From 185f77c477e121c0cbb5af9070efc300e8a1b007 Mon Sep 17 00:00:00 2001 From: zhanghui Date: Thu, 24 Sep 2026 18:26:08 +0800 Subject: [PATCH] fix(deps): pin openai below 3 so a fresh install can call the LLM openai 3.19.2 (released 2026-09-24) resolves with an httpx 1.0 pre-release and its client raises 'module httpx has no attribute Timeout' on every request, so a fresh 'pip install everos' today fails every LLM and embedding call (memorize and hybrid/vector search 500). Reproduced on macOS and on a stock Windows 11 machine with plain pip; environments from uv.lock (openai 2.36.0) are unaffected, which is why CI never saw it. Pin openai<3 and release 1.4.1 (version bump + CHANGELOG section). Co-Authored-By: Claude Fable 5.1 --- CHANGELOG.md | 22 ++++++++++++++++++++++ docs/openapi.json | 2 +- pyproject.toml | 6 ++++-- uv.lock | 4 ++-- 4 files changed, 29 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 4bb04ec78..8faa88d95 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,28 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +## [1.4.1] - 2026-09-24 + +**A fresh install works again.** The `openai` SDK released its 3.x line on +2026-09-24; an unconstrained install picked it up together with an httpx +pre-release, and every LLM and embedding call failed before reaching the +network. This release pins the SDK to the 2.x line the project is tested +against. Nothing else changed since 1.4.0. + +### Fixed + +- **`openai` is pinned below 3.** Fresh installs from PyPI resolved + `openai 3.19.2`, whose client raises `AttributeError: module 'httpx' has no + attribute 'Timeout'` on every request, so memorize and hybrid / vector + search returned 500. Existing environments built from `uv.lock` were never + affected. + +### Upgrade + +- `pip install --upgrade everos` brings `openai` back to 2.x. If a fresh + install of 1.4.0 (or any earlier version) today shows the `httpx` error + above, upgrade to 1.4.1 or run `pip install "openai<3"`. + ## [1.4.0] - 2026-09-24 **EverOS runs natively on Windows, and dense search stops scanning the whole diff --git a/docs/openapi.json b/docs/openapi.json index 2448de3f7..7d2c69ee4 100644 --- a/docs/openapi.json +++ b/docs/openapi.json @@ -3,7 +3,7 @@ "info": { "title": "everos", "description": "md-first memory extraction framework", - "version": "1.4.0" + "version": "1.4.1" }, "paths": { "/health": { diff --git a/pyproject.toml b/pyproject.toml index 141de1e8a..f7386781e 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "everos" -version = "1.4.0" +version = "1.4.1" description = "EverOS — local-first markdown memory framework for AI agents and user chats; lightweight, dev-friendly, small-team" license = {text = "Apache-2.0"} readme = "README.md" @@ -45,7 +45,9 @@ dependencies = [ "greenlet>=3.0", # Required by SQLAlchemy async # LLM & embedding (one provider per file pattern) - "openai>=1.0.0", + # <3: openai 3.x (2026-09-24) moved to the httpx 1.0 pre-release line and its + # client raises AttributeError on every request; 2.x is what the lock tests. + "openai>=1.0.0,<3", # Markdown / file system "PyYAML>=6.0", # YAML frontmatter parsing diff --git a/uv.lock b/uv.lock index 4bf39c3ba..f10590394 100644 --- a/uv.lock +++ b/uv.lock @@ -579,7 +579,7 @@ wheels = [ [[package]] name = "everos" -version = "1.4.0" +version = "1.4.1" source = { editable = "." } dependencies = [ { name = "aiosqlite" }, @@ -664,7 +664,7 @@ requires-dist = [ { name = "jieba", specifier = ">=0.42.1,<1.0" }, { name = "lancedb", specifier = ">=0.34.0,<0.35.0" }, { name = "msvc-runtime", marker = "sys_platform == 'win32'", specifier = ">=14.44" }, - { name = "openai", specifier = ">=1.0.0" }, + { name = "openai", specifier = ">=1.0.0,<3" }, { name = "opentelemetry-exporter-otlp-proto-http", marker = "extra == 'otel'", specifier = ">=1.27.0" }, { name = "opentelemetry-sdk", marker = "extra == 'otel'", specifier = ">=1.27.0" }, { name = "portalocker", specifier = ">=2.8.2" },