Pinned all dependencies, removed black, addressed dependabot warnings

This commit is contained in:
Michael Panchenko authored and Dominik Jain committed 2026-03-23 21:10:41 +01:00
1 parent 091b2245e3
commit 45cd8ca12e
3 files changed
+834 -809

No files matched your search

+2 -2
View File
@@ -5,7 +5,7 @@ This file provides guidance to Claude Code (claude.ai/code) when working with co
## Development Commands
**Essential Commands (use these exact commands):**
- `uv run poe format` - Format code (BLACK + RUFF) - ONLY allowed formatting command
- `uv run poe format` - Format code (RUFF) - ONLY allowed formatting command
- `uv run poe type-check` - Run mypy type checking - ONLY allowed type checking command
- `uv run poe test` - Run tests with default markers (excludes java/rust by default)
- `uv run poe test -m "python or go"` - Run specific language tests
@@ -108,7 +108,7 @@ Configuration is loaded from (in order of precedence):
## Working with the Codebase
- Project uses Python 3.11 with `uv` for dependency management
- Strict typing with mypy, formatted with black + ruff
- Strict typing with mypy, formatted with ruff
- Language servers run as separate processes with LSP communication
- Memory system enables persistent project knowledge
- Context/mode system allows workflow customization
+57 -52
View File
@@ -14,28 +14,36 @@ classifiers = [
"Programming Language :: Python :: 3.11",
]
dependencies = [
"requests>=2.32.3,<3",
"pyright>=1.1.396,<2",
"fortls>=3.2.2",
"overrides>=7.7.0,<8",
"python-dotenv>=1.0.0, <2",
"requests==2.32.4",
"pyright==1.1.403",
"fortls==3.2.2",
"overrides==7.7.0",
"python-dotenv==1.1.1",
"mcp==1.23.0",
"flask>=3.0.0",
"sensai-utils>=1.5.0",
"pydantic>=2.10.6",
"types-pyyaml>=6.0.12.20241230",
"pyyaml>=6.0.2",
"flask==3.1.3", # bumped from 3.1.1 for CVE fix (also fixes werkzeug alert)
"sensai-utils==1.5.0",
"pydantic==2.11.7",
"types-pyyaml==6.0.12.20250516",
"pyyaml==6.0.2",
"ruamel.yaml==0.18.14",
"jinja2>=3.1.6",
"dotenv>=0.9.9",
"pathspec>=0.12.1",
"psutil>=7.0.0",
"docstring_parser>=0.16",
"joblib>=1.5.1",
"tqdm>=4.67.1",
"tiktoken>=0.9.0",
"anthropic>=0.54.0",
"beautifulsoup4>=4.14.2",
"jinja2==3.1.6",
"dotenv==0.9.9",
"pathspec==0.12.1",
"psutil==7.0.0",
"docstring_parser==0.17.0",
"joblib==1.5.1",
"tqdm==4.67.1",
"tiktoken==0.9.0",
"anthropic==0.59.0",
"beautifulsoup4==4.14.2",
# Transitive deps pinned for security (dependabot alerts).
# Exact pins because uvx installs from git, ignoring the lock file.
"urllib3==2.6.3",
"werkzeug==3.1.6",
"starlette==1.0.0",
"python-multipart==0.0.22",
"filelock==3.25.2",
"cryptography==46.0.5",
]
[[tool.uv.index]]
@@ -54,29 +62,35 @@ text = "MIT"
[project.optional-dependencies]
dev = [
"black[jupyter]>=23.7.0, <26", # black 26 is incompatible with our pathspec version
"jinja2",
"jinja2==3.1.6",
# In version 1.0.4 we get a NoneType error related to some config conversion (yml_analytics is None and should be a list)
"mypy>=1.16.1",
"poethepoet>=0.20.0",
"pytest>=8.0.2",
"pytest-xdist>=3.5.0",
"mypy==1.17.0",
"poethepoet==0.36.0",
"pytest==8.4.1",
"pytest-xdist==3.8.0",
"ruff==0.12.5",
"toml-sort>=0.24.2",
"types-pyyaml>=6.0.12.20241230",
"syrupy>=4.9.1",
"types-requests>=2.32.4.20241230",
"toml-sort==0.24.2",
"types-pyyaml==6.0.12.20250516",
"syrupy==4.9.1",
"types-requests==2.32.4.20250809",
# docs
"sphinx>=7,<8",
"sphinx_rtd_theme>=0.5.1",
"sphinx==7.4.7",
"sphinx_rtd_theme==2.0.0",
"sphinx-toolbox==3.7.0",
"jupyter-book>=1,<2",
"nbsphinx",
"pyinstrument",
"pytest-timeout>=2.4.0",
"jupyter-book==1.0.4.post1",
"nbsphinx==0.9.7",
"pyinstrument==5.1.1",
"pytest-timeout==2.4.0",
# Transitive dev deps pinned for security (dependabot alerts).
# Exact pins because uvx installs from git, ignoring the lock file.
"tornado==6.5.5",
"nbconvert==7.17.0",
"wheel==0.46.3",
"pyasn1==0.6.3",
"PyJWT==2.12.1",
]
agno = ["agno>=2.2.1", "sqlalchemy>=2.0.40"]
google = ["google-genai>=1.8.0"]
agno = ["agno==2.5.10", "sqlalchemy==2.0.41"] # agno bumped for session state overwrite CVE
google = ["google-genai==1.27.0"]
[project.urls]
Homepage = "https://github.com/oraios/serena"
@@ -84,15 +98,6 @@ Homepage = "https://github.com/oraios/serena"
[tool.hatch.build.targets.wheel]
packages = ["src/serena", "src/interprompt", "src/solidlsp"]
[tool.black]
line-length = 140
target-version = ["py311"]
exclude = '''
/(
src/solidlsp/language_servers/.*/static|src/multilspy
)/
'''
[tool.doc8]
max-line-length = 1000
@@ -135,12 +140,12 @@ type = "simple"
# For custom markers, one can either adjust the env var or just use -m option in the command line,
# as the second -m option will override the first one.
test = "pytest test -vv"
_black_check = "black --check src scripts test"
_ruff_check = "ruff check src scripts test"
_black_format = "black src scripts test"
_ruff_format = "ruff check --fix src scripts test"
lint = ["_black_check", "_ruff_check"]
format = ["_ruff_format", "_black_format"]
_ruff_format_check = "ruff format --check src scripts test"
_ruff_fix = "ruff check --fix src scripts test"
_ruff_format = "ruff format src scripts test"
lint = ["_ruff_format_check", "_ruff_check"]
format = ["_ruff_fix", "_ruff_format"]
_mypy_core = "mypy src/serena src/solidlsp"
_mypy_test = "mypy --disable-error-code no-untyped-def test"
type-check = ["_mypy_core", "_mypy_test"]
Generated
+775 -755
View File
File diff suppressed because it is too large. Load diff