chore(deps)(deps): bump the evaluator-deps group in /scripts/aidlc-evaluator with 4 updates#257
Merged
mayakost merged 2 commits intoMay 11, 2026
Conversation
Bumps the evaluator-deps group in /scripts/aidlc-evaluator with 4 updates: [boto3](https://github.com/boto/boto3), [semgrep](https://github.com/semgrep/semgrep), [strands-agents](https://github.com/strands-agents/sdk-python) and [strands-agents-tools](https://github.com/strands-agents/tools). Updates `boto3` from 1.43.2 to 1.43.6 - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.43.2...1.43.6) Updates `semgrep` from 1.161.0 to 1.162.0 - [Release notes](https://github.com/semgrep/semgrep/releases) - [Changelog](https://github.com/semgrep/semgrep/blob/develop/CHANGELOG.md) - [Commits](semgrep/semgrep@v1.161.0...v1.162.0) Updates `strands-agents` from 1.26.0 to 1.39.0 - [Release notes](https://github.com/strands-agents/sdk-python/releases) - [Commits](strands-agents/sdk-python@v1.26.0...v1.39.0) Updates `strands-agents-tools` from 0.2.23 to 0.5.2 - [Release notes](https://github.com/strands-agents/tools/releases) - [Commits](strands-agents/tools@v0.2.23...v0.5.2) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: evaluator-deps - dependency-name: semgrep dependency-version: 1.162.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: evaluator-deps - dependency-name: strands-agents dependency-version: 1.39.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: evaluator-deps - dependency-name: strands-agents-tools dependency-version: 0.5.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: evaluator-deps ... Signed-off-by: dependabot[bot] <support@github.com>
…tor-deps-86d83405d2
mayakost
approved these changes
May 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the evaluator-deps group in /scripts/aidlc-evaluator with 4 updates: boto3, semgrep, strands-agents and strands-agents-tools.
Updates
boto3from 1.43.2 to 1.43.6Commits
f2ccf9fMerge branch 'release-1.43.6'ffb5712Bumping version to 1.43.6cc7756aAdd changelog entries from botocore500f6a7Merge branch 'release-1.43.5'05f5628Merge branch 'release-1.43.5' into develop65d9798Bumping version to 1.43.5357614aAdd changelog entries from botocore5128f23Bump https://github.com/astral-sh/ruff-pre-commit (#4785)96f1897Merge branch 'release-1.43.4'91de1d8Merge branch 'release-1.43.4' into developUpdates
semgrepfrom 1.161.0 to 1.162.0Release notes
Sourced from semgrep's releases.
Changelog
Sourced from semgrep's changelog.
Commits
f353aa4chore: release version 1.162.046aa0f4semgrep/semgrep-proprietary#6254db71a66logging: do not log debug lines to disk without --debug (semgrep/semgrep-prop...f6a11d7Revert "feat(logging): always log with debug level to a file" unit test (semg...a77b88dRevert "logging: do not log debug lines to disk without --debug" (semgrep/sem...b78e3b3semgrep/semgrep-proprietary#62188506fd7fix(mcp): allow semgrep_findings to query other branches and unrated findings...ffd9b97fix: throw an MCP error when metrics are off and auto config is used (semgrep...33f6e6dsemgrep/semgrep-proprietary#624189d279esemgrep/semgrep-proprietary#6217Updates
strands-agentsfrom 1.26.0 to 1.39.0Release notes
Sourced from strands-agents's releases.
... (truncated)
Commits
ead3179fix: integration test updates (#2262)fc386a3feat(a2a): implement full A2A task lifecycle state support (#2245)980bc91fix: correct MCPClient.exit and stop() type annotations (#2248)800e7c4feat: add useNativeTokenCount flag to skip token counting API calls (#2255)6b0df9afix: cache unsupported models for bedrocks token counting (#2250)d94d516fix: fix count tokens for bedrock models (#2254)559b2a0feat: add context window limit lookup table (#2249)8638fc2fix: include root cause in MCPClientInitializationError message (#2238)a245e6dfeat: enable openai provider use aws profile (#2230)6e208a8feat(bedrock): add strict_tools config with auto-inject of additional… (#2213)Updates
strands-agents-toolsfrom 0.2.23 to 0.5.2Release notes
Sourced from strands-agents-tools's releases.
... (truncated)
Commits
d5376f0fix(shell): close PTY file descriptor to prevent resource leak (#369)4ab97effeat(exa): add highlights, max_age_hours, instant search type, and new catego...4de42a0fix(rss): prevent path traversal via unvalidated feed_id in get_feed_file_pat...34146fedocs: update repository guidelines for new tools policy (#445)e172b1bfix: add namespace validation and fix TOCTOU in elasticsearch memory … (#447)53851d8feat(exa): remove deprecated neural/keyword search types, add deep (#411)cbb9010fix: use console util to allow output suppression (#436)a2b9553fix: mem0_memory - Replace direct Console initialization with console_util (#...b0c8f30docs: add use_agent, graph, and elasticsearch_memory to README (#431)0af4fd7fix: add info-level logging when auth token is resolved from environment vari...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions