Skip to content

build(deps): update dspy-ai requirement from <4.0.0,>=3.2.1 to >=3.3.1,<4.0.0 - #69

Merged
haasonsaas merged 2 commits into
mainfrom
dependabot/pip/dspy-ai-gte-3.3.1-and-lt-4.0.0
Sep 21, 2026
Merged

haasonsaas merged 2 commits into
mainfrom
dependabot/pip/dspy-ai-gte-3.3.1-and-lt-4.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on dspy-ai to permit the latest version.

Release notes

Sourced from dspy-ai's releases.

3.3.1

DSPy 3.3.1

DSPy 3.3.1 contains many interpreter fixes and improvements. It makes PythonInterpreter easier to install, substantially strengthens sandbox isolation and request handling, and adds end-to-end visibility into interpreter execution. The release also improves optimizer throughput, adapter correctness, and MCP compatibility.

Highlights

PythonInterpreter: Managed Runtime, Hardening, and Lifecycle Visibility

Installation, isolation, and execution integrity

PythonInterpreter now has an optional managed runtime installation:

pip install "dspy[deno]"

DSPy prefers that managed binary when present, while continuing to support system Deno 2.x and an explicit custom deno_command. The default path pins Pyodide, validates Deno >=2.0.0,<3.0.0, and ignores ambient Node and Deno project configuration so nearby application files cannot change sandbox startup.

The interpreter also closes several execution-integrity and isolation gaps:

  • unsolicited sandbox diagnostics can no longer desynchronize JSON-RPC replies;
  • request IDs are unpredictable, and recursive execution through one of an interpreter's own host tools is rejected;
  • bundled runtime files are protected and Deno-cache access is revoked after startup;
  • mounted files with distinct host paths cannot silently collide at the same sandbox basename; and
  • guest code cannot change host-tool identity by mutating JavaScript globals or prototypes.

Observability and agent integration

DSPy's callback API now exposes the complete interpreter lifecycle:

  • interpreter execution start and end;
  • sandbox-to-host tool-call start and end;
  • interpreter process startup and shutdown.

Events retain callback ancestry across modules, interpreters, tools, and LM calls. End callbacks receive terminating BaseException values such as cancellation and interruption instead of incorrectly reporting those operations as successful. Optimizer compile() runs receive the same start/end coverage.

... (truncated)

Commits
  • 638e155 feat(gepa): support objective-aware optimization (#10259)
  • 1fbfadf docs(dspy): fix the optimizers overview link on the BetterTogether page (#10253)
  • 33aaa19 feat(adapter): support nested XML data (#10239)
  • 7500171 Scope standard library guidance to PythonInterpreter (#10255)
  • e0400fd chore(deps): bump mkdocs-material from 9.7.6 to 9.7.7 in /docs (#10110)
  • 69dfed6 chore(deps): bump urllib3 from 2.6.3 to 2.7.0 in /docs (#9931)
  • 10e2973 chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#9945)
  • 4bbabc6 chore(deps): bump actions/setup-python from 6.2.0 to 6.3.0 (#9965)
  • 0d8047f chore(deps): bump actions/cache from 5.0.5 to 6.1.0 (#9966)
  • a94c146 chore(deps): bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 (#9967)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [dspy-ai](https://github.com/stanfordnlp/dsp) to permit the latest version.
- [Release notes](https://github.com/stanfordnlp/dsp/releases)
- [Commits](stanfordnlp/dspy@3.2.1...3.3.1)

---
updated-dependencies:
- dependency-name: dspy-ai
  dependency-version: 3.3.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 7, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgepa@​0.0.27 ⏵ 0.1.492 -5100100100100
Updateddspy@​3.2.1 ⏵ 3.3.194100100100100

View full report

@haasonsaas haasonsaas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Routine dependency bump; Socket Security checks green.

@haasonsaas
haasonsaas merged commit 4bb411c into main Sep 21, 2026
2 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/dspy-ai-gte-3.3.1-and-lt-4.0.0 branch September 21, 2026 02:49
haasonsaas added a commit that referenced this pull request Sep 21, 2026
Rebuilt on current main because the dependabot branch conflicted on all
four requirements files after the dspy-ai bump (#69) landed.

ruff 0.16.5 -> 0.16.7 and twilio 9.11.0 -> 9.11.1, with both lock files
regenerated by the command recorded in their headers:
  uv pip compile requirements.txt --output-file requirements.lock \
    --no-annotate --python-version 3.11 --python-platform x86_64-unknown-linux-gnu
and the requirements-dev equivalent.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant