Upgrade transitive deps in remaining package lock files #1316
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Run
uv lock --upgradeon the 9 remaining package lock files not covered by #1315.Lock files updated
packages/aws/uv.lockpackages/core/uv.lockpackages/devutils/uv.lockpackages/google/uv.lockpackages/hubspot/uv.lockpackages/main/uv.lockpackages/openai/uv.lockpackages/pdf/uv.lockpackages/recognition/uv.lockSkipped:
packages/assistant/uv.lock(broken due to robocorp-flet httpx conflict)This should resolve the bulk of the remaining 72 Dependabot alerts across these manifests.
Test plan
🤖 Generated with Claude Code
Note
Medium Risk
Lockfile-only dependency upgrades across multiple packages can introduce version incompatibilities or behavior changes at runtime/CI despite no code changes.
Overview
Upgrades pinned transitive dependencies by regenerating
uv.lockacross the remaining package manifests (e.g.aws,core,devutils,google,hubspot,main,openai,pdf,recognition).No application code changes; this is strictly dependency resolution/pin updates intended to reduce outstanding dependency alerts.
Written by Cursor Bugbot for commit 63ae7dc. This will update automatically on new commits. Configure here.