Skip to content

fix: remove stale pre-4.53 transformers comment from pyproject.toml - #29

Merged
cgfixit merged 2 commits into
mainfrom
claude/verify-deps-consistency-40zjsi
Aug 15, 2026
Merged

cgfixit merged 2 commits into
mainfrom
claude/verify-deps-consistency-40zjsi

Conversation

@cgfixit

@cgfixit cgfixit commented Aug 15, 2026

Copy link
Copy Markdown
Owner

Summary

Verified requirements.txt, constraints.txt, and pyproject.toml for accuracy and
mutual consistency per CLAUDE.md §4.9 (the "three files must move together" rule).
The actual version bounds/pins were already consistent — constraints.txt's == pins
all satisfy the >=/< ranges declared in requirements.txt and pyproject.toml.
However, the surrounding documentation had drifted out of sync with reality:

  • pyproject.toml: the dependency comment block said transformers was "Capped at
    <4.45 until upstream fix" with a remediation snippet for
    transformers==4.44.2/sentence-transformers==3.0.1 — directly contradicting the
    dependencies list two lines below (transformers>=4.53.0,<5.0.0). Root cause:
    the <4.45 cap comment was never removed when the floor was raised to >=4.53.0; it
    shipped self-contradictory from the same commit that introduced the file (9e5f8ff).
    Replaced with a DEPENDENCY NOTES block matching requirements.txt's existing house
    style, keeping only the notes that are still true.
  • .claude/skills/deps-security-refresh/SKILL.md and
    .claude/skills/insight-optimize/SKILL.md: both described accelerate==0.34.2 as
    "the current" constraints.txt pin. That was fixed to accelerate==1.14.0 in
    commit 312096b (2026-07-08) — over a month before this pass. Root cause: the
    skill docs were written to describe a live bug and never updated after the fix
    landed. Reworded to past-tense / "watch for regression" framing so a future agent
    reading these skills doesn't mistake fixed history for an open bug.
  • docs/SECURITY_AUDIT.md: re-ran pip-audit against a clean constraints-pinned
    install as part of this verification and logged one net-new, not-yet-triaged advisory
    (PYSEC-2026-2290, fix in 5.5.0) alongside the addendum's existing
    dedicated-retriage note. No reachability verdict assigned and no pin changed — a full
    CVE re-triage is explicitly out of scope here per the doc's own note (it's a separate,
    ask-first task).

Verification performed

  • Clean Python 3.12 and 3.13 venvs: pip install -r requirements.txt -c constraints.txt && pip install -e ".[dev]" — both succeed cleanly.
  • transformers/accelerate/sentence-transformers import triangle (init_empty_weights,
    TorchTensorParallelPlugin, SentenceTransformer) — imports clean on both.
  • ruff check src/ tests/ → 0 findings
  • ruff format --check src/ tests/ → already formatted
  • mypy src/insight_extractor → Success (strict), 10 files
  • pytest tests/unit/ -v --tb=short → 118/118 passed on Python 3.12 and 3.13
  • pip-audit against the actual pinned environment — no new findings beyond what's
    already documented, except the one net-new advisory noted above

Skipped: integration tests (tests/integration/) — no BERT model download in this
sandboxed environment, per repo convention (not moved into tests/unit/).

Test plan

  • All four CI gates pass locally (see above)
  • git diff --stat touches only the four files the task required
  • No run artifacts staged
  • No public API, defaults, or dependency pins changed — comments/docs only

Generated by Claude Code

claude added 2 commits August 15, 2026 03:34
- pyproject.toml: the dependency comment block said transformers was
  "Capped at <4.45 until upstream fix" with a remediation snippet for
  transformers==4.44.2/sentence-transformers==3.0.1, directly
  contradicting the dependencies list two lines below
  (transformers>=4.53.0,<5.0.0). Root cause: the >=4.45 cap comment was
  never removed when the floor was raised to >=4.53.0 in commit
  9e5f8ff — it shipped self-contradictory from that same commit.
  Replaced with a DEPENDENCY NOTES block matching requirements.txt's
  house style, keeping only the notes that are still true.
- .claude/skills/deps-security-refresh/SKILL.md,
  .claude/skills/insight-optimize/SKILL.md: both described
  accelerate==0.34.2 as "the current" constraints.txt pin, but that
  was fixed to accelerate==1.14.0 in commit 312096b (2026-07-08).
  Reworded to past-tense/"watch for regression" framing so a future
  agent reading these skills doesn't mistake fixed history for a live
  bug.
- docs/SECURITY_AUDIT.md: re-ran pip-audit against a clean
  constraints-pinned install as part of this verification; logged one
  net-new, not-yet-triaged advisory (PYSEC-2026-2290) alongside the
  already-flagged dedicated-retriage note. No verdict assigned, no pin
  changed — full triage stays a separate ask-first task per this
  repo's rules.

requirements.txt, constraints.txt, and pyproject.toml's actual version
bounds were already mutually consistent (constraints.txt's == pins all
satisfy the >= / < ranges in requirements.txt and pyproject.toml).

Verified: clean Python 3.12 + 3.13 venvs, `pip install -r
requirements.txt -c constraints.txt && pip install -e ".[dev]"`,
transformers/accelerate/sentence-transformers import triangle, ruff
check, ruff format --check, mypy --strict, and pytest tests/unit/
(118/118 passed on both interpreters). Integration tests skipped — no
model download in this environment.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQngYCdcQQHKr18ABhe4ut
Codifies the checks performed in this session as a repeatable skill:
cross-check requirements.txt/constraints.txt/pyproject.toml version
bounds, grep the repo for stale "current pin" claims left behind after
a fix (the pyproject.toml <4.45 comment and the two skill docs' stale
accelerate==0.34.2 references fixed in the prior commit are the
motivating examples), verify the clean-venv install + compatibility
triangle, run the four CI gates, and spot-check pip-audit against
docs/SECURITY_AUDIT.md's documented findings.

Deliberately scoped narrower than deps-security-refresh: this skill
makes no version-pin changes and does no CVE reachability triage — it
only catches and fixes documentation/comment drift once the pins
themselves are already correct.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DQngYCdcQQHKr18ABhe4ut
@cgfixit
cgfixit marked this pull request as ready for review August 15, 2026 03:38
@cgfixit
cgfixit merged commit f21e20a into main Aug 15, 2026
8 checks passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cf8dec84e0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +40 to +43
If you find a mismatch, the fix is almost always to `constraints.txt` or one comment —
**do not** widen/narrow a range to make a mismatch disappear; that's a behavior change
and is ask-first per CLAUDE.md §6. Report the mismatch and stop if the right fix isn't
obviously "the comment is wrong."

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Require approval before repairing a mismatched pin

When constraints.txt contains a pin outside the declared ranges, this directs the agent to treat changing that pin alone as the default fix, even though the skill promises not to change versions and the repository requires dependency changes to move through all three manifests. A verification-only invocation could therefore silently select a new package version without the required dependency-refresh review; report the mismatch and dispatch deps-security-refresh or ask before modifying any pin.

AGENTS.md reference: .codex/AGENTS.md:L54-L54

Useful? React with 👍 / 👎.

Comment on lines +52 to +54
```bash
grep -rn "4\.44\.2\|3\.0\.1\|<4\.45\|0\.26\.0\|0\.34\.2" --include='*.md' --include='*.toml' --include='*.txt' .
```

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Include current pins in the repository-wide search

The command advertised as searching both current and historical versions only contains the five historical values; it omits current pins such as 4.53.0, 3.4.1, and 1.14.0. Consequently, a stale assertion involving a current pin outside the handful of manually listed files is never discovered, so the skill can report a clean drift check without performing its stated repository-wide verification. Build the search terms from the manifests or include both current and historical values.

Useful? React with 👍 / 👎.

Comment on lines +141 to +142
Only if Steps 1-2 found real drift (most runs, especially soon after this skill is
created, should find nothing — say so and stop):

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Commit audit-only findings from Step 5

When Steps 1–2 are clean but the optional Step 5 audit finds a net-new advisory, Step 5 explicitly requires editing docs/SECURITY_AUDIT.md, while this condition says to commit only for drift found in Steps 1–2. Following the workflow therefore leaves the required audit update uncommitted or discarded; include Step 5 findings in this commit condition or make Step 5 report-only.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants