Skip to content

chore(deps): aggregate core dependabot updates - #1069

Merged
burtenshaw merged 3 commits into
mainfrom
codex/dependabot-core-2026-08-06
Aug 7, 2026
Merged

chore(deps): aggregate core dependabot updates#1069
burtenshaw merged 3 commits into
mainfrom
codex/dependabot-core-2026-08-06

Conversation

@burtenshaw

Copy link
Copy Markdown
Collaborator

dependabot Bot added 3 commits August 6, 2026 11:23
…_documentation.yml

Bumps [huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml](https://github.com/huggingface/doc-builder) from 6108e850ae1cf2f71bb0815a600bcd50c39abfa7 to 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c.
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Commits](huggingface/doc-builder@6108e85...7ccf6c0)

---
updated-dependencies:
- dependency-name: huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml
  dependency-version: 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
(cherry picked from commit a13cbb1)
…n_documentation.yml

Bumps [huggingface/doc-builder/.github/workflows/build_main_documentation.yml](https://github.com/huggingface/doc-builder) from 6108e850ae1cf2f71bb0815a600bcd50c39abfa7 to 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c.
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Commits](huggingface/doc-builder@6108e85...7ccf6c0)

---
updated-dependencies:
- dependency-name: huggingface/doc-builder/.github/workflows/build_main_documentation.yml
  dependency-version: 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
(cherry picked from commit 79f7680)
…documentation.yml

Bumps [huggingface/doc-builder/.github/workflows/build_pr_documentation.yml](https://github.com/huggingface/doc-builder) from 6108e850ae1cf2f71bb0815a600bcd50c39abfa7 to 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c.
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Commits](huggingface/doc-builder@6108e85...7ccf6c0)

---
updated-dependencies:
- dependency-name: huggingface/doc-builder/.github/workflows/build_pr_documentation.yml
  dependency-version: 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
(cherry picked from commit c868fce)
@bot-ci-comment

bot-ci-comment Bot commented Aug 6, 2026

Copy link
Copy Markdown

The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alignment Review Report

Scope: Dependabot CI maintenance bump. This PR bumps the pinned huggingface/doc-builder reusable-workflow SHA from 6108e8507ccf6c02 across 3 GitHub Actions workflow files (3 insertions, 3 deletions). No Python, library/runtime, or environment code is touched.

Automated Checks

  • Lint: PASS (for this diff). The repo lint pipeline (usort/ruff over src/, tests/, envs/) does not cover the changed files — all three are .github/workflows/*.yml. ruff check src/ tests/ passes cleanly. The only usort findings are the two files already documented as pre-existing baseline in AGENTS.md (tests/envs/test_grid_world.py, tests/envs/test_julia_env.py); ruff format diffs are an artifact of running an unpinned ruff version (the repo pins ruff>=0.14.0). None are attributable to this PR.
  • Debug code: CLEAN (for this diff). check-debug.sh surfaced only pre-existing print/TODO occurrences under src/; none are in the three changed workflow files.

Open RFCs Context

Active RFCs — 000, 001, 002, 003, 005 (In Review), 004 (rubrics), and 010 (Draft) — all concern environment architecture (abstractions, env spec, MCP, rubrics/rewards, agentic harnesses, token world model). None touch CI/CD, GitHub Actions, or the documentation build pipeline, so there is no overlap with this change.

Supply-chain Verification

  • New SHA 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c is a legitimate commit on huggingface/doc-builder@main (author XciD, 2026-07-31, _"fix(ci): read versions.yml from the serving bucket (#811)"; behind_by: 0 relative to main). The # main annotation is accurate.
  • Previous SHA 6108e850 (2026-07-13) → new SHA (2026-07-31) is a normal forward bump.
  • All three doc-builder references are updated consistently; no stale 6108e850 references remain anywhere in the repo.

Tier 1: Fixes Required

None.

Tier 2: Alignment Discussion

Principle Conflicts

None identified — the change is confined to CI documentation-build workflows and does not affect any API surface, reward computation, client/server boundary, or agent-isolation concern in PRINCIPLES.md / INVARIANTS.md.

RFC Conflicts

None identified — no open RFC covers CI or the doc-build pipeline.

Summary

  • 0 mechanical issues to fix
  • 0 alignment points for human review
  • 0 RFC conflicts to discuss

Low-risk, mergeable Dependabot maintenance bump; the pinned SHA is verified against upstream doc-builder@main.

Open in Web View Automation 

Sent by Cursor Automation: Pre-review

@burtenshaw
burtenshaw merged commit bbc74a9 into main Aug 7, 2026
10 checks passed
@burtenshaw
burtenshaw deleted the codex/dependabot-core-2026-08-06 branch August 7, 2026 09:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

codex codex-automation enhancement New feature or request size: small Small pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant