fix: remove stale pre-4.53 transformers comment from pyproject.toml - #29
Conversation
- pyproject.toml: the dependency comment block said transformers was "Capped at <4.45 until upstream fix" with a remediation snippet for transformers==4.44.2/sentence-transformers==3.0.1, directly contradicting the dependencies list two lines below (transformers>=4.53.0,<5.0.0). Root cause: the >=4.45 cap comment was never removed when the floor was raised to >=4.53.0 in commit 9e5f8ff — it shipped self-contradictory from that same commit. Replaced with a DEPENDENCY NOTES block matching requirements.txt's house style, keeping only the notes that are still true. - .claude/skills/deps-security-refresh/SKILL.md, .claude/skills/insight-optimize/SKILL.md: both described accelerate==0.34.2 as "the current" constraints.txt pin, but that was fixed to accelerate==1.14.0 in commit 312096b (2026-07-08). Reworded to past-tense/"watch for regression" framing so a future agent reading these skills doesn't mistake fixed history for a live bug. - docs/SECURITY_AUDIT.md: re-ran pip-audit against a clean constraints-pinned install as part of this verification; logged one net-new, not-yet-triaged advisory (PYSEC-2026-2290) alongside the already-flagged dedicated-retriage note. No verdict assigned, no pin changed — full triage stays a separate ask-first task per this repo's rules. requirements.txt, constraints.txt, and pyproject.toml's actual version bounds were already mutually consistent (constraints.txt's == pins all satisfy the >= / < ranges in requirements.txt and pyproject.toml). Verified: clean Python 3.12 + 3.13 venvs, `pip install -r requirements.txt -c constraints.txt && pip install -e ".[dev]"`, transformers/accelerate/sentence-transformers import triangle, ruff check, ruff format --check, mypy --strict, and pytest tests/unit/ (118/118 passed on both interpreters). Integration tests skipped — no model download in this environment. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DQngYCdcQQHKr18ABhe4ut
Codifies the checks performed in this session as a repeatable skill: cross-check requirements.txt/constraints.txt/pyproject.toml version bounds, grep the repo for stale "current pin" claims left behind after a fix (the pyproject.toml <4.45 comment and the two skill docs' stale accelerate==0.34.2 references fixed in the prior commit are the motivating examples), verify the clean-venv install + compatibility triangle, run the four CI gates, and spot-check pip-audit against docs/SECURITY_AUDIT.md's documented findings. Deliberately scoped narrower than deps-security-refresh: this skill makes no version-pin changes and does no CVE reachability triage — it only catches and fixes documentation/comment drift once the pins themselves are already correct. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DQngYCdcQQHKr18ABhe4ut
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cf8dec84e0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| If you find a mismatch, the fix is almost always to `constraints.txt` or one comment — | ||
| **do not** widen/narrow a range to make a mismatch disappear; that's a behavior change | ||
| and is ask-first per CLAUDE.md §6. Report the mismatch and stop if the right fix isn't | ||
| obviously "the comment is wrong." |
There was a problem hiding this comment.
Require approval before repairing a mismatched pin
When constraints.txt contains a pin outside the declared ranges, this directs the agent to treat changing that pin alone as the default fix, even though the skill promises not to change versions and the repository requires dependency changes to move through all three manifests. A verification-only invocation could therefore silently select a new package version without the required dependency-refresh review; report the mismatch and dispatch deps-security-refresh or ask before modifying any pin.
AGENTS.md reference: .codex/AGENTS.md:L54-L54
Useful? React with 👍 / 👎.
| ```bash | ||
| grep -rn "4\.44\.2\|3\.0\.1\|<4\.45\|0\.26\.0\|0\.34\.2" --include='*.md' --include='*.toml' --include='*.txt' . | ||
| ``` |
There was a problem hiding this comment.
Include current pins in the repository-wide search
The command advertised as searching both current and historical versions only contains the five historical values; it omits current pins such as 4.53.0, 3.4.1, and 1.14.0. Consequently, a stale assertion involving a current pin outside the handful of manually listed files is never discovered, so the skill can report a clean drift check without performing its stated repository-wide verification. Build the search terms from the manifests or include both current and historical values.
Useful? React with 👍 / 👎.
| Only if Steps 1-2 found real drift (most runs, especially soon after this skill is | ||
| created, should find nothing — say so and stop): |
There was a problem hiding this comment.
Commit audit-only findings from Step 5
When Steps 1–2 are clean but the optional Step 5 audit finds a net-new advisory, Step 5 explicitly requires editing docs/SECURITY_AUDIT.md, while this condition says to commit only for drift found in Steps 1–2. Following the workflow therefore leaves the required audit update uncommitted or discarded; include Step 5 findings in this commit condition or make Step 5 report-only.
Useful? React with 👍 / 👎.
Summary
Verified
requirements.txt,constraints.txt, andpyproject.tomlfor accuracy andmutual consistency per CLAUDE.md §4.9 (the "three files must move together" rule).
The actual version bounds/pins were already consistent —
constraints.txt's==pinsall satisfy the
>=/<ranges declared inrequirements.txtandpyproject.toml.However, the surrounding documentation had drifted out of sync with reality:
pyproject.toml: the dependency comment block said transformers was "Capped at<4.45 until upstream fix" with a remediation snippet for
transformers==4.44.2/sentence-transformers==3.0.1— directly contradicting thedependencieslist two lines below (transformers>=4.53.0,<5.0.0). Root cause:the
<4.45cap comment was never removed when the floor was raised to>=4.53.0; itshipped self-contradictory from the same commit that introduced the file (
9e5f8ff).Replaced with a
DEPENDENCY NOTESblock matchingrequirements.txt's existing housestyle, keeping only the notes that are still true.
.claude/skills/deps-security-refresh/SKILL.mdand.claude/skills/insight-optimize/SKILL.md: both describedaccelerate==0.34.2as"the current"
constraints.txtpin. That was fixed toaccelerate==1.14.0incommit
312096b(2026-07-08) — over a month before this pass. Root cause: theskill docs were written to describe a live bug and never updated after the fix
landed. Reworded to past-tense / "watch for regression" framing so a future agent
reading these skills doesn't mistake fixed history for an open bug.
docs/SECURITY_AUDIT.md: re-ranpip-auditagainst a clean constraints-pinnedinstall as part of this verification and logged one net-new, not-yet-triaged advisory
(
PYSEC-2026-2290, fix in5.5.0) alongside the addendum's existingdedicated-retriage note. No reachability verdict assigned and no pin changed — a full
CVE re-triage is explicitly out of scope here per the doc's own note (it's a separate,
ask-first task).
Verification performed
pip install -r requirements.txt -c constraints.txt && pip install -e ".[dev]"— both succeed cleanly.init_empty_weights,TorchTensorParallelPlugin,SentenceTransformer) — imports clean on both.ruff check src/ tests/→ 0 findingsruff format --check src/ tests/→ already formattedmypy src/insight_extractor→ Success (strict), 10 filespytest tests/unit/ -v --tb=short→ 118/118 passed on Python 3.12 and 3.13pip-auditagainst the actual pinned environment — no new findings beyond what'salready documented, except the one net-new advisory noted above
Skipped: integration tests (
tests/integration/) — no BERT model download in thissandboxed environment, per repo convention (not moved into
tests/unit/).Test plan
git diff --stattouches only the four files the task requiredGenerated by Claude Code