Skip to content

fix: lock file maintenance - #1010

Merged
n24q02m merged 1 commit into
mainfrom
renovate/lock-file-maintenance
Sep 11, 2026
Merged

fix: lock file maintenance#1010
n24q02m merged 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@renovate

@renovate renovate Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone Asia/Ho_Chi_Minh)

  • Branch creation
    • "before 5am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Dependency updates label Sep 4, 2026
@renovate
renovate Bot requested a review from n24q02m as a code owner September 4, 2026 17:08
@renovate renovate Bot added the dependencies Dependency updates label Sep 4, 2026
@renovate
renovate Bot enabled auto-merge (squash) September 4, 2026 17:08
@socket-security

socket-security Bot commented Sep 4, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedlitellm@​1.100.0 ⏵ 1.100.174100100100100

View full report

@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
pip/anyio 4.15.1 UnknownUnknown
pip/boto3 1.43.92 🟢 7.4
Details
CheckScoreReason
Code-Review⚠️ 0Found 0/28 approved changesets -- score normalized to 0
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 10all dependencies are pinned
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
SAST🟢 10SAST tool is run on all commits
pip/botocore 1.43.92 🟢 8
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 1/27 approved changesets -- score normalized to 0
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 10no binaries found in the repo
License🟢 10license file detected
Fuzzing🟢 10project is fuzzed
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
SAST🟢 10SAST tool is run on all commits
pip/cachetools 7.1.8 UnknownUnknown
pip/caio 0.12.4 UnknownUnknown
pip/cyclopts 4.25.2 UnknownUnknown
pip/filelock 3.32.6 UnknownUnknown
pip/griffelib 2.3.0 UnknownUnknown
pip/huggingface-hub 1.31.0 🟢 7.1
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 23 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Code-Review🟢 8Found 23/26 approved changesets -- score normalized to 8
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 5dependency not pinned by hash detected -- score normalized to 5
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
Packaging🟢 10packaging workflow detected
SAST🟢 8SAST tool is not run on all commits -- score normalized to 8
pip/litellm 1.100.1 UnknownUnknown
pip/multidict 6.8.0 🟢 7.4
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 5Found 14/27 approved changesets -- score normalized to 5
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Security-Policy🟢 10security policy file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
Signed-Releases🟢 85 out of the last 5 releases have a total of 5 signed artifacts.
pip/onnxruntime 1.30.0 UnknownUnknown
pip/platformdirs 4.11.8 UnknownUnknown
pip/protobuf 7.36.1 UnknownUnknown
pip/regex 2026.9.10 UnknownUnknown
pip/sse-starlette 3.4.11 UnknownUnknown
pip/tokenizers 0.23.2 UnknownUnknown

Scanned Files

  • uv.lock

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 7 times, most recently from b3f2273 to 59b7fb8 Compare September 10, 2026 15:29
@n24q02m n24q02m changed the title fix(deps): Lock file maintenance chore(deps): lock file maintenance Sep 11, 2026
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from 59b7fb8 to 1cf608d Compare September 11, 2026 00:13
@n24q02m n24q02m changed the title chore(deps): lock file maintenance fix: lock file maintenance Sep 11, 2026
@n24q02m n24q02m closed this Sep 11, 2026
auto-merge was automatically disabled September 11, 2026 00:38

Pull request was closed

@n24q02m n24q02m reopened this Sep 11, 2026
@n24q02m
n24q02m merged commit 201fa23 into main Sep 11, 2026
27 of 28 checks passed
@n24q02m
n24q02m deleted the renovate/lock-file-maintenance branch September 11, 2026 00:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant