build(deps): bump headroom-ai from 0.37.0 to 0.39.1 in /python - #122
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [headroom-ai](https://github.com/headroomlabs-ai/headroom) from 0.37.0 to 0.39.1. - [Release notes](https://github.com/headroomlabs-ai/headroom/releases) - [Changelog](https://github.com/headroomlabs-ai/headroom/blob/main/CHANGELOG.md) - [Commits](headroomlabs-ai/headroom@v0.37.0...v0.39.1) --- updated-dependencies: - dependency-name: headroom-ai dependency-version: 0.39.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
One Should-fix: this bump only touches the anchor file (python/requirements-headroom.txt), not action.yml's headroom_version default, which both the anchor file's own header comment and docs/headroom.md say must be hand-updated in the same PR. As it stands, merging this leaves the runtime-installed Headroom version at 0.37.0 while the tracked anchor says 0.39.1 — a drift the documented process exists specifically to prevent, and nothing else in the pipeline catches it since this bump isn't routed through the upstream-only "Investigate and adapt" automation.
Nothing else in this small diff is wrong — the version bump itself is a straightforward patch/minor dependency update with no other content to review.
Title and description are Dependabot's own and already specific and complete; left untouched. No prior reviews exist on this PR, so there's nothing to clean up.
If you'd like me to fix this, comment:
@claude bump action.yml's headroom_version default (line 378) from "0.37.0" to "0.39.1" to match the version this PR bumps python/requirements-headroom.txt to
| # the two in sync by hand (see README.md's "Context compression (Headroom)" section): when this file's | ||
| # version bumps, update action.yml's default to match in the same PR. | ||
| headroom-ai[proxy]==0.37.0 | ||
| headroom-ai[proxy]==0.39.1 |
There was a problem hiding this comment.
Should fix 🟠 [policy] — this bumps the anchor file's pin, but action.yml's headroom_version default (action.yml:378) is still "0.37.0". The comment three lines above this one, and docs/headroom.md's "Version pinning" section, both say explicitly that when this file's pin bumps, action.yml's matching default needs a hand-update in the same PR because the two are not wired together automatically.
As it stands, merging this PR changes only an anchor file that action.yml never installs from directly — the version actually pip-installed at runtime (action.yml:1469, via HEADROOM_VERSION) stays 0.37.0. The two pins are now out of sync with each other, which is exactly the drift this file's own comment exists to prevent.
This bump isn't routed through the "Investigate and adapt" automation either — that's scoped to anthropics/claude-code-action bumps only (is-upstream in .github/workflows/dependabot.yml), so nothing else catches this mismatch before merge.
|
🗜️ Headroom context compression
|
Bumps headroom-ai from 0.37.0 to 0.39.1.
Release notes
Sourced from headroom-ai's releases.
... (truncated)
Changelog
Sourced from headroom-ai's changelog.
... (truncated)
Commits
d13e196chore: release 0.39.1 (#3807)7968122fix(proxy): stop the 0.39.0 TPM limiter from refusing large-context requests ...66f4261chore: release 0.39.0 (#3713)e64b9f5test(cache): make purge insertion eligible after setup (#3790)12c1579fix(proxy): preserve Claude Code auto-mode protocol (#3784)7ce2580fix(cache/google): tolerate timezone-aware cache expiry timestamps (#3210)5ccec67fix(memory): tolerate None message content in inline memory parser (#3211)9b8cae8fix(security): create credential files private instead of narrowing after wri...19ddfe1fix(mcp): accept an empty install ledger instead of failing mutations as malf...1a6f941fix(memory/graph): apply relation_type filter to both sides of a BOTH subgrap...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)