Bump anyio from 4.12.1 to 4.14.2 - #1043
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: NVIDIA/cloudai/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
@dependabot rebase |
Bumps [anyio](https://github.com/agronholm/anyio) from 4.12.1 to 4.14.2. - [Release notes](https://github.com/agronholm/anyio/releases) - [Commits](agronholm/anyio@4.12.1...4.14.2) --- updated-dependencies: - dependency-name: anyio dependency-version: 4.14.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
1d68b67 to
86dfdc3
Compare
podkidyshev
left a comment
There was a problem hiding this comment.
Reviewed AnyIO 4.14.2 for provenance, current advisories, and actual CloudAI compatibility, revising the initial conservative hold based on upstream release notes.
- Runtime dependency chain: CloudAI -> huggingface-hub -> HTTPX -> AnyIO. CloudAI's HFModel uses synchronous snapshot_download and offline cache lookup. No direct AnyIO imports, AnyIO task-group use, dynamic attributes on AnyIO synchronization objects, or invalid receive sizes were found in CloudAI. Its synchronous Hub download path uses thread_map and synchronous HTTPX.
- Development-only chain: CloudAI[dev] -> import-linter -> FastAPI -> Starlette -> AnyIO. HTTPX/httpcore and Starlette's ordinary consumers were checked against the changed callable contracts and slots. No incompatible use found. Python >=3.10 matches CloudAI's supported minimum; transitive dependency versions and edges are unchanged.
- 86 focused CloudAI tests passed on Python 3.14 and 3.10. The full local suite passed on Python 3.14 with the AnyIO pytest plugin loaded: 2015 passed, 5 skipped, 528 deselected by the repository's default marker setting.
- Actual HFModel.install downloaded two verified files from a local Hugging Face-compatible HTTP server, and HFModel.is_installed performed a successful cache lookup without network access. Additional real HTTPX async TLS, repeated/concurrent requests, streaming, read timeout and recovery, and FastAPI/Starlette TestClient checks passed with both AnyIO 4.12.1 and 4.14.2 on Python 3.10 and 3.14: 9 scenarios per combination, 36 successful comparisons. The pre-existing Starlette TestClient deprecation warning was present on both versions.
- pre-commit checks for uv.lock passed, including import-linter. The published rebased tree is identical to the locally tested tree; fresh CI is being checked before merging.
- All changed artifact URLs/SHA-256 hashes match the non-yanked PyPI release. PyPI publisher provenance identifies agronholm/anyio publish.yml; all 43 wheel Python files match official tag 4.14.2. PyPI reports no known advisories affecting 4.14.2; it fixes the process-worker deadlock and TLS hostname certificate-spoofing advisories affecting the old version. No evidence of package compromise found.
No regression found for CloudAI's own paths and its normal dependency consumers. Arbitrary external integrations are outside this validation.
Bumps anyio from 4.12.1 to 4.14.2.
Release notes
Sourced from anyio's releases.
... (truncated)
Commits
c384f99Bumped up the versiondbba29dFixed 100% CPU spin on cancel scope misuse (#1217)6bbc6c3Fix CapacityLimiter over-granting tokens on asyncio (#1172)6f82b25Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flakybe24b04Relaxed timeouts to fix test flakiness8113506Fix test flakiness caused by slow callback duration logging1e988b6Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (#1...44713f3Pin setup-uv to a commit sha across downstream jobs (#1213)f1b7301Fixed stderr writes in a worker subprocess causing a deadlock (#1207)212be93Fix flaky test_tcp_listener_same_port using a hardcoded port (#1206)