Bump tornado from 6.5.7 to 6.5.9 - #1071
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: NVIDIA/cloudai/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
@dependabot rebase |
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.7 to 6.5.9. - [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst) - [Commits](tornadoweb/tornado@v6.5.7...v6.5.9) --- updated-dependencies: - dependency-name: tornado dependency-version: 6.5.9 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
b4e2712 to
4f298b4
Compare
podkidyshev
left a comment
There was a problem hiding this comment.
Reviewed Tornado 6.5.9 for provenance, security advisories, and actual CloudAI compatibility, revising the initial conservative hold based on upstream server changes.
- Sole dependency chain: CloudAI -> Bokeh 3.8.2 -> Tornado. No direct Tornado imports or Tornado/Bokeh server, HTTP client, static-file handler, server-session or websocket-server calls were found in CloudAI source, tests, or public documentation.
- CloudAI's BokehReportTool writes standalone HTML with output_file/save; ComparisonReport embeds standalone Bokeh components. The 6.5.8/6.5.9 StaticFileHandler symlink restriction, form/query limits, curl HTTP-client response limit and IOStream error changes are outside those report paths. The known Jupyter compatibility change in 6.5.10 also concerns server StaticFileHandler configurations, which CloudAI does not use. Python >=3.9 preserves all CloudAI-supported Python versions.
- 228 focused report-generation tests passed on Python 3.14 and again on Python 3.10. Real BokehReportTool.finalize_report generated and validated HTML both in ordinary and symlinked output directories; chart components were serialized successfully. These checks passed with Tornado 6.5.7 and 6.5.9 on both Python versions. Guards confirmed no Tornado HTTPServer.listen, AsyncHTTPClient.fetch or StaticFileHandler.get invocation. The compiled speedups.websocket_mask extension returned the expected bytes with both versions on both Python versions.
- pre-commit checks for uv.lock passed, including import-linter. Published rebased tree exactly matches the tested tree, and all fresh CI checks passed.
- All 10 changed release artifact URLs/SHA-256 hashes match the non-yanked PyPI 6.5.9 release. PyPI publisher provenance identifies tornadoweb/tornado build.yml; all 73 wheel Python files match official upstream tag v6.5.9. PyPI reports no advisories affecting 6.5.9; it fixes multiple known vulnerabilities affecting 6.5.7. No evidence of package compromise found.
No compatibility regression found in CloudAI's own report paths. This does not claim compatibility for external applications running Tornado or Bokeh/Jupyter servers in the same environment.
Bumps tornado from 6.5.7 to 6.5.9.
Changelog
Sourced from tornado's changelog.
... (truncated)
Commits
75ef8b1Merge pull request #3719 from bdarnell/fixes-6593590cb4test: Hardcode SimpleAsyncHTTPClient in HTTP1xxLimitTestCase9fc5d6dtest: Make tracemalloc optional in httpclient_test555a2eeiostream: Treat connection resets as a clean close in read_until_close3ba622fRelease notes and version bump for 6.5.941eea68test: Fix some test issues only found by our custom tox configab1a778Merge remote-tracking branch 'bdarnell/claude/asynchttpclient-streaming-memor...437ab5fweb: Do not follow symlinks out of the static directory0394513httputil: Apply the argument count limit to query stringsb798f83http1connection: Return after reading the response that follows a 1xx