Skip to content

updating depset - #61919

Merged
aslonnie merged 1 commit into
releases/2.54.1from
update-llm-batch-depset
Mar 20, 2026
Merged

aslonnie merged 1 commit into
releases/2.54.1from
update-llm-batch-depset

Conversation

@elliot-barn

@elliot-barn elliot-barn commented Mar 20, 2026 •

Copy link
Copy Markdown
Collaborator

updating llm batch test depset to resolve dependency compilation error: https://buildkite.com/ray-project/premerge/builds/62664#019d0c41-fbcc-4c68-bcbc-387ded78ee56

Signed-off-by: elliot-barn <elliot.barnwell@anyscale.com>
@elliot-barn
elliot-barn requested a review from a team as a code owner March 20, 2026 18:51
@elliot-barn
elliot-barn requested a review from aslonnie March 20, 2026 18:52

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

--hash=sha256:f9e130248f4462aaa8e2552d547f36ddadbeaa573879158d721bbd33dfe4743a \
--hash=sha256:fed51ac40f757d41b7c48425901843666a6677e3e8eb0abcff09e4ba6e664f50
markupsafe==3.0.2 ; sys_platform != 'win32' \
--hash=sha256:a123e330ef0853c6e822384873bef7507557d8e4a082961e1defa947aa59ba84

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Downgraded markupsafe with almost all platform hashes removed

High Severity

markupsafe was downgraded from 3.0.3 to 3.0.2, and the ~90 platform-specific wheel hashes were replaced with a single hash. Since MarkupSafe includes C extensions and produces different wheels per platform/architecture, pip with hash-checking mode (as used by lock files) will fail to install on any platform whose wheel doesn't match this lone hash. This will break installations for nearly all environments.

Fix in Cursor Fix in Web

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates a dependency, downgrading markupsafe from version 3.0.3 to 3.0.2. My review has identified a critical issue with this downgrade, as version 3.0.2 is a known broken release. Please see the specific comment for details.

Comment on lines +982 to +983
markupsafe==3.0.2 ; sys_platform != 'win32' \
--hash=sha256:a123e330ef0853c6e822384873bef7507557d8e4a082961e1defa947aa59ba84

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

critical

This change downgrades markupsafe from version 3.0.3 to 3.0.2. However, markupsafe==3.0.2 is a broken release and should not be used. The markupsafe changelog states for version 3.0.2: "This release was not packaged correctly and should not be used. Use 3.0.3 instead."

It is critical to revert this change and continue using markupsafe==3.0.3 to avoid potential build or runtime issues.

@elliot-barn elliot-barn added the go add ONLY when ready to merge, run all tests label Mar 20, 2026
@ray-gardener ray-gardener Bot added serve Ray Serve Related Issue devprod labels Mar 20, 2026
@aslonnie
aslonnie merged commit 8768a32 into releases/2.54.1 Mar 20, 2026
4 of 6 checks passed
@aslonnie
aslonnie deleted the update-llm-batch-depset branch March 20, 2026 19:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

devprod go add ONLY when ready to merge, run all tests serve Ray Serve Related Issue

2 participants