Skip to content

deps(uv): bump the uv-minor-patch group across 1 directory with 43 updates - #2046

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/uv-minor-patch-23b388f229
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/uv-minor-patch-23b388f229

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the uv-minor-patch group with 43 updates in the / directory:

Package From To
charset-normalizer 3.5.1 3.5.2
cryptography 50.0.1 50.0.2
fastapi 0.141.1 0.142.2
fonttools 4.65.0 4.66.1
pyparsing 3.3.2 3.3.3
pyjwt 2.14.0 2.15.1
python-dotenv 1.2.3 1.2.4
regex 2026.9.10 2026.9.29
sqlalchemy 2.0.54 2.1.2
starlette 1.6.0 1.7.0
uvicorn 0.53.0 0.54.0
werkzeug 3.1.8 3.1.9
webauthn 3.0.0 3.0.1
pymssql 2.4.1 2.4.2
oracledb 26.0.0 26.0.1
pymongo 4.18.1 4.18.2
snowflake-connector-python 4.7.4 4.8.0
pillow-heif 1.7.0 1.8.0
mammoth 1.12.2 1.13.0
gitpython 3.1.62 3.2.0
opentelemetry-api 1.44.0 1.45.0
opentelemetry-sdk 1.44.0 1.45.0
opentelemetry-exporter-otlp 1.44.0 1.45.0
opentelemetry-instrumentation-fastapi 0.65b0 0.66b0
opentelemetry-instrumentation-sqlalchemy 0.65b0 0.66b0
opentelemetry-instrumentation-logging 0.65b0 0.66b0
cyclonedx-bom 7.4.0 7.5.0
hypothesis 6.168.0 6.168.3
httpx2 2.13.0 2.13.1
markdown 3.10.3 3.11
mypy 2.3.1 2.4.0
ruff 0.16.8 0.16.10
ast-serialize 0.11.2 0.12.0
cbor2 6.1.4 6.1.5
coverage 7.16.1 7.16.2
fqdn 1.5.1 1.6.0
httpcore2 2.13.0 2.13.1
identify 2.6.19 2.6.20
librt 0.15.0 0.16.0
nodeenv 1.10.0 1.11.0
platformdirs 4.11.11 4.12.2
soupsieve 2.9.2 2.10
virtualenv 21.9.0 21.14.5

Updates charset-normalizer from 3.5.1 to 3.5.2

Release notes

Sourced from charset-normalizer's releases.

Version 3.5.2

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Changelog

Sourced from charset-normalizer's changelog.

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Commits
  • 935c29a Release 3.5.2 (#805)
  • 9d3238a test: disable traefik in downstream niquests
  • b4c0368 docs: write changelog entry for 3.5.2
  • 717da31 chore: bump version to 3.5.2
  • 264895d chore: update pypa/cibuildwheel and pypa/gh-action-pypi-publish
  • 41e28b6 chore: raise Cython upper bound to 3.3
  • b130b7d Fix valid UTF-8 Chinese JSON misdetected as PTCP154 (#796)
  • f6afd31 Make the IANA_NO_ALIASES encodings resolvable by name (#800)
  • See full diff in compare view

Updates cryptography from 50.0.1 to 50.0.2

Changelog

Sourced from cryptography's changelog.

50.0.2 - 2026-09-30


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.3.
* Added ``abi3.abi3t`` wheels for free-threaded CPython 3.15 and later.
* Updated to PyO3 0.29.2, which fixes building ``cryptography`` on Cygwin and
  MSYS2.

.. _v50-0-1:

Commits

Updates fastapi from 0.141.1 to 0.142.2

Release notes

Sourced from fastapi's releases.

0.142.2

Fixes

  • 🐛 Allow startup when automatic OpenTelemetry configuration fails. PR #16418 by @​tiangolo.

0.142.1

Fixes

0.142.0

Features

Refactors

Docs

Translations

Internal

... (truncated)

Commits

Updates fonttools from 4.65.0 to 4.66.1

Release notes

Sourced from fonttools's releases.

4.66.1

  • [designspaceLib] When splitting a DesignSpace v5 document with makeNames=True (as varLib.build_many does), family and style names set explicitly on an instance now take precedence over the ones computed from the STAT labels, in all languages, and a PostScript name is no longer made up from the labels for an instance that has its own style name (#3131, #4206, #4208).
  • [cmap] Decompiling a format 4 subtable whose idRangeOffset points outside glyphIndexArray now raises TTLibError. A negative index used to silently map the code point to the wrong glyph, and one past the end raised a bare AssertionError (#4209).
  • [cmap] Fix compiling a format 2 subtable when the lowest glyph ID in a lead-byte row is 32768 or higher, which failed with struct.error (#4210).

4.66.0

  • Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later. fontTools.misc.enumTools now only re-exports enum.StrEnum and is deprecated. Explicitly test and declare support for Python 3.15 (#4183, #4196).
  • [unicodedata] Update the bundled script, script extension, block and bidi-mirroring tables to Unicode 18.0.0, and require unicodedata2 18.0.0 when it is used (#4192, #4197).
  • [feaLib] Support language statements listing multiple language tags, e.g. language AZE CRT;adobe-type-tools/feature_file_workshops#8dflt cannot be combined with other tags. LanguageStatement.language is still the first tag; all of them are in the new languages attribute (#4201, #4202).
  • [feaLib] Fix lookups being dropped when a script/language pair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#4189).
  • [feaLib] Raise FeatureLibError instead of UnboundLocalError when a STAT table block lacks ElidedFallbackName or ElidedFallbackNameID (#3834, #4179).
  • [cffLib] Always recompile the CFF2 VarStore when saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a stale VarStore next to its updated charstrings (#4199).
  • [ttLib] Support static VARC fonts that omit fvar while retaining gvar or CFF2 variation data for component-internal axes: hidden axes are addressed by index and gvar can compile, decompile and round-trip through TTX without fvar, reading the axis count from a new axisCount element (#4187, #4188).
  • [ttLib] Fix drawing VARC components whose condition is negated (format 5), which raised AttributeError (#4191).
  • [instancer] Fix VARC axis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced by VARC components, and stop culling avar2 ranges for component-internal variations, which can reach outside the font-level ranges (#4190, #4193).
  • [bezierTools] Preserve exact endpoints in splitQuadraticAtT and splitCubicAtTC as well, like splitCubicAtT since 4.55.4 (#3742, #4194).
  • [bezierTools] Fix ZeroDivisionError in lineLineIntersections for collinear vertical lines; they are now treated as parallel like horizontal ones (#3515, #4181).
  • [subset] pyftsubset now preserves the input font's flavor (WOFF, WOFF2) when --flavor is omitted, instead of writing uncompressed sfnt data under the same extension; pass --flavor=none to force uncompressed output (#3630, #4182).
  • [merge] Report incompatible unitsPerEm values by name, with the input values, instead of a bare assertion (#2844, #4184).
  • [designspaceLib] Fix the type annotation and documentation of DesignSpaceDocument.default, which holds a SourceDescriptor, not a source name (#2994, #4186).
  • [ttLib.sfnt] Raise TTLibError instead of AssertionError for inconsistent WOFF table, metadata and private-data lengths, so the checks also hold under python -O (#4178).
  • [misc.etree] Disable entity resolution altogether on lxml >= 5.0 as well: lxml's resolve_entities="internal" still fetched external parameter entities before lxml 6.1.3, so a crafted DTD could read local files into parsed XML content (#4195).
  • [cmap] Bound the expansion of format 4 segments and format 12/13 groups when decompiling, like HarfBuzz does: groups are clamped to U+10FFFF, inverted or overlapping groups are skipped with a warning, and groups mapped to the missing glyph are not expanded. A crafted font could previously exhaust memory with a single group ending at 0xFFFFFFFF (#4204).
  • [varLib.avar] Escape axis names and tags when varLib.avar.unbuild emits its designspace snippet, so a crafted font cannot inject markup (#4203).
Changelog

Sourced from fonttools's changelog.

4.66.1 (released 2026-09-29)

  • [designspaceLib] When splitting a DesignSpace v5 document with makeNames=True (as varLib.build_many does), family and style names set explicitly on an instance now take precedence over the ones computed from the STAT labels, in all languages, and a PostScript name is no longer made up from the labels for an instance that has its own style name (#3131, #4206, #4208).
  • [cmap] Decompiling a format 4 subtable whose idRangeOffset points outside glyphIndexArray now raises TTLibError. A negative index used to silently map the code point to the wrong glyph, and one past the end raised a bare AssertionError (#4209).
  • [cmap] Fix compiling a format 2 subtable when the lowest glyph ID in a lead-byte row is 32768 or higher, which failed with struct.error (#4210).

4.66.0 (released 2026-09-23)

  • Drop support for EOL Python 3.10; fontTools now requires Python 3.11 or later. fontTools.misc.enumTools now only re-exports enum.StrEnum and is deprecated. Explicitly test and declare support for Python 3.15 (#4183, #4196).
  • [unicodedata] Update the bundled script, script extension, block and bidi-mirroring tables to Unicode 18.0.0, and require unicodedata2 18.0.0 when it is used (#4192, #4197).
  • [feaLib] Support language statements listing multiple language tags, e.g. language AZE CRT;, as Glyphs does and as proposed for the spec adobe-type-tools/feature_file_workshops#8 references are registered under every listed language. dflt cannot be combined with other tags. LanguageStatement.language is still the first tag; all of them are in the new languages attribute (#4201, #4202).
  • [feaLib] Fix lookups being dropped when a script/language pair is repeated within a feature block: the repeated statement replaced the language system's lookups with a fresh copy of the default ones (#4189).
  • [feaLib] Raise FeatureLibError instead of UnboundLocalError when a STAT table block lacks ElidedFallbackName or ElidedFallbackNameID (#3834, #4179).
  • [cffLib] Always recompile the CFF2 VarStore when saving. Previously the bytes compiled by an earlier save were reused, so a CFF2 variable font that was saved and then modified in place, e.g. by the instancer, was written with a stale VarStore next to its updated charstrings (#4199).
  • [ttLib] Support static VARC fonts that omit fvar while retaining gvar or CFF2 variation data for component-internal axes: hidden axes are addressed by index and gvar can compile, decompile and round-trip through TTX without fvar, reading the axis count from a new axisCount element (#4187, #4188).
  • [ttLib] Fix drawing VARC components whose condition is negated (format 5), which raised AttributeError (#4191).
  • [instancer] Fix VARC axis references left stale when removing an unrelated axis, reject pinning or restricting axes referenced by VARC components, and stop culling avar2 ranges for component-internal variations,

... (truncated)

Commits
  • 9e95795 Release 4.66.1
  • 8fc91fb Update NEWS.rst [skip ci]
  • 82dc507 Merge pull request #4209 from insaf021/cmap4-idrangeoffset-bounds
  • a83553e trim comments
  • 85049d3 Merge pull request #4208 from fonttools/fix-split-stat-names-override
  • 1ad111d Merge pull request #4210 from youdie006/cmap-format2-high-gids
  • c9e9d68 [cmap] fix format 2 compile for glyph IDs above 32767
  • 85625c5 raise TTLibError for out-of-range glyphIndexArray offset in cmap format 4
  • 879173e [designspaceLib] Let explicit instance names win over STAT labels when splitting
  • 718b61b Bump version: 4.66.0 → 4.66.1.dev0
  • Additional commits viewable in compare view

Updates pyparsing from 3.3.2 to 3.3.3

Changelog

Sourced from pyparsing's changelog.

Version 3.3.3 - in development

  • Added support for Python 3.15.

  • Parse actions that return a tuple value for a named expression formerly saved just the first value of the tuple. Now they return the entire tuple. Partially fixes Issue #401, PR #640 submitted by Vincent Gao et AI.

  • Fixed CI unit test jobs selecting a tox environment with no test commands. The matrix and fallback now select py-unit, as diagnosed and proposed by glaziermag in issue #662; submitted by Neal Lin et AI.

  • Fixed Dict returning an empty nested ParseResults.as_dict() as [] instead of {}. Incorporates partial solution submitted in PR #635 submitted by Leo Ji.

    Additional fixes found as part of this work:

    • Removed vestigial unused ParseResults._modal attribute.

    • Fixed incidental bug when Dict tries to create a dict with a ParseResults value for a key (not hashable).

  • Fixed Word(..., max=n) raising instead of matching up to max characters when the character set contained whitespace - Word(nums, max=3) and Word(nums + " ", max=3) gave opposite results on the same input. Now both forms match up to max and leave the rest for the next parser. PR #646 submitted by Andrew Chen et AI.

  • Fixed QuotedString stripping whitespace that is part of a multi-character quote delimiter, e.g. the leading newline in QuotedString("\n;", multiline=True). The delimiter was silently collapsed to ";", so the newline was ignored when matching. QuotedString now only rejects quote_char/end_quote_char values that are empty or entirely whitespace, and preserves any surrounding whitespace that is part of a valid delimiter. Reported in issue #492.

  • Fixed pyparsing_common.as_datetime raising Invalid date/time: microsecond must be in 0..999999 for valid ISO-8601 timestamps whose fractional seconds round up to a full second (e.g. 2021-06-15T12:30:59.9999995, common in nanosecond-precision timestamps). The rounded microseconds are now added via timedelta so the value carries into the next second instead of overflowing the datetime microsecond argument. PR submitted by Andrew Chen et AI.

  • Fixed debug output corruption when a parsed line contains a carriage return or other control character. set_debug() printed the source line verbatim, so a stray \r returned the terminal cursor to column 0 and overwrote the "Match ... at loc" text. Control characters in the debug line are now shown escaped, and the marker caret stays aligned with the match location. Issue #496, reported by Matthew Rowles.

... (truncated)

Commits
  • d90d38b Update flit version and exclusion of generated railroad diagrams from source ...
  • 4220992 Updated CI to execute unit tests, PR #663; update test_unit.py to add test ca...
  • e266043 Reworked internal recursive implementations to use local stack vars or iterat...
  • See full diff in compare view

Updates pyjwt from 2.14.0 to 2.15.1

Release notes

Sourced from pyjwt's releases.

2.15.1

See the 2.15.1 changelog for complete release details.

2.15.0

See the 2.15.0 changelog for complete release details.

Changelog

Sourced from pyjwt's changelog.

v2.15.1 <https://github.com/jpadilla/pyjwt/compare/2.15.0...2.15.1>__

Fixed


- Accept trailing Base64URL ``=`` padding when decoding JWS segments, so
  tokens issued by AWS ALB and similar systems verify instead of raising
  ``DecodeError: Invalid crypto padding``. Non-alphabet junk such as
  ``!!!!`` remains rejected (`[#1209](https://github.com/jpadilla/pyjwt/issues/1209) <https://github.com/jpadilla/pyjwt/issues/1209>`__).

v2.15.0 &lt;https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&gt;__

Security

  • Wrap recursion errors from deeply nested JWT payloads in DecodeError instead of exposing a raw RecursionError.

Added


- Support Python 3.15 by @kytta in `[#1202](https://github.com/jpadilla/pyjwt/issues/1202) <https://github.com/jpadilla/pyjwt/pull/1202>`__

Changed

  • JWKSetCache now stores the parsed PyJWKSet rather than the raw JWKS payload, so a cache hit no longer re-parses every key. JWKSetCache.put() accepts either form and raises PyJWKSetError for anything else. As a result, PyJWKClient.get_jwk_set() returns the same PyJWKSet instance for as long as it stays cached, rather than a freshly built one per call in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) <https://github.com/jpadilla/pyjwt/pull/1208>__
  • PyJWKClient.fetch_data() now raises PyJWKClientError("The JWKS endpoint did not return a JSON object") when the endpoint response is not a JSON object, instead of returning it for get_jwk_set() to reject. Callers reaching the JWKS through get_jwk_set() see the same error as before in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) <https://github.com/jpadilla/pyjwt/pull/1208>__

Fixed


- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead
  of raising ``PyJWKClientError("The JWKS endpoint did not return a JSON
  object")``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value,
  so callers pre-populating the cache to avoid a network round-trip could not
  read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) <https://github.com/jpadilla/pyjwt/issues/914>`__ and
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) <https://github.com/jpadilla/pyjwt/pull/1208>`__
</tr></table> 

... (truncated)

Commits
  • 7d5ef55 chore: prepare 2.15.1 release
  • 7bf3252 Accept canonical Base64URL padding in JWT segments (#1216)
  • 1d41a64 chore: prepare 2.15.0 release
  • 9bc0665 fix: make recursive payload tests deterministic
  • 5fde08a fix: normalize recursive JWT payload errors
  • 171062d utils: mention bytes in force_bytes type error (#1173)
  • c9d4d53 docs/conf: drop duplicate 'and' from read() docstring (#1174)
  • 2763752 Add support for Python 3.15 (#1202)
  • 4adcd02 Catch http.client.HTTPException in PyJWKClient.fetch_data (#1201)
  • 9e501d9 fix: correct docstring typo in _validate_jti (#1179)
  • Additional commits viewable in compare view

Updates python-dotenv from 1.2.3 to 1.2.4

Release notes

Sourced from python-dotenv's releases.

v1.2.4

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Changelog

Sourced from python-dotenv's changelog.

[1.2.4] - 2026-10-01

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Commits
  • a565c2c Bump version: 1.2.3 → 1.2.4
  • 4a7abd0 docs: add 1.2.4 release notes (#663, #698, #700)
  • f215c02 fix: dotenv get exits 0 for empty string values (#700)
  • 58f2d7c test: make test_run_with_command_flags portable and meaningful (#709)
  • e0310e5 fix: honor --no-override when expanding variables in dotenv run (#698)
  • a00cb2e docs: add CHANGELOG entry for #663 (fix #600)
  • f5485a6 fix: parse empty unquoted value with inline comment as empty string
  • See full diff in compare view

Updates regex from 2026.9.10 to 2026.9.29

Changelog

Sourced from regex's changelog.

Version: 2026.9.29

Updated to Unicode 18.0.0.

Switched to using stdbool.h and stdint.h.

Version: 2026.9.19

Git issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group

Version: 2026.9.10

Fixed version.

Version: 2026.9.9

PR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers

PR #616: Preserve Python Exceptions in Input Decoding and String Detachment

PR #617: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining

PR #618: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution

Version: 2026.9.3

New version of cibuildwheel no longer supports building for free-threaded Python 3.13.

Version: 2026.9.2

New version of cibuildwheel no longer needs nor supports cpython-freethreading option.

Version: 2026.9.1

Updated cibuildwheel.
Support Python 3.15.

Version: 2026.8.31

Fixed version.

Version: 2026.8.30

Git issue 611: Heap out-of-bounds write at compile time
Git issue 612: count_one() size underflow through the stale required-string cache
Git issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop
Git issue 614: build_GROUP() does not propagate the match direction

Version: 2026.8.12

... (truncated)

Commits
  • 0e8cb05 Updated to Unicode 18.0.0.
  • 85e568c Git issue 619: Match.expand() segfaults after detach_string() when the te...
  • See full diff in compare view

Updates sqlalchemy from 2.0.54 to 2.1.2

Release notes

Sourced from sqlalchemy's releases.

2.1.2

Released: October 2, 2026

orm

  • [orm] [bug] [regression] Fixed regression caused by #5987 where the selectinload() loader strategy would ignore additional criteria present in the _orm.relationship.primaryjoin of a many-to-many relationship, such as a comparison against a column on the association table or on the parent table, loading related rows that should have been excluded. The omit_join optimization for many-to-many relationships is now only used when the primaryjoin consists solely of comparisons between the parent's primary key columns and the association table.

    References: #13626

engine

  • [engine] [bug] [regression] Fixed regression where result rows delivered by the DBAPI as a subclass of tuple would fail to be processed when the Cython extensions were in use, raising TypeError: Expected tuple. Such rows are now converted to a plain tuple, as was the case in 2.0. Rows delivered as a plain tuple, or as a sequence that is not a tuple at all such as asyncpg's Record, were not affected. Drivers such as the Databricks SQL connector return rows that are tuple subclasses.

    References: #13619

sql

  • [sql] [bug] The plain string portions of a _sql.tstring() construct are no longer scanned for bound parameter names in the :name format, and no longer interpret the \: escape sequence; the text is now rendered exactly as given. Previously, each string portion was parsed in the same way as _sql.text(), so that a colon within a quoted SQL string, such as 'time is :now', would be rendered as a bound parameter, failing at execution time.

    This change is a breaking change in the behavior of the newly introduced _sql.tstring() feature, as the former use of text() inadvertently provided a behavior that wasn't intended. In order to embed an explicit parameter in the SQL generated by _sql.tstring(), _sql.bindparam() may be used directly, e.g. tstring(t"SELECT {bindparam('p')}").

    References: #13616

... (truncated)

Commits

Updates starlette from 1.6.0 to 1.7.0

Release notes

Sourced from starlette's releases.

Version 1.7.0

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING] OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

Full changelog: 1.6.0...1.7.0

Changelog

Sourced from starlette's changelog.

1.7.0 (September 23, 2026)

This release adds experimental OpenTelemetry tracing and requires AnyIO 4.

!!! warning "OpenTelemetryMiddleware is experimental" Its API and emitted telemetry may change in minor releases without a deprecation period #3574.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.
Commits

…dates

Bumps the uv-minor-patch group with 43 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.5.1` | `3.5.2` |
| [cryptography](https://github.com/pyca/cryptography) | `50.0.1` | `50.0.2` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.141.1` | `0.142.2` |
| [fonttools](https://github.com/fonttools/fonttools) | `4.65.0` | `4.66.1` |
| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.3.2` | `3.3.3` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.14.0` | `2.15.1` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.3` | `1.2.4` |
| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.9.10` | `2026.9.29` |
| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.54` | `2.1.2` |
| [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.53.0` | `0.54.0` |
| [werkzeug](https://github.com/pallets/werkzeug) | `3.1.8` | `3.1.9` |
| [webauthn](https://github.com/duo-labs/py_webauthn) | `3.0.0` | `3.0.1` |
| [pymssql](https://github.com/pymssql/pymssql) | `2.4.1` | `2.4.2` |
| [oracledb](https://github.com/oracle/python-oracledb) | `26.0.0` | `26.0.1` |
| [pymongo](https://github.com/mongodb/mongo-python-driver) | `4.18.1` | `4.18.2` |
| [snowflake-connector-python](https://github.com/snowflakedb/snowflake-connector-python) | `4.7.4` | `4.8.0` |
| [pillow-heif](https://github.com/bigcat88/pillow_heif) | `1.7.0` | `1.8.0` |
| [mammoth](https://github.com/mwilliamson/python-mammoth) | `1.12.2` | `1.13.0` |
| [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.62` | `3.2.0` |
| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [opentelemetry-instrumentation-fastapi](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.65b0` | `0.66b0` |
| [opentelemetry-instrumentation-sqlalchemy](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.65b0` | `0.66b0` |
| [opentelemetry-instrumentation-logging](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.65b0` | `0.66b0` |
| [cyclonedx-bom](https://github.com/CycloneDX/cyclonedx-python) | `7.4.0` | `7.5.0` |
| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.168.0` | `6.168.3` |
| [httpx2](https://github.com/pydantic/httpx2) | `2.13.0` | `2.13.1` |
| [markdown](https://github.com/Python-Markdown/markdown) | `3.10.3` | `3.11` |
| [mypy](https://github.com/python/mypy) | `2.3.1` | `2.4.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.8` | `0.16.10` |
| [ast-serialize](https://github.com/mypyc/ast_serialize) | `0.11.2` | `0.12.0` |
| [cbor2](https://github.com/agronholm/cbor2) | `6.1.4` | `6.1.5` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.16.1` | `7.16.2` |
| [fqdn](https://github.com/ypcrts/fqdn) | `1.5.1` | `1.6.0` |
| [httpcore2](https://github.com/pydantic/httpx2) | `2.13.0` | `2.13.1` |
| [identify](https://github.com/pre-commit/identify) | `2.6.19` | `2.6.20` |
| [librt](https://github.com/mypyc/librt) | `0.15.0` | `0.16.0` |
| [nodeenv](https://github.com/ekalinin/nodeenv) | `1.10.0` | `1.11.0` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.11` | `4.12.2` |
| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.9.2` | `2.10` |
| [virtualenv](https://github.com/pypa/virtualenv) | `21.9.0` | `21.14.5` |



Updates `charset-normalizer` from 3.5.1 to 3.5.2
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](jawah/charset_normalizer@3.5.1...3.5.2)

Updates `cryptography` from 50.0.1 to 50.0.2
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@50.0.1...50.0.2)

Updates `fastapi` from 0.141.1 to 0.142.2
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.141.1...0.142.2)

Updates `fonttools` from 4.65.0 to 4.66.1
- [Release notes](https://github.com/fonttools/fonttools/releases)
- [Changelog](https://github.com/fonttools/fonttools/blob/main/NEWS.rst)
- [Commits](fonttools/fonttools@4.65.0...4.66.1)

Updates `pyparsing` from 3.3.2 to 3.3.3
- [Release notes](https://github.com/pyparsing/pyparsing/releases)
- [Changelog](https://github.com/pyparsing/pyparsing/blob/master/CHANGES)
- [Commits](pyparsing/pyparsing@3.3.2...3.3.3)

Updates `pyjwt` from 2.14.0 to 2.15.1
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.14.0...2.15.1)

Updates `python-dotenv` from 1.2.3 to 1.2.4
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.3...v1.2.4)

Updates `regex` from 2026.9.10 to 2026.9.29
- [Changelog](https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt)
- [Commits](mrabarnett/mrab-regex@2026.9.10...2026.9.29)

Updates `sqlalchemy` from 2.0.54 to 2.1.2
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

Updates `starlette` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.6.0...1.7.0)

Updates `uvicorn` from 0.53.0 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.53.0...0.54.0)

Updates `werkzeug` from 3.1.8 to 3.1.9
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.8...3.1.9)

Updates `webauthn` from 3.0.0 to 3.0.1
- [Release notes](https://github.com/duo-labs/py_webauthn/releases)
- [Changelog](https://github.com/duo-labs/py_webauthn/blob/master/CHANGELOG.md)
- [Commits](duo-labs/py_webauthn@v3.0.0...v3.0.1)

Updates `pymssql` from 2.4.1 to 2.4.2
- [Release notes](https://github.com/pymssql/pymssql/releases)
- [Changelog](https://github.com/pymssql/pymssql/blob/master/ChangeLog.rst)
- [Commits](pymssql/pymssql@v2.4.1...v2.4.2)

Updates `oracledb` from 26.0.0 to 26.0.1
- [Release notes](https://github.com/oracle/python-oracledb/releases)
- [Commits](oracle/python-oracledb@v26.0.0...v26.0.1)

Updates `pymongo` from 4.18.1 to 4.18.2
- [Release notes](https://github.com/mongodb/mongo-python-driver/releases)
- [Changelog](https://github.com/mongodb/mongo-python-driver/blob/main/doc/changelog.rst)
- [Commits](mongodb/mongo-python-driver@4.18.1...4.18.2)

Updates `snowflake-connector-python` from 4.7.4 to 4.8.0
- [Release notes](https://github.com/snowflakedb/snowflake-connector-python/releases)
- [Commits](snowflakedb/snowflake-connector-python@v4.7.4...v4.8.0)

Updates `pillow-heif` from 1.7.0 to 1.8.0
- [Release notes](https://github.com/bigcat88/pillow_heif/releases)
- [Changelog](https://github.com/bigcat88/pillow_heif/blob/master/CHANGELOG.md)
- [Commits](bigcat88/pillow_heif@v1.7.0...v1.8.0)

Updates `mammoth` from 1.12.2 to 1.13.0
- [Changelog](https://github.com/mwilliamson/python-mammoth/blob/master/NEWS)
- [Commits](mwilliamson/python-mammoth@1.12.2...1.13.0)

Updates `gitpython` from 3.1.62 to 3.2.0
- [Release notes](https://github.com/gitpython-developers/GitPython/releases)
- [Changelog](https://github.com/gitpython-developers/GitPython/blob/main/CHANGES)
- [Commits](gitpython-developers/GitPython@3.1.62...3.2.0)

Updates `opentelemetry-api` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-sdk` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-exporter-otlp` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-instrumentation-fastapi` from 0.65b0 to 0.66b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-sqlalchemy` from 0.65b0 to 0.66b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-logging` from 0.65b0 to 0.66b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `cyclonedx-bom` from 7.4.0 to 7.5.0
- [Release notes](https://github.com/CycloneDX/cyclonedx-python/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-python/blob/main/CHANGELOG.md)
- [Commits](CycloneDX/cyclonedx-python@v7.4.0...v7.5.0)

Updates `hypothesis` from 6.168.0 to 6.168.3
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.168.0...v6.168.3)

Updates `httpx2` from 2.13.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](pydantic/httpx2@v2.13.0...v2.13.1)

Updates `markdown` from 3.10.3 to 3.11
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](Python-Markdown/markdown@3.10.3...3.11.0)

Updates `mypy` from 2.3.1 to 2.4.0
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v2.3.1...v2.4.0)

Updates `ruff` from 0.16.8 to 0.16.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/0.16.10/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.8...0.16.10)

Updates `ast-serialize` from 0.11.2 to 0.12.0
- [Commits](mypyc/ast_serialize@v0.11.2...v0.12.0)

Updates `cbor2` from 6.1.4 to 6.1.5
- [Release notes](https://github.com/agronholm/cbor2/releases)
- [Commits](agronholm/cbor2@6.1.4...6.1.5)

Updates `coverage` from 7.16.1 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.1...7.16.2)

Updates `fqdn` from 1.5.1 to 1.6.0
- [Release notes](https://github.com/ypcrts/fqdn/releases)
- [Changelog](https://github.com/ypcrts/fqdn/blob/develop/CHANGELOG.md)
- [Commits](ypcrts/fqdn@v1.5.1...v1.6.0)

Updates `httpcore2` from 2.13.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Commits](pydantic/httpx2@v2.13.0...v2.13.1)

Updates `identify` from 2.6.19 to 2.6.20
- [Commits](pre-commit/identify@v2.6.19...v2.6.20)

Updates `librt` from 0.15.0 to 0.16.0
- [Commits](mypyc/librt@v0.15.0...v0.16.0)

Updates `nodeenv` from 1.10.0 to 1.11.0
- [Release notes](https://github.com/ekalinin/nodeenv/releases)
- [Changelog](https://github.com/ekalinin/nodeenv/blob/master/CHANGES)
- [Commits](ekalinin/nodeenv@1.10.0...1.11.0)

Updates `platformdirs` from 4.11.11 to 4.12.2
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.11...4.12.2)

Updates `soupsieve` from 2.9.2 to 2.10
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](facelessuser/soupsieve@2.9.2...2.10)

Updates `virtualenv` from 21.9.0 to 21.14.5
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](pypa/virtualenv@21.9.0...21.14.5)

---
updated-dependencies:
- dependency-name: charset-normalizer
  dependency-version: 3.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: cryptography
  dependency-version: 50.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: fastapi
  dependency-version: 0.142.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: fonttools
  dependency-version: 4.66.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: pyparsing
  dependency-version: 3.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: pyjwt
  dependency-version: 2.15.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: python-dotenv
  dependency-version: 1.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: regex
  dependency-version: 2026.9.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: sqlalchemy
  dependency-version: 2.1.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: werkzeug
  dependency-version: 3.1.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: webauthn
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: pymssql
  dependency-version: 2.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: oracledb
  dependency-version: 26.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: pymongo
  dependency-version: 4.18.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: snowflake-connector-python
  dependency-version: 4.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: pillow-heif
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: mammoth
  dependency-version: 1.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: gitpython
  dependency-version: 3.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-api
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-sdk
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-exporter-otlp
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-instrumentation-fastapi
  dependency-version: 0.66b0
  dependency-type: direct:production
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-instrumentation-sqlalchemy
  dependency-version: 0.66b0
  dependency-type: direct:production
  dependency-group: uv-minor-patch
- dependency-name: opentelemetry-instrumentation-logging
  dependency-version: 0.66b0
  dependency-type: direct:production
  dependency-group: uv-minor-patch
- dependency-name: cyclonedx-bom
  dependency-version: 7.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: hypothesis
  dependency-version: 6.168.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: httpx2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: markdown
  dependency-version: '3.11'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: mypy
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: ruff
  dependency-version: 0.16.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: ast-serialize
  dependency-version: 0.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: cbor2
  dependency-version: 6.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: fqdn
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: httpcore2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: identify
  dependency-version: 2.6.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-minor-patch
- dependency-name: librt
  dependency-version: 0.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: nodeenv
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: platformdirs
  dependency-version: 4.12.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: soupsieve
  dependency-version: '2.10'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
- dependency-name: virtualenv
  dependency-version: 21.14.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

requirements.txt / pylock.toml drift (unsigned push blocked)

uv.lock / pyproject.toml changed but GitHub Actions cannot push an unsigned commit under the required_signatures ruleset (#1419).

Option A — signed commit on this Dependabot branch:

git fetch origin pull/2046/head:dependabot-review
git checkout dependabot-review
uv export --frozen --no-emit-project -o requirements.txt
uv export --format pylock.toml --frozen --all-extras --all-groups --output-file pylock.toml
git add requirements.txt pylock.toml
git commit -S -m "chore(deps): regenerate requirements.txt and pylock.toml after uv.lock update"
git push origin "HEAD:<dependabot-branch-name>"

Option B — supersede PR: apply the bump + export locally with signed commits (see CONTRIBUTING.md).

Download the CI-generated requirements.txt and pylock.toml from the workflow artifact on this run when present.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants