `github-actions[bot]`, so GitHub gates the resulting runs behind manual approval (`action_required`) — and because `main` advances every few minutes during impl merges, each branch was re-updated long before anyone could approve. **PR #9674 accumulated 174 runs in 22 h: 162 `action_required` against only 4 green** (the original `dependabot[bot]` push) - Dependabot branches are now skipped. They merge fine while behind — the `main` ruleset is **not** strict (`strict_required_status_checks_policy: false`); the file's header claimed the opposite and is corrected - `/dependabot`'s playbook told operators to run that same harmful `update-branch` by hand; it now says the opposite and documents the `@dependabot recreate` remedy ## Verification `.github/workflows/` has no verification loop (CLAUDE.md), so this was reviewed by a 4-lens adversarial pass with an independent refutation round (regression / shell-under-`bash -e` / retry idempotency / the Dependabot premise), and every claim was re-checked against the live repo before acting. That pass is what caught the `ai-attempt-4` blocker and the false Dependabot-rebase premise in my first draft. - YAML parses; `bash -n` clean on the extracted steps - `gh_retry` semantics exercised under `bash -e`: succeeds first try / recovers after 2 failures / multi-arg passthrough / hard failure aborts the step - the corrected control flow tested for all three cases — normal, **attempt 4 with a permanently failing label add (dispatch must still fire)**, and dispatch exhaustion (`ai-rejected` dropped, exit 1) - confirmed the CI runner's `gh` adds labels fine; only the locally-installed gh 2.45.0 hits the `projectCards` GraphQL deprecation, so hard-failing on `--add-label` is safe in CI - ruleset strictness, the `ai-attempt-*` label set, and the poisoned Dependabot head commits were all read from the live repo, not assumed ## Follow-up (not in this PR) - #9674, #9648 and #8820 already have a `github-actions[bot]` merge commit as their head. Once this merges their head stops moving, so approving each gated run **once** is enough — verified that the required contexts do report as SUCCESS on a bot-authored head after approval (#9674, commit `59545076`). Doing it before this merges would just get re-gated by the next push to `main`. (`@dependabot recreate` is an equivalent alternative; it also restores a clean `dependabot[bot]` head but re-resolves the versions.) - Whether `auto-update-pr-branches.yml` should exist at all now that the ruleset is non-strict is worth deciding separately — it affects every auto-merge PR, so it isn't folded in here. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Owner
|
@dependabot recreate |
Updates the requirements on [uvicorn[standard]](https://github.com/Kludex/uvicorn) to permit the latest version. - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.50.0...0.51.0) --- updated-dependencies: - dependency-name: uvicorn[standard] dependency-version: 0.51.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/uv/uvicorn-standard--gte-0.51.0
branch
from
July 24, 2026 21:15
f0d9c2b to
7a3d3ea
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the requirements on uvicorn[standard] to permit the latest version.
Release notes
Sourced from uvicorn[standard]'s releases.
Changelog
Sourced from uvicorn[standard]'s changelog.
... (truncated)
Commits
e4d0b05Version 0.51.0 (#3028)944e43dRemove colorama from the standard extra (#3027)2e78770Restart workers with overlap on SIGHUP for near-zero-downtime reloads (#3025)a1b570cVersion 0.50.2 (#3022)83c7da7Require websockets>=13.0 for the default sansio implementation (#3021)b4d0116Version 0.50.1 (#3020)2a9151dSplit comma-separatedSec-WebSocket-Protocolvalues in the websockets-sansi...1bf3ab4Cover the excluded-directory branch inFileFilterwith a direct test (#3014)837b5f9Deflake multiprocess, reload, and signal supervisor tests (#2975)