Skip to content

build(deps): bump headroom-ai from 0.37.0 to 0.39.1 in /python - #122

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python/headroom-ai-0.39.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python/headroom-ai-0.39.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps headroom-ai from 0.37.0 to 0.39.1.

Release notes

Sourced from headroom-ai's releases.

Release v0.39.1

0.39.1 (2026-09-26)

Bug Fixes

  • proxy: stop the 0.39.0 TPM limiter from refusing large-context requests forever (#3806) (7968122)

Release v0.39.0

0.39.0 (2026-09-25)

Features

  • compression: describe what CCR compression dropped, not just how much (#3635) (62d1cc0)
  • hooks: add protect_messages, a hard per-message compression veto (#3772) (d17ac6a)
  • opencode: exclude hosts from transport plugin routing (#3668) (0024b57)
  • proxy: let /transformations/feed omit message bodies for number-only pollers (#3672) (46ac52d)
  • savings: carry exact cache-read cost in history rollups (#3734) (1cb779e)
  • savings: show the new-input savings basis beside the whole-wire figure (#3485) (e92cccc)
  • savings: track lifetime output spend so a bill-share rate has a denominator (#3520) (c766bdb)
  • sdk: support per-call config override in compress() (#3370) (c3e8a1e)
  • wrap: support 1m context in vscode claude (#3361) (fc5a09e)

Bug Fixes

  • anthropic: reject ping-only SSE from buffered CCR (#3682) (000fefc)
  • anthropic: stop the spurious compaction warning and drop dead handler code (#3678) (6e71267)
  • backends/litellm: stop dropping image blocks from /v1/messages requests (#3753) (577336d)
  • binaries: fail closed when a download carries no sha256 pin (#3724) (26a2c49)
  • cache/google: tolerate timezone-aware cache expiry timestamps (#3210) (7ce2580)
  • cache: default CCR payload previews off; harden the log when they are on (#3728) (5cb87bc)
  • cache: never batch-compress already-forwarded small Responses outputs in cache mode (#3756) (ab62b9e)
  • cache: preserve cache_control schema properties (#3348) (b84c4c9)
  • cache: preserve the forwarded OpenAI chat prefix across turns (#3757) (deca575)
  • cache: stop prefix transforms from busting the provider cache (#3735) (a2bf5ed)
  • cache: stop skipping tool compaction on a pinned tools array (#3750) (a6a9cef)
  • cli: keep non-ASCII working directory names out of the init profile slug (#3718) (f3d95ee)
  • cli: report anonymous beacon status accurately in the banner, log, and /stats (#3533) (fa9edb3)
  • content_detector: detect CMTrace (SCCM/Intune) logs as BUILD_OUTPUT (#3712) (6feb1fb)
  • dashboard: separate rolling cache economics by owner (#3319) (a29162b), closes #960
  • docker: support OpenCode in native wrapper (#3547) (d90dadf)
  • fall back for non-admin Windows task installs (#3437) (b958509)
  • graph: fetch and extract the zip codebase-memory-mcp asset on Windows (#3730) (b776983)
  • grok: preserve xAI model context metadata (#3312) (#3315) (c81378c)
  • init: raise the ensure hook's timeout above cold-start latency (#3438) (9a11109)
  • install: apply managed env vars added after a deployment was installed (#3740) (a4cb2bc)
  • install: wait for the old process to stop before restarting (#3670) (11c7320)
  • kompress: bound the inference deadline to the request, not each block (#3693) (7f2766c)

... (truncated)

Changelog

Sourced from headroom-ai's changelog.

0.39.1 (2026-09-26)

Bug Fixes

  • proxy: stop the 0.39.0 TPM limiter from refusing large-context requests forever (#3806) (7968122)

0.39.0 (2026-09-25)

Features

  • compression: describe what CCR compression dropped, not just how much (#3635) (62d1cc0)
  • hooks: add protect_messages, a hard per-message compression veto (#3772) (d17ac6a)
  • opencode: exclude hosts from transport plugin routing (#3668) (0024b57)
  • proxy: let /transformations/feed omit message bodies for number-only pollers (#3672) (46ac52d)
  • savings: carry exact cache-read cost in history rollups (#3734) (1cb779e)
  • savings: show the new-input savings basis beside the whole-wire figure (#3485) (e92cccc)
  • savings: track lifetime output spend so a bill-share rate has a denominator (#3520) (c766bdb)
  • sdk: support per-call config override in compress() (#3370) (c3e8a1e)
  • wrap: support 1m context in vscode claude (#3361) (fc5a09e)

Bug Fixes

  • anthropic: reject ping-only SSE from buffered CCR (#3682) (000fefc)
  • anthropic: stop the spurious compaction warning and drop dead handler code (#3678) (6e71267)
  • backends/litellm: stop dropping image blocks from /v1/messages requests (#3753) (577336d)
  • binaries: fail closed when a download carries no sha256 pin (#3724) (26a2c49)
  • cache/google: tolerate timezone-aware cache expiry timestamps (#3210) (7ce2580)
  • cache: default CCR payload previews off; harden the log when they are on (#3728) (5cb87bc)
  • cache: never batch-compress already-forwarded small Responses outputs in cache mode (#3756) (ab62b9e)
  • cache: preserve cache_control schema properties (#3348) (b84c4c9)
  • cache: preserve the forwarded OpenAI chat prefix across turns (#3757) (deca575)
  • cache: stop prefix transforms from busting the provider cache (#3735) (a2bf5ed)
  • cache: stop skipping tool compaction on a pinned tools array (#3750) (a6a9cef)
  • cli: keep non-ASCII working directory names out of the init profile slug (#3718) (f3d95ee)
  • cli: report anonymous beacon status accurately in the banner, log, and /stats (#3533) (fa9edb3)
  • content_detector: detect CMTrace (SCCM/Intune) logs as BUILD_OUTPUT (#3712) (6feb1fb)
  • dashboard: separate rolling cache economics by owner (#3319) (a29162b), closes #960
  • docker: support OpenCode in native wrapper (#3547) (d90dadf)
  • fall back for non-admin Windows task installs (#3437) (b958509)
  • graph: fetch and extract the zip codebase-memory-mcp asset on Windows (#3730) (b776983)
  • grok: preserve xAI model context metadata (#3312) (#3315) (c81378c)
  • init: raise the ensure hook's timeout above cold-start latency (#3438) (9a11109)
  • install: apply managed env vars added after a deployment was installed (#3740) (a4cb2bc)
  • install: wait for the old process to stop before restarting (#3670) (11c7320)
  • kompress: bound the inference deadline to the request, not each block (#3693) (7f2766c)
  • kompress: keep the boolean connectives that hold a condition together (#3687) (bf290ba)
  • learn: treat an unreadable project memory dir as absent instead of crashing (#3710) (ff60d57)

... (truncated)

Commits
  • d13e196 chore: release 0.39.1 (#3807)
  • 7968122 fix(proxy): stop the 0.39.0 TPM limiter from refusing large-context requests ...
  • 66f4261 chore: release 0.39.0 (#3713)
  • e64b9f5 test(cache): make purge insertion eligible after setup (#3790)
  • 12c1579 fix(proxy): preserve Claude Code auto-mode protocol (#3784)
  • 7ce2580 fix(cache/google): tolerate timezone-aware cache expiry timestamps (#3210)
  • 5ccec67 fix(memory): tolerate None message content in inline memory parser (#3211)
  • 9b8cae8 fix(security): create credential files private instead of narrowing after wri...
  • 19ddfe1 fix(mcp): accept an empty install ledger instead of failing mutations as malf...
  • 1a6f941 fix(memory/graph): apply relation_type filter to both sides of a BOTH subgrap...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [headroom-ai](https://github.com/headroomlabs-ai/headroom) from 0.37.0 to 0.39.1.
- [Release notes](https://github.com/headroomlabs-ai/headroom/releases)
- [Changelog](https://github.com/headroomlabs-ai/headroom/blob/main/CHANGELOG.md)
- [Commits](headroomlabs-ai/headroom@v0.37.0...v0.39.1)

---
updated-dependencies:
- dependency-name: headroom-ai
  dependency-version: 0.39.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 5, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 5, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One Should-fix: this bump only touches the anchor file (python/requirements-headroom.txt), not action.yml's headroom_version default, which both the anchor file's own header comment and docs/headroom.md say must be hand-updated in the same PR. As it stands, merging this leaves the runtime-installed Headroom version at 0.37.0 while the tracked anchor says 0.39.1 — a drift the documented process exists specifically to prevent, and nothing else in the pipeline catches it since this bump isn't routed through the upstream-only "Investigate and adapt" automation.

Nothing else in this small diff is wrong — the version bump itself is a straightforward patch/minor dependency update with no other content to review.

Title and description are Dependabot's own and already specific and complete; left untouched. No prior reviews exist on this PR, so there's nothing to clean up.

If you'd like me to fix this, comment:

@claude bump action.yml's headroom_version default (line 378) from "0.37.0" to "0.39.1" to match the version this PR bumps python/requirements-headroom.txt to

# the two in sync by hand (see README.md's "Context compression (Headroom)" section): when this file's
# version bumps, update action.yml's default to match in the same PR.
headroom-ai[proxy]==0.37.0
headroom-ai[proxy]==0.39.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should fix 🟠 [policy] — this bumps the anchor file's pin, but action.yml's headroom_version default (action.yml:378) is still "0.37.0". The comment three lines above this one, and docs/headroom.md's "Version pinning" section, both say explicitly that when this file's pin bumps, action.yml's matching default needs a hand-update in the same PR because the two are not wired together automatically.

As it stands, merging this PR changes only an anchor file that action.yml never installs from directly — the version actually pip-installed at runtime (action.yml:1469, via HEADROOM_VERSION) stays 0.37.0. The two pins are now out of sync with each other, which is exactly the drift this file's own comment exists to prevent.

This bump isn't routed through the "Investigate and adapt" automation either — that's scoped to anthropics/claude-code-action bumps only (is-upstream in .github/workflows/dependabot.yml), so nothing else catches this mismatch before merge.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

🗜️ Headroom context compression

Metric Value
Requests proxied 23
Tokens saved 146412
Aggregate savings 7.2% of all tokens sent
Average per-request compression 9.8%

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants