Skip to content

build(deps): refresh Python and npm dependencies - #114

Merged
frankbuckley merged 1 commit into
mainfrom
dev/codex/update-dependencies-2026-09-30
Sep 30, 2026
Merged

frankbuckley merged 1 commit into
mainfrom
dev/codex/update-dependencies-2026-09-30

Conversation

@frankbuckley

Copy link
Copy Markdown
Member

Note

Drafted by a LLM-based AI tool (Codex/GPT-6).

Refresh the dependency declarations and both lockfiles against stable releases available on 30 September 2026. The library now requires xarray 2026.9.0 and DuckDB 1.5.6; the documentation tooling uses cspell 10.3.6.

Changes

Direct dependency Before After
xarray 2026.7.0 2026.9.0
DuckDB 1.5.5 1.5.6
cspell 10.3.4 10.3.6

uv lock --upgrade also updates charset-normalizer, filelock, fonttools, fqdn, ipykernel, msgspec, platformdirs, PyJWT, uv and virtualenv. The npm refresh updates the cspell packages, ansi-regex, chalk and chalk-template.

Checked all declared Python dependencies, optional extras, development and research groups, the build backend, npm dependencies, CI actions and the .NET SDK against their official registries or releases. Other direct dependencies and pinned CI actions and SDK are current. Keep Python 3.14 and Node 24 LTS as the supported runtime lines. Keep the NumPy and PyTensor limits; PyTensor 3.3.2 still requires Numba <=0.67.0, and Numba 0.67.0 requires NumPy <2.6.

The xarray release disables Bottleneck by default, removes the remaining zarr-python 2 compatibility code and raises its h5netcdf minimum to 1.8. This repository already requires Zarr 3.4.0 and h5netcdf 1.8.1, and does not enable Bottleneck. The dependency update needs no library code changes.

Validation

Validated locally on Windows x64 with Python 3.14.7 and Node 24.21.0.

  • uv sync --locked, uv lock --check and uv pip check passed.
  • Full pytest suite passed with 1,166 passed and 13 Windows-specific skips. Test temporary files were placed outside the worktree because the Git provenance tests need a directory outside a Git repository.
  • uv run --no-sync ruff check src/python and uv run --no-sync ruff format --check src/python passed.
  • uv build --package dse-research-utils built the wheel and source archive.
  • A local smoke check passed for an ArviZ DataTree saved and loaded through h5netcdf, including named observation alignment. DuckDB checks passed for pandas strings, missing values and SQL aggregates.
  • npm ci passed and reported no known vulnerabilities. npm outdated --json returned no outdated direct dependencies.
  • npm run spellcheck -- --gitignore checked all 15 repository Markdown files selected by the spelling configuration with no issues. The flag excludes the temporary package caches used for local validation.
  • npm run format:check and git diff --check passed.

The CI workflow will also test Linux ARM64. These local checks do not validate downstream research analyses or refit models.

@frankbuckley frankbuckley self-assigned this Sep 30, 2026
@frankbuckley
frankbuckley marked this pull request as ready for review September 30, 2026 08:29
@frankbuckley
frankbuckley merged commit 12fd7e5 into main Sep 30, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant