Repository navigation
chore(deps): bump the python-minor-patch group with 7 updates - #144
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the python-minor-patch group with 7 updates: | Package | From | To | | --- | --- | --- | | [ruff](https://github.com/astral-sh/ruff) | `0.16.9` | `0.16.10` | | [fastapi](https://github.com/fastapi/fastapi) | `0.141.1` | `0.142.2` | | [msgspec](https://github.com/msgspec/msgspec) | `0.21.1` | `0.22.0` | | [pydantic-core](https://github.com/pydantic/pydantic) | `2.46.5` | `2.49.0` | | [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.3` | `1.2.4` | | [sse-starlette](https://github.com/sysid/sse-starlette) | `3.4.11` | `3.5.0` | | [w3lib](https://github.com/scrapy/w3lib) | `2.4.1` | `2.5.0` | Updates `ruff` from 0.16.9 to 0.16.10 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.9...0.16.10) Updates `fastapi` from 0.141.1 to 0.142.2 - [Release notes](https://github.com/fastapi/fastapi/releases) - [Commits](fastapi/fastapi@0.141.1...0.142.2) Updates `msgspec` from 0.21.1 to 0.22.0 - [Release notes](https://github.com/msgspec/msgspec/releases) - [Changelog](https://github.com/msgspec/msgspec/blob/main/docs/changelog.md) - [Commits](msgspec/msgspec@0.21.1...0.22.0) Updates `pydantic-core` from 2.46.5 to 2.49.0 - [Release notes](https://github.com/pydantic/pydantic/releases) - [Changelog](https://github.com/pydantic/pydantic/blob/main/HISTORY.md) - [Commits](https://github.com/pydantic/pydantic/commits) Updates `python-dotenv` from 1.2.3 to 1.2.4 - [Release notes](https://github.com/theskumar/python-dotenv/releases) - [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md) - [Commits](theskumar/python-dotenv@v1.2.3...v1.2.4) Updates `sse-starlette` from 3.4.11 to 3.5.0 - [Release notes](https://github.com/sysid/sse-starlette/releases) - [Commits](sysid/sse-starlette@v3.4.11...v3.5.0) Updates `w3lib` from 2.4.1 to 2.5.0 - [Release notes](https://github.com/scrapy/w3lib/releases) - [Changelog](https://github.com/scrapy/w3lib/blob/master/NEWS) - [Commits](scrapy/w3lib@v2.4.1...v2.5.0) --- updated-dependencies: - dependency-name: ruff dependency-version: 0.16.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: fastapi dependency-version: 0.142.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: msgspec dependency-version: 0.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: pydantic-core dependency-version: 2.49.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: python-dotenv dependency-version: 1.2.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: sse-starlette dependency-version: 3.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch - dependency-name: w3lib dependency-version: 2.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Owner
|
Superseded by #148: same updates, but pydantic-core stays at 2.46.5 (pydantic 2.13.5 requires exactly that version, so this PR could not be installed) and opentelemetry-api 1.45.0, the new dependency of fastapi 0.142, is pinned. |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
dependabot
Bot
deleted the
dependabot/pip/python-minor-patch-b144a6d27a
branch
October 6, 2026 15:50
tunjayoff
added a commit
that referenced
this pull request
Oct 6, 2026
chore(deps): python minor/patch group with pydantic-core and opentelemetry-api pins [supersedes #144]
This was referenced Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the python-minor-patch group with 7 updates:
0.16.90.16.100.141.10.142.20.21.10.22.02.46.52.49.01.2.31.2.43.4.113.5.02.4.12.5.0Updates
rufffrom 0.16.9 to 0.16.10Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
Commits
3265ed1Bump version to 0.16.10 (#29055)e786964Authorize shared PR security-review workflow to publish findings (#29052)a81291e[ty] Defer uv workspace discovery until after project configuration (#28525)b6a74d2[ty] Refresh uv project metadata when uv files change (#28529)41d30dfUpdate Rust toolchain to 1.99 and MSRV to 1.97 (#29047)317e0a3[ty] Bound nested callable signature display (#29049)8546752[ty] Fix member lookup on union-bounded type variables (#29018)56180bc[ty] Specialize instance members once (#29043)aa9a1ff[ty] Avoid stale I/O diagnostics when closing deleted files (#28988)2d25346[ty] Improveunresolved-importdocumentation (#29039)Updates
fastapifrom 0.141.1 to 0.142.2Release notes
Sourced from fastapi's releases.
... (truncated)
Commits
78c4324🔖 Release version 0.142.2 (#16419)2579ed0📝 Update release notes1d4953d🐛 Allow startup when automatic OpenTelemetry configuration fails (#16418)3e33a03🔖 Release version 0.142.1 (#16415)12ea7f5📝 Update release notesac88f56🐛 Fix repeated endpoint wrapping in included routers (#16414)bd41128🔖 Release version 0.142.0 (#16411)7aa21e5📝 Update release notes4b3949c✨ Add native OpenTelemetry support (#16403)c30032a📝 Update release notesUpdates
msgspecfrom 0.21.1 to 0.22.0Release notes
Sourced from msgspec's releases.
... (truncated)
Changelog
Sourced from msgspec's changelog.
... (truncated)
Commits
6d3443fFix a reference leak of a non-Struct base's type dict (#1199)2f0b50dCorrect the reported signatures of several public callables (#1197)8a25471Skip instance__dataclass_fields__lookup for non-dataclass types (#1196)7930780Fix reference leak when defining a Struct type (#1194)55f5cddfix(msgpack): raise DecodeError for unhashable map keys (#1209)b2d1b7aRejectgc=Falseon struct types with a weakref slot (#1207)f2bbec5Move the unreleased changes into the 0.22.0 changelog (#1211)c23e150Fix json schema defaults for set / bytearray default_factory fields (#1183)fed9fc3Skip recursive type alias test on Windows ARM64 with Python 3.12 (#1210)e7552f0Bump msgpack from 1.2.1 to 1.2.2 (#1202)Updates
pydantic-corefrom 2.46.5 to 2.49.0Commits
Updates
python-dotenvfrom 1.2.3 to 1.2.4Release notes
Sourced from python-dotenv's releases.
Changelog
Sourced from python-dotenv's changelog.
Commits
a565c2cBump version: 1.2.3 → 1.2.44a7abd0docs: add 1.2.4 release notes (#663, #698, #700)f215c02fix: dotenv get exits 0 for empty string values (#700)58f2d7ctest: make test_run_with_command_flags portable and meaningful (#709)e0310e5fix: honor --no-override when expanding variables in dotenv run (#698)a00cb2edocs: add CHANGELOG entry for #663 (fix #600)f5485a6fix: parse empty unquoted value with inline comment as empty stringUpdates
sse-starlettefrom 3.4.11 to 3.5.0Release notes
Sourced from sse-starlette's releases.
Commits
1705b2dBump version to 3.5.016179fdMerge pull request #212 from sysid/fix/issue2113821353fix(shutdown): re-resolve uvicorn server on every watcher poll6925c68fix(tests): import httpx2 instead of removed httpx dependencyaa3b89ebuild(deps): bump starlette to 1.7.0 for anyio BlockingPortal deprecation329a72cbuild(deps): bump anyio, autobahn, setuptools for security advisoriesd43a29ftest(experimentation): assert consumer line counts in main thread96afe01fix(shutdown): stop latching AppStatus.should_exit from uvicorn stateUpdates
w3libfrom 2.4.1 to 2.5.0Changelog
Sourced from w3lib's changelog.
... (truncated)
Commits
537c5d4Bump version: 2.4.1 → 2.5.01bc3dfcRelease notes for 2.5.0 (#260)8c153f2Merge pull request #353 from uchiha-bug-hunter/html-scanners-ascii-whitespace7caeccdEnd start tag names on [\s/>] instead of \b in remove_tags_with_content916476fmatch only ASCII whitespace in the html tag and refresh regexesd5d5e4fMerge pull request #352 from scrapy/dot-segments-linearfc3d1cbMake _remove_dot_segments() linear and skip ineligible URLs early.4d7db49Find the URL delimiters with str.find() in _urlsplit(). (#351)9c1d9cbBenchmark URL functions on a long URL with a cold _urlsplit cache. (#350)0a98564Merge pull request #349 from uchiha-bug-hunter/base-url-href-attributeDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions