Python: Bump starlette from 0.47.1 to 1.3.1 in /python/samples/demos/mcp_with_oauth#14094
Conversation
Bumps [starlette](https://github.com/Kludex/starlette) from 0.47.1 to 1.3.1. - [Release notes](https://github.com/Kludex/starlette/releases) - [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md) - [Commits](Kludex/starlette@0.47.1...1.3.1) --- updated-dependencies: - dependency-name: starlette dependency-version: 1.3.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Automated Code Review
Reviewers: 5 | Confidence: 77%
✓ Correctness
This is a straightforward lock file update bumping starlette from 0.47.1 to 1.3.1. The starlette dependency is transitive (pulled in by sse-starlette/mcp). The APIs used in this demo (Starlette, Route, Request, Response subclasses, HTTPException) are all stable core APIs that remain unchanged across the 0.x→1.x transition. The lock file format is correct with valid hashes and URLs. No correctness issues found.
✓ Security Reliability
This is a straightforward lock file update bumping starlette from 0.47.1 to 1.3.1, which includes security fixes for FormParser limit enforcement (DoS mitigation). The lock file change itself is correct with proper integrity hashes and a trusted PyPI source. However, the
server/uv.lock(where starlette is directly used for HTTP request handling) was not updated and still pins starlette 0.47.1, meaning the security fixes don't reach the component that would benefit most from them.
✓ Test Coverage
This PR bumps starlette from 0.47.1 to 1.3.1 in a lock file for a demo/sample project (mcp_with_oauth). Starlette is a transitive dependency (not directly listed in pyproject.toml) and the demo has no tests. Since this is purely a lock file update for a sample project with no behavioral code changes in this repository, there are no test coverage concerns to flag.
✓ Failure Modes
This is a straightforward lock file update bumping starlette from 0.47.1 to 1.3.1 in a demo sample. The starlette APIs used in this project (Starlette, HTTPException, Request, Response, JSONResponse, HTMLResponse, RedirectResponse, Route) are all stable core APIs that remain available and unchanged in starlette 1.x. The lock file is auto-generated by uv and the hashes/URLs are consistent. No silent failure modes, swallowed exceptions, or operational issues are introduced by this change.
✗ Design Approach
This bump appears to target the wrong environment. The demo instructions run the authorization and resource servers from
python/samples/demos/mcp_with_oauth/server(README.md:16-20,README.md:34-40), and those server entry points are the code that actually imports Starlette (server/mcp_simple_auth/auth_server.py:22-26,server/mcp_simple_auth/legacy_as_server.py:22-24). But the checked-in lockfile for that server environment still pinsstarletteto0.47.1(server/uv.lock:621-626), so updating only the top-level sample lockfile does not change the dependency used by the server code path this PR is trying to affect.
Flagged Issues
- The PR updates
python/samples/demos/mcp_with_oauth/uv.lock, but the Starlette-using server is installed and run frompython/samples/demos/mcp_with_oauth/serverperREADME.md:16-20andREADME.md:34-40, and that separate environment still pinsstarletteto0.47.1inserver/uv.lock:621-626.
Automated review by dependabot[bot]'s agents
|
Flagged issue The PR updates Source: automated DevFlow PR review |
### Motivation and Context Semantic Kernel currently has 43 open Dependabot pull requests spanning GitHub Actions, .NET, Python, npm, and Yarn dependency graphs. This rollup applies their compatible net changes together on the latest `main`, making it possible to validate and merge the updates as one coherent dependency state. Supersedes: - microsoft#13133 - microsoft#13134 - microsoft#13136 - microsoft#13172 - microsoft#13507 - microsoft#13601 - microsoft#13606 - microsoft#13666 - microsoft#13673 - microsoft#13688 - microsoft#13700 - microsoft#13707 - microsoft#13708 - microsoft#13712 - microsoft#13721 - microsoft#13873 - microsoft#13930 - microsoft#13939 - microsoft#13949 - microsoft#13950 - microsoft#13951 - microsoft#13997 - microsoft#14000 - microsoft#14053 - microsoft#14069 - microsoft#14088 - microsoft#14091 - microsoft#14094 - microsoft#14103 - microsoft#14106 - microsoft#14107 - microsoft#14108 - microsoft#14109 - microsoft#14110 - microsoft#14128 - microsoft#14148 - microsoft#14149 - microsoft#14160 - microsoft#14161 - microsoft#14164 - microsoft#14171 - microsoft#14172 - microsoft#14173 ### Description - Updates the requested GitHub Actions and preserves the PR-file-scoped typos workflow fix. - Consolidates the .NET Aspire, AWS SDK, ReportGenerator, JavaScript, and SQLite security updates. - Regenerates the npm, Yarn, and uv lockfiles from the combined manifests instead of resolving generated-file conflicts by selection. - Rolls overlapping updates forward to one compatible result: pyasn1 0.6.4 supersedes 0.6.3; pyOpenSSL 26.2.0 remains compatible with cryptography 48.0.1; and Vite 8/Rolldown makes the older Rollup-only overrides obsolete. - Retains updates already present on current `main` without reintroducing stale pins, including Aspire Hosting Azure Search 13.3.0 and Prompty.Core 2.0.0-beta.3. The full .NET solution builds in Debug with zero warnings and errors. Focused validation passed 82 .NET tests (3 skipped), 1,096 Python tests, both frontend production builds, and uv lock consistency checks for the main Python project and OAuth sample. ### Contribution Checklist - [x] The code builds clean without any errors or warnings - [ ] The PR follows the [SK Contribution Guidelines](https://github.com/microsoft/semantic-kernel/blob/main/CONTRIBUTING.md) and the [pre-submission formatting script](https://github.com/microsoft/semantic-kernel/blob/main/CONTRIBUTING.md#development-scripts) raises no violations - [ ] All unit tests pass, and I have added new tests where possible - [x] I didn't break anyone 😄 --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
|
Superseded by #14176 |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps starlette from 0.47.1 to 1.3.1.
Release notes
Sourced from starlette's releases.
... (truncated)
Changelog
Sourced from starlette's changelog.
... (truncated)
Commits
8ebffd0Version 1.3.1 (#3330)25b8e17EnforceFormParserlimits in parser callbacks (#3331)dba1c4bEnforcemax_fieldsandmax_part_sizeinFormParser(#3329)45e51dcUseStarletteDeprecationWarninginstead ofDeprecationWarning(#3119)5f8610cVersion 1.3.0 (#3327)167b585Buildrequest.urlfrom structured components (#3326)3730925Useremoveprefixto strip weak ETag indicator inis_not_modified(#3193)e6f7ad1avoid collapsing exception groups from user code (#2830)115228fAnnotate URLPath protocol parameter with Literal (#3285)113f193docs: replace inline ASGI server list with link to canonical implemen… (#3204)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.