Repository navigation
chore(deps): update dependency virtualenv to v21.14.6 - #730
Conversation
There was a problem hiding this comment.
This bump cannot land as-is: validate fails because virtualenv==21.14.2 declares a new runtime dependency, packaging>=23.1, and requirements-ci.lock has no packaging entry. With pip install --require-hashes -r requirements-ci.lock (the Static hygiene step), pip refuses any transitive requirement that isn't pinned and hashed:
Collecting packaging>=23.1 (from virtualenv==21.14.2->-r requirements-ci.lock (line 111))
ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not:
packaging>=23.1 … (from virtualenv==21.14.2->-r requirements-ci.lock (line 111))
(job 110367457364; identical failure on the earlier run 110367421005.)
requirements-ci.lock:111 is the only line Renovate changed; grep -n '^packaging' requirements-ci.lock at head 1a60858 returns nothing. Renovate's lockfile-maintenance for this file type only rewrites the one pin, so it will keep re-pushing the same broken state.
Fix is a lockfile regeneration, not a Renovate retry: rerun the command in requirements-ci.lock:2 (uv pip compile --generate-hashes --python-version 3.13 -) so packaging gets a pinned, hashed entry alongside virtualenv==21.14.2. Someone with push access to this branch (or a fresh PR) needs to do that; I have not changed anything. #729 (filelock 4.0.8) is unaffected — its validate is green.
Confidence: 3/5 (needs attention) — 1 high finding
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
|
Hive filed out-of-scope review findings as backlog issues so they do not block this PR:
Cap: 3 backlog issue(s) per PR. |
🐝 Superseded regeneration series
Posted once on the newest PR rather than on each of them, so a daily regeneration does not produce a daily comment on every PR in the series. Evidence — identical changed-file set (1 file(s)):
This is a suggestion, not a verdict. Hive will not close, label, approve or merge anything here — a human decides. It was produced by comparing changed-file sets across open PRs, which is a candidate generator: PRs that share a file are not necessarily the same work. Here the patches DIFFER, so this is the weaker tier: dependency-bump PRs that edit one shared manifest, and unrelated fixes to one busy file, both land in it. Read the diffs before acting. |
1a60858 to
2fdbe92
Compare
There was a problem hiding this comment.
HUMAN DECISION NEEDED — merge is blocked until requirements-ci.lock is regenerated with the new packaging transitive pin; decide whether to regenerate on this branch or let Renovate re-roll.
correctness
- Lock is incomplete; CI install fails (
requirements-ci.lock:111). virtualenv 21.14.2 adds a new runtime dependencypackaging>=23.1(PyPIrequires_dist; absent in 21.13.0). The diff bumps only thevirtualenv==line, sopython -m pip install --require-hashes -r requirements-ci.lock(.github/workflows/validate.yml:43,.github/workflows/publish-contribute.yml:56) aborts with "In --require-hashes mode, all requirements must have their versions pinned" — bothvalidatechecks on this PR fail for exactly that. Fix:uv pip compile --generate-hashes --python-version 3.13per the header atrequirements-ci.lock:2so a hashedpackaging==entry is added.
style (out-of-scope, backlog)
scripts/update-requirements-ci-hashes.mjs:12-49only refreshes hashes for existing==lines (REQUIREMENT_START_PATTERN), so therenovate-hashes.ymlrepair step (.github/workflows/renovate-hashes.yml:127) cannot add newly introduced transitive deps; any upstream dep that grows a requirement will break the lock this way again.
No findings from: security, intent-alignment (linked issue #8203 does not exist in this repo; judged against the PR title/body instead), docs-currency.
Confidence: 3/5 (needs attention) — 1 high finding
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
2fdbe92 to
6a42249
Compare
There was a problem hiding this comment.
correctness
requirements-ci.lock:111bumpsvirtualenvto 21.14.2 but the lock has no entry for its new runtime dependencypackaging>=23.1(added in virtualenv 21.14.0, pypa/virtualenv#3361). CIvalidatejob runspip install --require-hashes -r requirements-ci.lockand fails: "In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1 from … (from virtualenv==21.14.2->-r requirements-ci.lock (line 111))" (runs 36906602210, 36906594794).scripts/update-requirements-ci-hashes.mjsonly refreshes hashes for pins already present, so the renovate hash-repair cannot add the missing transitive pin. Fix: regenerate the lock with the tool named inrequirements-ci.lock:2(uv pip compile --generate-hashes --python-version 3.13) sopackaging==<ver>with hashes and# via virtualenvis added.
intent-alignment
- The PR's closing keyword references projectbluefin/contribute#8203, which does not resolve (
gh issue view 8203→ "Could not resolve to an issue"). Contract cannot be verified; treating the Renovate update itself as the intent.
No findings from: security, style, docs-currency.
Confidence: 3/5 (needs attention) — 1 high finding
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
6a42249 to
7cec50f
Compare
There was a problem hiding this comment.
correctness
- Lock missing new transitive dep
packaging—requirements-ci.lock:111bumpsvirtualenv==21.14.2, whoserequires_distaddspackaging>=23.1(not required by 21.13.0). The lock pins nopackagingentry, sopython -m pip install --require-hashes -r requirements-ci.lock(validate job) fails:ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1 from virtualenv==21.14.2. Bothvalidatechecks are red (jobs 110589315568, 110589316166). Fix: regenerate the lock (uv pip compile --generate-hashes --python-version 3.13, perrequirements-ci.lock:2) sopackaging==<ver>with hashes is added; the hash-repair task only refreshes existing pins and cannot add a new package.
intent-alignment
- Closing reference
#8203does not resolve to an issue in this repo (gh issue viewfails); reviewed against the PR body (plain Renovate bump) instead.
No findings from: security, style, docs-currency.
Confidence: 3/5 (needs attention) — 1 high finding
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
7cec50f to
4291e11
Compare
There was a problem hiding this comment.
correctness
validatefails: lock is missing virtualenv's new transitive deppackaging(requirements-ci.lock:111-114). virtualenv 21.14.0+ declarespackaging>=23.1as a runtime requirement (added by pypa/virtualenv#3361, "compare wheel versions with PEP 440"); 21.13.0 did not. This PR only rewrote thevirtualenv==line and its two--hashlines, sopip install --require-hashes -r requirements-ci.lock(.github/workflows/validate.yml, "Run set -euo pipefail" step) aborts withIn --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1— see job 110652122914. Therefreshjob passed becausescripts/update-requirements-ci-hashes.mjsonly re-fetches hashes for lines already present (parseRequirement/fetchPackageHashes, lines 22-78); it never recompiles the dependency set, so new transitive deps are invisible to it.
Fix: recompile per the header onrequirements-ci.lock:2(uv pip compile --generate-hashes --python-version 3.13) or add apackaging==<ver>block with both PyPI sha256 hashes and# via virtualenv.
No findings from: security, intent-alignment, style, docs-currency.
Confidence: 3/5 (needs attention) — 1 high finding
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
0bdf58d to
5a6930c
Compare
There was a problem hiding this comment.
correctness
- CI install broken — new transitive dep
packagingmissing from lock (high). virtualenv 21.14.3 addspackaging>=23.1torequires_dist(21.13.0 did not).requirements-ci.lockhas nopackagingentry (entries at lines 3–111 are cfgv, distlib, filelock, identify, nodeenv, platformdirs, pre-commit, python-discovery, pyyaml, virtualenv), so.github/workflows/validate.yml:43(pip install --require-hashes -r requirements-ci.lock) fails:ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1 (from virtualenv==21.14.3->-r requirements-ci.lock (line 111))(job 110732884496).publish-contribute.ymlruns the same install. Fix: regenerate per the header atrequirements-ci.lock:2(uv pip compile --generate-hashes --python-version 3.13) sopackaging==<ver>with hashes is added. - Out-of-scope:
scripts/update-requirements-ci-hashes.mjs/renovate-hashes.ymlonly rewrite hashes for existingname==versionlines, so any upstream bump that introduces a new transitive dependency will keep breaking this way; worth a follow-up to detect missing transitive pins.
intent-alignment
- Info: the review contract cites issue #8203 but
gh issue view 8203returns "Could not resolve", and the PR body has no closing keyword. Judged against the PR title instead; the diff (lines 111–113) is exactly the stated bump. Hashes verified against PyPI forvirtualenv-21.14.3-py3-none-any.whland.tar.gz.
No findings from: security, style, docs-currency.
Confidence: 3/5 (needs attention) — 1 high finding
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
5a6930c to
f312861
Compare
There was a problem hiding this comment.
correctness
- Lockfile missing new transitive dep
packaging—validateCI fails. virtualenv 21.14.3 addspackaging>=23.1to itsRequires-Dist(21.13.0 did not have it). The PR only rewrote the pin/hashes atrequirements-ci.lock:111-113; nopackaging==…entry was added..github/workflows/validate.yml:43runspython -m pip install --require-hashes -r requirements-ci.lock, which aborts:ERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1 (from virtualenv==21.14.3)(run 36989252630). Fix: regenerate the lock per its header (requirements-ci.lock:2:uv pip compile --generate-hashes --python-version 3.13 -) sopackagingis pinned with hashes. - (out-of-scope, tooling)
scripts/update-requirements-ci-hashes.mjs:30-78only refreshes hashes for packages already listed in the lock; it cannot add transitive deps a new upstream version introduces, so therenovate-hashes.ymlbackstop described atdocs/skills/image-build.md:119-124passes (refresh✅) while the lock is still unbuildable. Worth a follow-up to recompile instead of hash-patch.
intent-alignment
- (out-of-scope, info) Linked contract projectbluefin/contribute#8203 does not resolve (
gh issue view 8203→ not found); diff was judged against the PR title/body, which it matches apart from the missing dep above.
No findings from: security, style, docs-currency.
Confidence: 3/5 (needs attention) — 1 high finding
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
f312861 to
bd17f52
Compare
There was a problem hiding this comment.
correctness
- Lock is incomplete; CI
validatefails on install.requirements-ci.lock:111bumpsvirtualenv==21.14.3, which (unlike 21.13.0) declarespackaging>=23.1as a runtime dependency. The lock has nopackagingentry, sopython -m pip install --require-hashes -r requirements-ci.lockaborts withERROR: In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1(job 110836837650). Renovate's version-only bump + hash refresh (scripts/update-requirements-ci-hashes.mjs) cannot add new transitive deps. Fix: regenerate the lock with the documented command inrequirements-ci.lock:2(uv pip compile --generate-hashes --python-version 3.13) sopackaging==<ver>with hashes is added under# via virtualenv.
intent-alignment
- Closing-keyword issue projectbluefin/contribute#8203 does not resolve (
gh issue view→ not found); contract judged against the PR title (dependency bump) instead.
No findings from: security, style, docs-currency.
Confidence: 3/5 (needs attention) — 1 high finding
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
bd17f52 to
3d8c8e8
Compare
There was a problem hiding this comment.
correctness
requirements-ci.lock:111bumpsvirtualenv21.13.0 → 21.14.4, but virtualenv 21.14.x adds a new runtime dependencypackaging>=23.1(PyPIrequires_dist; absent in 21.13.0). The lock has nopackagingentry, sopip install --require-hashes -r requirements-ci.lock(validate/ Static hygiene job) fails:In --require-hashes mode, all requirements must have their versions pinned with ==. These do not: packaging>=23.1. Bothvalidateruns on this head fail (runs 37026314817, 37026323567). The hash-repair workflow only refreshes hashes for existing pins; it cannot add a transitive. Fix: regenerate the lock per its header (uv pip compile --generate-hashes --python-version 3.13) so a pinned+hashedpackagingline (# via virtualenv) is added.
intent-alignment
- Closing-keyword contract
#8203does not resolve inprojectbluefin/contribute(gh issue view 8203→ not found); judged against the PR title only.
No findings from: security, style, docs-currency.
Confidence: 3/5 (needs attention) — 1 high finding
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
3d8c8e8 to
656fb1b
Compare
840ebc9 to
0106f17
Compare
c81f5d2 to
7134bd3
Compare
41fc67b to
50d926f
Compare
dac606e to
daa310b
Compare
395414f to
43ddae4
Compare
There was a problem hiding this comment.
intent-alignment
- info: Review contract cites projectbluefin/contribute#8203, but
gh issue view 8203returns "Could not resolve to an issue"; the PR body carries no closing keyword. Judged against the PR's own stated intent (virtualenv 21.13.0 → 21.14.5), which the diff fully matches (requirements-ci.lock:115-117). Added transitivepackaging==26.3(requirements-ci.lock:25-28) is required by virtualenv 21.14.5 (packaging>=23.1); both hashes match PyPI.python-discovery==1.6.1(requirements-ci.lock:36-39) already satisfies the newpython-discovery>=1.6requirement.
No findings from: correctness, security, style, docs-currency.
Confidence: 5/5 (safe)
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
There was a problem hiding this comment.
intent-alignment
- (low) PR title/body say virtualenv
21.14.5and the release notes stop at 21.14.5, but the lock pinsvirtualenv==21.14.6(requirements-ci.lock:115, already in the first commit 82a34ef). Hashes verified against PyPI for 21.14.6 wheel+sdist (lock:116-117), and transitive pins satisfy its metadata (packaging==26.3lock:25,python-discovery==1.6.1lock:36,distlib==0.4.3lock:7). Content is fine; title/body should be refreshed so the 21.14.6 changes are what reviewers see.
No findings from: correctness, security, style, docs-currency.
Confidence: 5/5 (safe)
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
There was a problem hiding this comment.
intent-alignment
- (low) PR title/body describe
21.14.5, butrequirements-ci.lock:115pinsvirtualenv==21.14.6(Renovate commit f3f9c0d is already titled 21.14.6; 21.14.6 shipped 2026-10-08 14:49 UTC). Body release notes stop at 21.14.5, so the 21.14.6 changes (pypa/virtualenv#3378–#3383, CI + embed-log read guard) are not surfaced. Hashes atrequirements-ci.lock:116-117andpackaging==26.3at:25-27match PyPI;python-discovery==1.6.1(:36) satisfies the new>=1.6.1floor;validate(workflow_dispatch) passed on baef075. Title will self-correct on next Renovate rebase — not blocking.
Note: the linked contract issue #8203 does not resolve in this repo (gh issue view 8203 → not found); intent judged against the PR body.
No findings from: correctness, security, style, docs-currency.
Confidence: 5/5 (safe)
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
There was a problem hiding this comment.
intent-alignment
- (low) PR title/body say
virtualenv→21.14.5, butrequirements-ci.lock:115pinsvirtualenv==21.14.6(and the Renovate commit on the branch is "update dependency virtualenv to v21.14.6"). The title/body are stale relative to the diff; the merged state will be 21.14.6. The linked contract issue #8203 could not be resolved (gh issue view→ not found), so intent was judged from the diff and commit messages only.
Verified independently against PyPI: virtualenv 21.14.6 wheel/sdist sha256 and packaging 26.3 wheel/sdist sha256 match requirements-ci.lock:25-27,115-117; packaging>=26.3 is a new requirement of virtualenv 21.14.x and is present with # via virtualenv. No CI checks were reported on the branch at review time.
No findings from: correctness, security, style, docs-currency.
Confidence: 3/5 (needs attention) — 1 perspective requested changes
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
|
Title updated to match the diff: Hive-Fix-Attempt: 1/6 🐝 Hive Agent: — hive: agent=scanner backend=copilot model=claude-opus-5.5 copilot=1.0.88 |
There was a problem hiding this comment.
intent-alignment
- info: PR body table says
21.13.0→21.14.5, but the diff pinsvirtualenv==21.14.6(requirements-ci.lock:115) and the title says v21.14.6. Stale Renovate body; the lock is what ships. Hashes at requirements-ci.lock:116-117 and the newpackaging==26.3pin (requirements-ci.lock:25-27) match PyPI, and 21.14.6's requirements (packaging>=26.3, python-discovery>=1.6.1, filelock, platformdirs, distlib) are all satisfied by existing pins. - info: the linked contract issue #8203 does not resolve in this repo (
gh issue view 8203→ not found) and the PR carries no closing reference; judged against the PR's own stated purpose.
No findings from: correctness, security, style, docs-currency.
Confidence: 5/5 (safe)
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
There was a problem hiding this comment.
docs-currency
- info: PR body table and release notes stop at
21.13.0 → 21.14.5, whilerequirements-ci.lock:115pinsvirtualenv==21.14.6(title matches the lock). Body is stale by one patch; Renovate will normally refresh it on the next rebase.
No findings from: correctness, security, intent-alignment, style.
Confidence: 5/5 (safe)
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
There was a problem hiding this comment.
intent-alignment
- info: PR body's update table and release notes stop at
21.13.0 → 21.14.5, butrequirements-ci.lock:115pinsvirtualenv==21.14.6(recompiled byrenovate-hashes.ymlin 4f92202). Title matches the lock; body is stale. Not blocking — the 21.14.6 sdist/wheel sha256 inrequirements-ci.lock:116-117andpackaging==26.3in:25-27match PyPI, and the dispatchedvalidaterun on this head passed. - Linked issue #8203 does not resolve in this repo; intent judged against the PR title/diff.
No findings from: correctness, security, style, docs-currency.
Confidence: 5/5 (safe)
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
There was a problem hiding this comment.
docs-currency
- PR body is stale: table and release notes stop at
21.13.0→21.14.5, but the diff pinsvirtualenv==21.14.6(requirements-ci.lock:115). Renovate rebased the branch without regenerating the body; the 21.14.6 release notes are not shown. Non-blocking — hashes at requirements-ci.lock:116-117 match the PyPI sdist/wheel for 21.14.6, andpackaging==26.3(requirements-ci.lock:25-27) satisfies the newpackaging>=26.3requirement with matching hashes.
intent-alignment
- The closing-keyword issue projectbluefin/contribute#8203 does not resolve (
gh issue view 8203→ not found). The diff itself is a pure lock bump matching the PR title, so this is a metadata issue, not a scope problem.
No findings from: correctness, security, style.
Confidence: 5/5 (safe)
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
There was a problem hiding this comment.
intent-alignment
- (low) PR body table and release notes stop at
21.13.0 → 21.14.5, but the title andrequirements-ci.lock:115pinvirtualenv==21.14.6. Body is stale from a Renovate re-push; the diff is the authoritative bump. Hashes atrequirements-ci.lock:116-117and the newpackaging==26.3pin at:25-27match PyPI for 21.14.6 / 26.3. The closing-keyword reference#8203does not resolve in this repo, so no issue contract was available to judge against.
No findings from: correctness, security, style, docs-currency.
Confidence: 5/5 (safe)
— hive: agent=reviewer backend=copilot model=claude-fable-5.1 copilot=1.0.88
Renovate bumped the pinned version but could not run the post-upgrade task that recompiles the lockfile, so its --hash lines and any newly required dependency were missing and pip --require-hashes rejected it. Recompiled with uv by scripts/update-requirements-ci-hashes.mjs in https://github.com/projectbluefin/contribute/actions/runs/38010273563.
This PR contains the following updates:
21.13.0→21.14.5Release Notes
pypa/virtualenv (virtualenv)
v21.14.5Compare Source
What's Changed
Full Changelog: pypa/virtualenv@21.14.4...21.14.5
v21.14.4Compare Source
What's Changed
Full Changelog: pypa/virtualenv@21.14.3...21.14.4
v21.14.3Compare Source
What's Changed
Full Changelog: pypa/virtualenv@21.14.2...21.14.3
v21.14.2Compare Source
What's Changed
Full Changelog: pypa/virtualenv@21.14.1...21.14.2
v21.14.1Compare Source
What's Changed
Full Changelog: pypa/virtualenv@21.14.0...21.14.1
v21.14.0Compare Source
What's Changed
New Contributors
Full Changelog: pypa/virtualenv@21.13.0...21.14.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.