Skip to content

build(deps): bump headroom-ai from 0.37.0 to 0.38.0 in /python - #108

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python/headroom-ai-0.38.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python/headroom-ai-0.38.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Bumps headroom-ai from 0.37.0 to 0.38.0.

Release notes

Sourced from headroom-ai's releases.

Release v0.38.0

0.38.0 (2026-09-21)

Features

  • beacon: schema v2 — routing/compression training signal, gzip transport (#3253) (67eb910)
  • cache: add the headroom-cache-ttl offline TTL estimator the docs reference (#2670) (52c7aa2)
  • dashboard: Cost Saved headline card; label per-row savings as message-only (#3353) (17b0412)
  • dashboard: show routing savings for this session and all time (#3362) (a811984)
  • proxy/model-router: add require_tools route condition (#2362) (ae75ca4)
  • proxy: accept the OpenAI Responses shape on the gateway turn (#3661) (be00a79)
  • proxy: full-savings cost card, cache-aware tool-schema pricing, routing-stats seam (#3351) (b8fa3ad)
  • router: elide dense machine-generated lines no compressor can shrink (#3685) (9263b42)
  • vertex: add Gemini 3.8 Flash agent benchmark suite (#3371) (e67b3c8)

Bug Fixes

  • attach stdin for docker-native MCP stdio (#3447) (a490bba)
  • auth: match the Bearer auth scheme case-insensitively (RFC 7235) (#3219) (75105e2)
  • cache: keep cached-prefix replay after background recompression (#3380) (aebe989)
  • ccr: log the exception type when a CCR continuation call fails (#3137) (9f75f91)
  • changelog-gen: raise on git failure and remove unreachable fallback regex (#1247) (4e1f776)
  • compression: compress cache_control blocks in the request's final message (#3483) (55d7e64)
  • compression: pause AST compression per language after repeated invalid-syntax discards (#3387) (dde83c9)
  • compression: preserve Bash control flow (#3425) (ee90207)
  • compression: protect Bash before the tree-sitter guard, not after (#3435) (ee6f9db)
  • dashboard: make every control keyboard operable and name icon-only controls (#3434) (15debbe)
  • dashboard: report Headroom-attributable cost savings, not the provider cache discount (#3356) (bfe3c78)
  • deps: bump anyio to 4.14.2 for CVE-2026-63374 and CVE-2026-64847 (#3662) (bc21c93)
  • deps: install on Python 3.14 from prebuilt wheels only (#3631) (b8b222f)
  • deps: remediate vulnerable CLI and plugin dependency trees (#3521) (4263da1)
  • deps: upgrade rustls to 0.23.45 for RUSTSEC-2026-0285 (#3584) (b256d25)
  • doctor: detect Codex routing via active provider base_url (#2618) (4794d68)
  • e2e: lock CLI dependencies for reproducible wrap builds (#3512) (5abcdbd)
  • fix security issue in server.py (#3593) (97aa949)
  • hold Cursor's read_file byte-exact too (d02e7df)
  • keep dashboard route boundaries out of upstream passthrough (#3324) (213b371)
  • keep file-read tool output byte-exact through the lossless fold (59499f7)
  • kompress: append the CCR marker whenever the saving pays for it (#3484) (7bd4dba)
  • kompress: bound download retry backoff before overflow (#3630) (a7858fd)
  • langchain: implement get_metrics() on HeadroomChatModel (#3446) (#3459) (dba5d2f)
  • langchain: make the integration work on LangChain 1.x, and document it (#3399) (5d025f7)
  • learn: count each tool call once per tool_call_id when detecting loops (#3462) (4088a65)
  • learn: derive loop signature from tool input identity, not display summary (#3461) (f6b9fc0)
  • learn: distinguish Grep and Glob searches by path (#3455) (f302a38)
  • learn: echo live progress during claude-cli analysis (#3158) (4c6bd3e)
  • learn: guard session-derived path checks against PermissionError in gemini/grok plugins (#2522) (60bfe8b)
  • learn: prevent Windows CRLF accumulation in context writers (#3594) (3c1a901)

... (truncated)

Changelog

Sourced from headroom-ai's changelog.

0.38.0 (2026-09-21)

Features

  • beacon: schema v2 — routing/compression training signal, gzip transport (#3253) (67eb910)
  • cache: add the headroom-cache-ttl offline TTL estimator the docs reference (#2670) (52c7aa2)
  • dashboard: Cost Saved headline card; label per-row savings as message-only (#3353) (17b0412)
  • dashboard: show routing savings for this session and all time (#3362) (a811984)
  • proxy/model-router: add require_tools route condition (#2362) (ae75ca4)
  • proxy: accept the OpenAI Responses shape on the gateway turn (#3661) (be00a79)
  • proxy: full-savings cost card, cache-aware tool-schema pricing, routing-stats seam (#3351) (b8fa3ad)
  • router: elide dense machine-generated lines no compressor can shrink (#3685) (9263b42)
  • vertex: add Gemini 3.8 Flash agent benchmark suite (#3371) (e67b3c8)

