chore(deps): bump langgraph-checkpoint from 4.0.1 to 4.1.1#1730
chore(deps): bump langgraph-checkpoint from 4.0.1 to 4.1.1#1730dependabot[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
LGTM, transitive dependency lockfile bump from Dependabot.
Extended reasoning...
Overview
This PR is a Dependabot lockfile-only change that bumps langgraph-checkpoint from 4.0.1 to 4.1.1 in uv.lock. The package is a transitive dependency (not directly referenced anywhere in the source tree — only appears in uv.lock), pulled in by langgraph. The diff also updates the exclude-newer metadata field to a sentinel value with an explanatory comment, which is a uv-managed lock file artifact.
Security risks
None. This is a lockfile change for a transitive dependency. The new version is a minor+patch bump on the same major (4.x), with release notes showing internal fixes (lc:2 envelope revival restriction, idna/urllib3 bumps inside langgraph). No direct API surface in this repo touches langgraph_checkpoint.
Level of scrutiny
Minimal — this is the canonical 'low-risk Dependabot bump': lockfile-only, transitive dep, minor version on the same major, no source files modified. CI tests act as the safety net.
Other factors
Single-file change to uv.lock. No bug reports from the hunting system. The langfuse-python repo uses langgraph only via integration code, and this checkpoint package is a sub-dep. Safe to auto-approve.
Bumps [langgraph-checkpoint](https://github.com/langchain-ai/langgraph) from 4.0.1 to 4.1.1. - [Release notes](https://github.com/langchain-ai/langgraph/releases) - [Commits](langchain-ai/langgraph@checkpoint==4.0.1...checkpoint==4.1.1) --- updated-dependencies: - dependency-name: langgraph-checkpoint dependency-version: 4.1.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
0c8328b to
ef1b7c0
Compare
Bumps langgraph-checkpoint from 4.0.1 to 4.1.1.
Release notes
Sourced from langgraph-checkpoint's releases.
... (truncated)
Commits
d1e2ff0release(checkpoint): 4.1.1 (#7890)e787af2release(sdk-py): 0.3.15 (#7891)604534efix(sdk-py): percent-encode caller-supplied identifiers in URL paths (#7893)346aa97fix(checkpoint): restrict lc:2 envelope revival to default constructor (#7892)82b3872chore(deps): bump the uv group across 2 directories with 1 update (#7853)fcc4ab8chore(deps): bump idna from 3.11 to 3.15 in /libs/checkpoint (#7860)701d344chore(deps): bump idna from 3.11 to 3.15 in /libs/checkpoint-postgres (#7861)2c7967cchore(deps): bump idna from 3.11 to 3.15 in /libs/cli (#7865)bf7fec0release(langgraph): 1.2.1 (#7883)8215a9dfeat(langgraph): addbefore_builtinsopt-in for stream transformers (#7882)