deps: bump pyo3 0.25 -> 0.29 across the binding crates (mu-mf6x) - #432
Open
sahuagin wants to merge 1 commit into
Open
deps: bump pyo3 0.25 -> 0.29 across the binding crates (mu-mf6x)#432sahuagin wants to merge 1 commit into
sahuagin wants to merge 1 commit into
Conversation
Clears all 8 open dependabot alerts (4 high: OOB read in nth/nth_back for PyList/PyTuple iterators; 4 medium: missing Sync bound on PyCFunction::new_closure closures) — one root cause, pyo3 < 0.29, in mu-bridge, mu-events-py, and mu-anthropic-py. One API adjustment: pyo3 0.29 makes the Clone-derived FromPyObject opt-in; PyMuEvent is output-only so it takes skip_from_py_object (the extraction impl was never used). Bead: mu-mf6x
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clears all 8 open dependabot alerts — one root cause, pyo3 < 0.29, in the three binding crates (mu-bridge, mu-events-py, mu-anthropic-py). 4x high: out-of-bounds read in nth/nth_back for PyList/PyTuple iterators (reachable wherever Python iterates lists/tuples from these modules — the analytics tooling does); 4x medium: missing Sync bound on PyCFunction::new_closure closures.
One API adjustment: pyo3 0.29 makes the Clone-derived FromPyObject opt-in; PyMuEvent is output-only (returned to Python, never extracted from arguments), so it takes skip_from_py_object — the extraction impl was never used.
Verification: scripts/pre-pr-check.sh green (full workspace); ci-aipr panel CONSENSUS APPROVE round 1. Python-side import smoke of the rebuilt extension modules is a post-merge deploy-host step (maturin build not run in this jail).
Bead: mu-mf6x
🤖 Generated with Claude Code
https://claude.ai/code/session_012P4F7VoJPSQCvLy6duFH43