Skip to content

LCORE-4284: Updated dependencies - #2851

Merged
tisnik merged 1 commit into
lightspeed-core:mainfrom
tisnik:lcore-4284-updated-dependencies-6
Oct 6, 2026
Merged

tisnik merged 1 commit into
lightspeed-core:mainfrom
tisnik:lcore-4284-updated-dependencies-6

Conversation

@tisnik

@tisnik tisnik commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Description

LCORE-4284: Updated dependencies

Type of change

  • Refactor
  • New feature
  • Bug fix
  • CVE fix
  • Optimization
  • Documentation Update
  • Configuration Update
  • Bump-up service version
  • Bump-up dependent library [pyproject.toml + uv.lock]
  • Bump-up dependent library [requirements.*.txt for Konflux]
  • Bump-up library or tool used for development (does not change the final image)
  • CI configuration change
  • Konflux configuration change
  • Unit tests improvement
  • Integration tests improvement
  • End to end tests improvement
  • Benchmarks improvement

Tools used to create PR

  • Assisted-by: N/A
  • Generated by: N/A

Related Tickets & Documents

  • Related Issue #LCORE-4284

Summary by CodeRabbit

  • Chores
    • Updated the supported jsonpath-ng version range to exclude version 1.9.0 and later.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: lightspeed-core/lightspeed-stack/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 73ec0b8f-4680-40eb-a922-184a43c68c76
📥 Commits

Reviewing files that changed from the base of the PR and between e930978 and 48d40ee.

⛔ Files ignored due to path filters (1)
  • uv.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • pyproject.toml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (31)
  • GitHub Check: E2E: library / ci / rbac
  • GitHub Check: E2E: server / ci / other
  • GitHub Check: E2E: library / ci / shields
  • GitHub Check: E2E: server / ci / authorized
  • GitHub Check: E2E: server / ci / tls
  • GitHub Check: E2E: library / ci / skills
  • GitHub Check: E2E: library / ci / authorized
  • GitHub Check: E2E: server / ci / mcp
  • GitHub Check: E2E: server / ci / default
  • GitHub Check: E2E: library / ci / other
  • GitHub Check: E2E: server / ci / rbac
  • GitHub Check: E2E: server / ci / skills
  • GitHub Check: E2E: library / ci / mcp
  • GitHub Check: E2E: library / ci / default
  • GitHub Check: E2E: server / ci / shields
  • GitHub Check: Pylinter
  • GitHub Check: bandit
  • GitHub Check: list_outdated_dependencies
  • GitHub Check: black
  • GitHub Check: ruff
  • GitHub Check: spectral
  • GitHub Check: unit_tests (3.13)
  • GitHub Check: integration_tests (3.13)
  • GitHub Check: Pyright
  • GitHub Check: integration_tests (3.12)
  • GitHub Check: unit_tests (3.12)
  • GitHub Check: build-pr
  • GitHub Check: Red Hat Konflux / rag-content-0-8-e2e-tests / lightspeed-stack-0-8
  • GitHub Check: Red Hat Konflux / lightspeed-core-0-8-enterprise-contract / lightspeed-stack-0-8
  • GitHub Check: Red Hat Konflux / lightspeed-stack-0-8-e2e-tests / lightspeed-stack-0-8
  • GitHub Check: Konflux kflux-prd-rh02 / lightspeed-stack-0-8-on-pull-request
🔇 Additional comments (1)
pyproject.toml (1)

58-58: LGTM!


Walkthrough

The jsonpath-ng dependency requirement retains minimum version 1.6.1 and excludes version 1.9.0 and later.

Changes

Dependency constraint

Layer / File(s) Summary
Set jsonpath-ng version bound
pyproject.toml
The requirement keeps minimum version 1.6.1 and caps the allowed version below 1.9.0.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Suggested reviewers: jrobertsboos

Merge Risk: ⚪ Minimal · up to 48d40

The dependency constraint matches the committed lockfile resolution. No actionable merge-blocking risk is identified.

🚥 Pre-merge checks | ✅ 7
✅ Passed checks (7 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title identifies a dependency update, which matches the pull request’s change to the dependency requirement in pyproject.toml.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Performance And Algorithmic Complexity ✅ Passed PASSED. The PR changes only pyproject.toml and uv.lock. The source diff adds an upper bound for jsonpath-ng; the lockfile changes versions of aiohttp, cachetools, google-api-core, `google-…
Security And Secret Handling ✅ Passed PASSED. The PR changes only pyproject.toml and uv.lock: it constrains jsonpath-ng to <1.9.0 and updates five locked package versions. The diff adds no secrets, API endpoint changes, injection …
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
✨ Simplify code
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@tisnik
tisnik force-pushed the lcore-4284-updated-dependencies-6 branch from fc97a9b to 48d40ee Compare October 6, 2026 07:49
@tisnik
tisnik merged commit 73c4085 into lightspeed-core:main Oct 6, 2026
40 of 41 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant