Skip to content

Align locked dependencies with Home Assistant core pins - #96

Open
mdz wants to merge 1 commit into
mainfrom
claude/dependabot-home-assistant-versions-203d46
Open

mdz wants to merge 1 commit into
mainfrom
claude/dependabot-home-assistant-versions-203d46

Conversation

@mdz

@mdz mdz commented Oct 6, 2026

Copy link
Copy Markdown
Owner

This library ships in the Home Assistant smarttub integration, so the lockfile should test against the versions HA core pins rather than whatever Dependabot picks.

Changes

Locked to the versions pinned on Home Assistant core's dev/rc branch (homeassistant/package_constraints.txt):

Package Before After
aiohttp 3.14.3 3.14.4
PyJWT 2.13.0 2.15.1
yarl 1.20.1 1.25.1
propcache 0.3.2 0.5.4
attrs 25.3.0 26.1.0
cryptography 50.0.0 50.0.1

Also:

  • urllib3 2.7.0 → 2.8.0 and virtualenv 20.36.1 → 21.7.13 (dev-only security updates; HA only constrains urllib3>=2.0)
  • multidict 6.5.0 → 6.9.1, since 6.5.0 was yanked (HA requires >=6.4.2)
  • requirements.txt: pyjwt cap raised to <2.16

The published dependency ranges in pyproject.toml are unchanged, so this does not affect what HA resolves.

Supersedes #93, #94 and #95. #94 would have locked PyJWT 2.15.0, which matches neither HA stable (2.13.0) nor dev/rc (2.15.1).

Testing

ruff check and pytest --cov-fail-under=100 pass locally on Python 3.14.

🤖 Generated with Claude Code

Lock the packages Home Assistant core pins to the versions on its dev/rc
branch (aiohttp 3.14.4, PyJWT 2.15.1, yarl 1.25.1, propcache 0.5.4,
attrs 26.1.0, cryptography 50.0.1) so tests run against what HA ships.
Also pick up the dev-only security bumps for urllib3 (2.8.0) and
virtualenv (21.7.13), and move off the yanked multidict 6.5.0.

Supersedes #93, #94 and #95.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant