Skip to content

fix(deps): update vulnerable and incompatible dependencies - #325

Merged
betinacosta merged 6 commits into
release-0.36.2from
fix/release-0.36.2
Sep 10, 2026
Merged

betinacosta merged 6 commits into
release-0.36.2from
fix/release-0.36.2

Conversation

@betinacosta

Copy link
Copy Markdown
Member

Disclaimer: Do not include SAP-internal or customer-specific information in this PR (e.g. internal system URLs, customer names, tenant IDs, or confidential configurations). This is a public repository.

Description

Patch release 0.36.2 that upgrades OpenTelemetry to 1.44.x, tightens dependency version bounds, and fixes several bugs across the telemetry, ADMS, and data anonymization modules.

Dependency updates:

  • Upgraded opentelemetry-api, opentelemetry-sdk, and OTLP exporters from ~=1.42.1 to ~=1.44.0
  • Upgraded protobuf from >=4.25.0 to >=7.36.0,<8
  • Upgraded protovalidate from >=0.13.0 to >=1.0.0,<2
  • Added explicit upper-bound constraints to all runtime and optional dependencies to prevent silent breakage on major version releases

Bug fixes:

  • AsyncHttpClient._resolve_token(): switched from asyncio.iscoroutinefunction to inspect.iscoroutinefunction to correctly detect coroutine functions wrapped by third-party libraries
  • GenAIAttributeTransformer: fixed TypeError under OpenTelemetry 1.44.x where BoundedAttributes (the default OTEL span attribute type) is immutable — now copied to a plain dict before mutation
  • HttpTransport._post_file_request: added explicit BinaryIO | bytes type annotation and a None-guard assertion for file_content to satisfy the ty type checker

Other:

  • Updated pypa/gh-action-pypi-publish in release.yml from v1.14.0 to v1.14.2
  • Added docs/HOTFIX.md: step-by-step guide for applying hotfixes to previously released versions without including unreleased main changes
  • Updated test fixtures for S3Error constructor argument order (minio API change) and a2a-sdk message format (role now a string, parts required)

Related Issue

Closes #

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update
  • Dependency update

How to Test

  1. Install in a clean environment: uv sync
  2. Run the unit test suite: uv run pytest tests/unit
  3. Verify telemetry span attribute mutation no longer raises TypeError with OpenTelemetry 1.44.x
  4. Verify AsyncHttpClient correctly resolves async token callables (including those wrapped by functools or similar)
  5. Run pre-commit checks: uvx pre-commit run --all-files

Checklist

  • I have read the Contributing Guidelines
  • I have verified that my changes solve the issue
  • I have added/updated automated tests to cover my changes
  • All tests pass locally
  • I have verified that my code follows the Code Guidelines
  • I have updated documentation (if applicable)
  • I have added type hints for all public APIs
  • My code does not contain sensitive information (credentials, tokens, etc.)
  • I have followed Conventional Commits for commit messages

Additional Notes

The protobuf and protovalidate major version bumps may require consumers who have pinned older majors to update their constraints. The uv.lock file was fully regenerated after all constraint changes.

@betinacosta
betinacosta marked this pull request as ready for review September 10, 2026 17:27
@betinacosta
betinacosta requested a review from a team as a code owner September 10, 2026 17:28
@betinacosta
betinacosta merged commit c3bd49f into release-0.36.2 Sep 10, 2026
5 of 7 checks passed
@betinacosta
betinacosta deleted the fix/release-0.36.2 branch September 10, 2026 19:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants