Skip to content

chore(deps): Update tiktoken requirement from >=0.12.0 to >=0.13.0 in /apps/backend#303

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/pip/apps/backend/tiktoken-gte-0.13.0
Closed

chore(deps): Update tiktoken requirement from >=0.12.0 to >=0.13.0 in /apps/backend#303
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/pip/apps/backend/tiktoken-gte-0.13.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 31, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on tiktoken to permit the latest version.

Changelog

Sourced from tiktoken's changelog.

[v0.13.0]

  • Update fancy-regex for significantly increased performance
  • Branch byte pair encoding to fix performance on unusual input
  • Fix AttributeError caused by incomplete redaction of experimental code
  • Update version of pyo3
  • Update version of optional dependency blobfile

[v0.12.0]

  • Build wheels for Python 3.14
  • Build musllinux aarch64 wheels
  • Support for free-threaded Python
  • Update version of pyo3 and rustc-hash
  • Avoid use of blobfile for reading local files
  • Recognise gpt-5 model identifier
  • Minor performance improvement for file reading

[v0.11.0]

  • Support for GPT-5
  • Update version of pyo3
  • Use new Rust edition
  • Fix special token handling in encode_to_numpy
  • Better error handling
  • Improvements to private APIs

[v0.10.0]

  • Support for newer models
  • Improvements to private APIs

[v0.9.0]

  • Support for o1 and o3 models
  • Better error messages when loading invalid vocabulary files
  • Support for encoding to numpy arrays
  • Delayed imports when not strictly necessary

[v0.8.0]

  • Support for o1- and chatgpt-4o- models
  • Build wheels for Python 3.13
  • Add possessive quantifiers to limit backtracking in regular expressions, thanks to @​l0rinc!
  • Provide a better error message and type for invalid token decode
  • Permit tuples in type hints
  • Better error message for passing invalid input to get_encoding
  • Better error messages during plugin loading
  • Add a __version__ attribute
  • Update versions of pyo3, regex, fancy-regex
  • Drop support for Python 3.8

[v0.7.0]

  • Support for gpt-4o

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [tiktoken](https://github.com/openai/tiktoken) to permit the latest version.
- [Release notes](https://github.com/openai/tiktoken/releases)
- [Changelog](https://github.com/openai/tiktoken/blob/main/CHANGELOG.md)
- [Commits](openai/tiktoken@0.12.0...0.13.0)

---
updated-dependencies:
- dependency-name: tiktoken
  dependency-version: 0.13.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label May 31, 2026
@dependabot @github

dependabot Bot commented on behalf of github May 31, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: python. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown
Contributor

🎉 Thanks for your first PR!

A maintainer will review it soon. Please make sure:

  • Your branch is synced with develop
  • CI checks pass
  • You've followed our contribution guide

Welcome to the Auto Code community!

@OBenner

OBenner commented Jun 24, 2026

Copy link
Copy Markdown
Owner

Superseded by #349, which combines all open dependency updates into a single PR. Closing in favor of that.

@OBenner OBenner closed this Jun 24, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jun 24, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/pip/apps/backend/tiktoken-gte-0.13.0 branch June 24, 2026 09:21
@sonarqubecloud

Copy link
Copy Markdown

OBenner added a commit that referenced this pull request Jun 24, 2026
Consolidates the open chore(deps) Dependabot PRs. npm manifests were edited to
their target versions and the root lockfile regenerated from develop's baseline
so its hoisting layout is preserved (the frontend CI relies on it).

Python — apps/backend/requirements.txt (floors already installed in the venv;
QA suites green):
- claude-agent-sdk >=0.1.19 -> >=0.2.87 (#301)
- real_ladybug     >=0.13.0 -> >=0.15.3 (#302)
- pandas           >=3.0.2  -> >=3.0.3  (#299)
- psutil           >=5.9.0  -> >=7.2.2  (#298)
- tiktoken         >=0.12.0 -> >=0.13.0 (#303)

npm — apps/frontend/package.json + package-lock.json:
- electron          ^41.3.0 -> ^42.4.0  (#344)
- @anthropic-ai/sdk ^0.95.1 -> ^0.104.1 (#345)
- @biomejs/biome    2.4.15  -> 2.5.0    (#346)
- vite              ^8.0.11 -> ^8.0.16  (#347)
- react-router-dom  ^7.13.0 -> ^7.17.0  (#327, apps/web-frontend)
- hono (transitive) 4.12.18 -> 4.12.27  (#328, via overrides)

.design-system (taken verbatim from the Dependabot branch):
- @vitejs/plugin-react ^5.1.2 -> ^5.2.0, vite ^7.3.3 -> ^8.0.16, esbuild (#343)

Held back — the vitest bump (#310, 4.0.x -> 4.1.0) and apps/web-frontend's
vite 7 -> 8 bump. Combined, they make npm nest vitest under apps/frontend
instead of hoisting it to the root node_modules (electron-vite pins root vite
to <=7, and vitest 4.1 needs vite 8). The frontend CI (setup-node-frontend)
deletes apps/frontend/node_modules and symlinks it to root, so a nested vitest
vanishes and `tsc --noEmit` fails with "Cannot find module 'vitest'". Kept at
develop's versions so vitest stays hoisted at root; Dependabot will re-propose
these once electron-vite supports vite 8.

Verified locally: npm ci --ignore-scripts + the CI symlink step + tsc --noEmit
pass, and the frontend vitest suite is green (3868 passed).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Oleg Miagkov <mrobenner@gmail.com>
OBenner added a commit that referenced this pull request Jun 24, 2026
* chore(deps): combine Dependabot dependency updates into one PR

Consolidates the open chore(deps) Dependabot PRs. npm manifests were edited to
their target versions and the root lockfile regenerated from develop's baseline
so its hoisting layout is preserved (the frontend CI relies on it).

Python — apps/backend/requirements.txt (floors already installed in the venv;
QA suites green):
- claude-agent-sdk >=0.1.19 -> >=0.2.87 (#301)
- real_ladybug     >=0.13.0 -> >=0.15.3 (#302)
- pandas           >=3.0.2  -> >=3.0.3  (#299)
- psutil           >=5.9.0  -> >=7.2.2  (#298)
- tiktoken         >=0.12.0 -> >=0.13.0 (#303)

npm — apps/frontend/package.json + package-lock.json:
- electron          ^41.3.0 -> ^42.4.0  (#344)
- @anthropic-ai/sdk ^0.95.1 -> ^0.104.1 (#345)
- @biomejs/biome    2.4.15  -> 2.5.0    (#346)
- vite              ^8.0.11 -> ^8.0.16  (#347)
- react-router-dom  ^7.13.0 -> ^7.17.0  (#327, apps/web-frontend)
- hono (transitive) 4.12.18 -> 4.12.27  (#328, via overrides)

.design-system (taken verbatim from the Dependabot branch):
- @vitejs/plugin-react ^5.1.2 -> ^5.2.0, vite ^7.3.3 -> ^8.0.16, esbuild (#343)

Held back — the vitest bump (#310, 4.0.x -> 4.1.0) and apps/web-frontend's
vite 7 -> 8 bump. Combined, they make npm nest vitest under apps/frontend
instead of hoisting it to the root node_modules (electron-vite pins root vite
to <=7, and vitest 4.1 needs vite 8). The frontend CI (setup-node-frontend)
deletes apps/frontend/node_modules and symlinks it to root, so a nested vitest
vanishes and `tsc --noEmit` fails with "Cannot find module 'vitest'". Kept at
develop's versions so vitest stays hoisted at root; Dependabot will re-propose
these once electron-vite supports vite 8.

Verified locally: npm ci --ignore-scripts + the CI symlink step + tsc --noEmit
pass, and the frontend vitest suite is green (3868 passed).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Oleg Miagkov <mrobenner@gmail.com>

* ci(deps): bump GitHub Actions versions

- azure/trusted-signing-action    v1.2.0 -> v2.0.0  (#297; release.yml + beta-release.yml)
- peter-evans/create-pull-request v6.1.0 -> v8.1.1 (#300; nightly-provider-autonomy.yml)
- codecov/codecov-action          v6 -> v7         (#312; ci.yml)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Oleg Miagkov <mrobenner@gmail.com>

---------

Signed-off-by: Oleg Miagkov <mrobenner@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/backend chore dependencies Pull requests that update a dependency file size/XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant