Skip to content

chore(deps): bump actions/checkout from 4 to 6 - #61

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-6
Open

chore(deps): bump actions/checkout from 4 to 6#61
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/checkout-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 7, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/checkout from 4 to 6.

Release notes

Sourced from actions/checkout's releases.

v6.0.0

What's Changed

Full Changelog: actions/checkout@v5.0.0...v6.0.0

v6-beta

What's Changed

Updated persist-credentials to store the credentials under $RUNNER_TEMP instead of directly in the local git config.

This requires a minimum Actions Runner version of v2.329.0 to access the persisted credentials for Docker container action scenarios.

v5.0.1

What's Changed

Full Changelog: actions/checkout@v5...v5.0.1

v5.0.0

What's Changed

⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

Full Changelog: actions/checkout@v4...v5.0.0

v4.3.1

What's Changed

Full Changelog: actions/checkout@v4...v4.3.1

v4.3.0

What's Changed

... (truncated)

Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label May 7, 2026
@dependabot
dependabot Bot requested a review from lukeocodes as a code owner May 7, 2026 05:18
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label May 7, 2026
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/checkout-6 branch from 36c7ed1 to 0725b92 Compare May 9, 2026 09:03
GregHolmes added a commit that referenced this pull request Aug 18, 2026
…twine >=7 (#95)

Audit of outdated dependencies turned up a **live user-facing bug**, so
this PR leads with the fix.

## 1. `dg mcp` is broken for every new install 🔴

`deepgram-mcp 0.1.1` declares an unbounded `mcp>=1.0.0`. mcp **2.0**
removed `streamablehttp_client` from `mcp.client.streamable_http`, which
`deepgram-mcp` still imports — so a fresh `pip install deepctl` resolves
mcp 2.0.0 and:

```
$ dg mcp
Error running MCP proxy: cannot import name 'streamablehttp_client' from 'mcp.client.streamable_http'
```

Reproduced in a clean venv against the **released 0.2.27 wheel** — this
is not caused by this branch.

**Why tests didn't catch it:** all 1052 unit tests pass, because they
mock `run_proxy`. Only a live invocation fails. (Those `coroutine
'run_proxy' was never awaited` warnings in the suite are that mock.)

**Fix:** cap `mcp>=1.0.0,<2.0.0` in `deepctl-cmd-mcp` until
`deepgram-mcp` supports 2.x. Verified `dg mcp` returns a valid
`initialize` response on mcp 1.29.0.

## 2. Nothing was pinned across environments

`uv.lock` had been gitignored since the initial commit, and CI ran `uv
sync --group testing` with no lock — so local, CI, the publish-action
image and end users each resolved independently. That is the same class
of problem behind both this mcp break and the 0.2.27 publish failure.

- Commit `uv.lock`
- CI now uses `uv sync --group testing --locked`, so drift shows up as a
reviewable diff instead of a surprise

Note this fixes **dev/CI reproducibility only** — it does not constrain
end users. Upper bounds in `pyproject.toml` (item 1) are the only thing
that protects them.

## 3. `twine>=7.0.0` for dev

twine <7 rejects `Metadata-Version: 2.5` (emitted by hatchling) — the
exact cause of the failed 0.2.27 publish. The venv had twine 6.2.0, so
`make verify-packages` **would** have caught it locally, while CI's
fresh `pip install twine` always got 7.x and always passed. Raising the
floor keeps local verification equal to what actually publishes.

## Verification

- `ruff format` / `ruff check` / `mypy` clean (on ruff **0.16.3**, up
from 0.15.21)
- **1052 passed**, 6 skipped
- `dg mcp` initialize verified live on mcp 1.29.0
- Full **68-check live API smoke suite** passes (STT
files/URLs/live-stream/mic, TTS Aura + Flux incl.
`--speed`/`--expressivity`, read, account, api, mcp)
- Lockfile also moves websockets 16.1 → **17.0.1**; verified Flux TTS
streaming and live STT both work on it

## Deliberately not included

- `astro 6 → 7` in `web/` (clears **20 npm security alerts**, 11 high) —
separate PR, needs a site check
- The 6 stale Dependabot PRs (#61, #64, #81–84)
- No `npm` ecosystem and only `pip` at `/` in `dependabot.yml`, so
`web/` and the 31 `packages/*` are never scanned — worth a follow-up
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants