Python: Update mistralai requirement from <2.7.3,>=1.2 to >=1.2,<2.9.5 in /python - #14391
dependabot[bot] wants to merge 3 commits into
Conversation
Updates the requirements on [mistralai](https://github.com/mistralai/client-python) to permit the latest version. - [Release notes](https://github.com/mistralai/client-python/releases) - [Changelog](https://github.com/mistralai/client-python/blob/main/RELEASES.md) - [Commits](mistralai/client-python@v1.2.0...v2.9.4) --- updated-dependencies: - dependency-name: mistralai dependency-version: 2.9.4 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
🟡 Changes recommended
The dependency constraint update leaves the committed Python lockfile out of sync, which can break frozen/reproducible installs.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR updates the Python package extra dependency constraint for mistralai to allow newer client versions, aligning Semantic Kernel’s Python connector ecosystem with the latest mistralai releases.
Changes:
- Bumps the allowed
mistralaiversion range from<2.7.3to<2.9.5in the Pythonpyproject.tomlextras.
File summaries
| File | Description |
|---|---|
| python/pyproject.toml | Expands the allowed mistralai dependency upper bound for the mistralai extra. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| mistralai = [ | ||
| "mistralai >= 1.2,< 2.7.3" | ||
| "mistralai >= 1.2,< 2.9.5" | ||
| ] |
Eduard van Valkenburg (eavanvalkenburg)
left a comment
There was a problem hiding this comment.
Review finding (blocking): mistralai 2.x breaks the existing connector imports
This allows mistralai 2.9.4, but the connector and tests still import top-level symbols that the 2.x package no longer exports, including Mistral, CompletionEvent, and utils. The unit-test run fails during collection with these import errors. Please either retain an upper bound below the breaking client version or migrate the connector and tests to the 2.x API, then regenerate the lockfile.
|
Copilot Make this dependency update compatible with the existing Mistral connector. Either migrate the connector and tests to the |
Co-authored-by: eavanvalkenburg <13749212+eavanvalkenburg@users.noreply.github.com>
Implemented in 16c669a. The constraint and |
Updates the requirements on mistralai to permit the latest version.
Release notes
Sourced from mistralai's releases.
Changelog
Sourced from mistralai's changelog.
... (truncated)
Commits
df37126ci: publish with a twine that accepts current wheel metadata (#612)b770bb8feat(otel): read workflow execution id from baggage (#611)22f9040chore: 🐝 Update SDK - Generate MISTRALAI MISTRALAI-SDK [speakeasy/mistralai-s...e31acb2chore: 🐝 Update SDK - Generate MISTRALAI MISTRALAI-SDK [speakeasy/mistralai-s...22608d4Add optional parameter to force payload offloading (#608)dd6a743chore: 🐝 Update SDK - Generate MISTRALAI MISTRALAI-SDK [speakeasy/mistralai-s...504bcfcfix(otel): relax semantic-conventions upper bound (#605)1cc2d2cchore: 🐝 Update SDK - Generate MISTRALAI MISTRALAI-SDK [speakeasy/mistralai-s...c53dcfdchore: 🐝 Update SDK - Generate MISTRALAI MISTRALAI-SDK [speakeasy/mistralai-s...7749c84chore: 🐝 Update SDK - Generate MISTRALAI MISTRALAI-SDK [speakeasy/mistralai-s...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)