Bug Fixes

  • attach stdin for docker-native MCP stdio (#3447) (a490bba)
  • auth: match the Bearer auth scheme case-insensitively (RFC 7235) (#3219) (75105e2)
  • cache: keep cached-prefix replay after background recompression (#3380) (aebe989)
  • ccr: log the exception type when a CCR continuation call fails (#3137) (9f75f91)
  • changelog-gen: raise on git failure and remove unreachable fallback regex (#1247) (4e1f776)
  • compression: compress cache_control blocks in the request's final message (#3483) (55d7e64)
  • compression: pause AST compression per language after repeated invalid-syntax discards (#3387) (dde83c9)
  • compression: preserve Bash control flow (#3425) (ee90207)
  • compression: protect Bash before the tree-sitter guard, not after (#3435) (ee6f9db)
  • dashboard: make every control keyboard operable and name icon-only controls (#3434) (15debbe)
  • dashboard: report Headroom-attributable cost savings, not the provider cache discount (#3356) (bfe3c78)
  • deps: bump anyio to 4.14.2 for CVE-2026-63374 and CVE-2026-64847 (#3662) (bc21c93)
  • deps: install on Python 3.14 from prebuilt wheels only (#3631) (b8b222f)
  • deps: remediate vulnerable CLI and plugin dependency trees (#3521) (4263da1)
  • deps: upgrade rustls to 0.23.45 for RUSTSEC-2026-0285 (#3584) (b256d25)
  • doctor: detect Codex routing via active provider base_url (#2618) (4794d68)
  • e2e: lock CLI dependencies for reproducible wrap builds (#3512) (5abcdbd)
  • fix security issue in server.py (#3593) (97aa949)
  • hold Cursor's read_file byte-exact too (d02e7df)
  • keep dashboard route boundaries out of upstream passthrough (#3324) (213b371)
  • keep file-read tool output byte-exact through the lossless fold (59499f7)
  • kompress: append the CCR marker whenever the saving pays for it (#3484) (7bd4dba)
  • kompress: bound download retry backoff before overflow (#3630) (a7858fd)
  • langchain: implement get_metrics() on HeadroomChatModel (#3446) (#3459) (dba5d2f)
  • langchain: make the integration work on LangChain 1.x, and document it (#3399) (5d025f7)
  • learn: count each tool call once per tool_call_id when detecting loops (#3462) (4088a65)
  • learn: derive loop signature from tool input identity, not display summary (#3461) (f6b9fc0)
  • learn: distinguish Grep and Glob searches by path (#3455) (f302a38)
  • learn: echo live progress during claude-cli analysis (#3158) (4c6bd3e)
  • learn: guard session-derived path checks against PermissionError in gemini/grok plugins (#2522) (60bfe8b)
  • learn: prevent Windows CRLF accumulation in context writers (#3594) (3c1a901)
  • learn: prevent Windows CRLF accumulation in context writers (#3594) (abde3e6)

... (truncated)

Commits
  • 94206e2 chore: release 0.38.0
  • 89a58fd fix(pricing): price savings against the cache mix, not flat list price (#3699)
  • 85fac8c fix(stats): stop rejected upstream turns from feeding the savings funnel (#3615)
  • 6f404de fix(proxy): keep OpenCode Zen /responses requests streaming (#3659)
  • ebc0b36 fix(sdk): emit the final SSE event when the stream has no trailing newline (#...
  • 261796f fix(spreadsheet): render an .xls cell the way the .xlsx loader renders it (#3...
  • 545f544 fix: preserve JSON object fields in SmartCrusher (#3648)
  • 334317d fix(tabular): pass a table through when one cell is past the csv field limit ...
  • f734c57 fix(proxy): enforce budget limits on OpenAI and Gemini routes (#3579)
  • 3c1a901 fix(learn): prevent Windows CRLF accumulation in context writers (#3594)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [headroom-ai](https://github.com/headroomlabs-ai/headroom) from 0.37.0 to 0.38.0.
- [Release notes](https://github.com/headroomlabs-ai/headroom/releases)
- [Changelog](https://github.com/headroomlabs-ai/headroom/blob/main/CHANGELOG.md)
- [Commits](headroomlabs-ai/headroom@v0.37.0...v0.38.0)

---
updated-dependencies:
- dependency-name: headroom-ai
  dependency-version: 0.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 29, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is an automated Dependabot bump of headroom-ai (0.37.0 → 0.38.0) in python/requirements-headroom.txt, but it isn't paired with the matching bump to action.yml's headroom_version default — see the inline comment. The requirements file is only a Dependabot anchor, not what the action actually installs, so this omission means the action would keep installing 0.37.0 despite the anchor file claiming 0.38.0.

Should fix

  • python/requirements-headroom.txt:6 — action.yml's headroom_version default (currently "0.37.0" at action.yml:378) needs to be bumped to "0.38.0" in the same PR, per both this file's own header comment and docs/headroom.md's stated sync policy.

Nothing else in the diff — the version bump itself is a straightforward one-line change. No prior reviews exist on this PR to reconcile against. Title and description are Dependabot's standard, complete auto-generated release-notes body, so I left them as-is.

# the two in sync by hand (see README.md's "Context compression (Headroom)" section): when this file's
# version bumps, update action.yml's default to match in the same PR.
headroom-ai[proxy]==0.37.0
headroom-ai[proxy]==0.38.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Should fix [policy] — this bump isn't paired with the matching update to action.yml's headroom_version default, which is still "0.37.0" (action.yml:378).

The comment three lines above this diff (python/requirements-headroom.txt:3-5) says explicitly: "keep the two in sync by hand ... when this file's version bumps, update action.yml's default to match in the same PR." docs/headroom.md states the same policy for both anchor files. Because headroom_version is what the action actually installs — this file is only a Dependabot anchor, per that same doc — merging as-is leaves the action still installing 0.37.0 while the anchor file claims 0.38.0.

This is a plain Dependabot PR with no accompanying action.yml edit, so this looks like the automated sync step for this dependency didn't run (the dependabot.yml workflow's investigate job only covers the anthropics/claude-code-action upstream SHA, not this pip anchor). action.yml:378's default needs bumping to "0.38.0" in this PR, or in a fast-follow before merge.

@github-actions

Copy link
Copy Markdown

🗜️ Headroom context compression

Metric Value
Requests proxied 20
Tokens saved 22629
Aggregate savings 1.4% of all tokens sent
Average per-request compression 2.1%

@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #122.

@dependabot dependabot Bot closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants