Skip to content

chore(deps): bump the python-minor-patch group with 7 updates - #144

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-minor-patch-b144a6d27a
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-minor-patch-b144a6d27a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-minor-patch group with 7 updates:

Package From To
ruff 0.16.9 0.16.10
fastapi 0.141.1 0.142.2
msgspec 0.21.1 0.22.0
pydantic-core 2.46.5 2.49.0
python-dotenv 1.2.3 1.2.4
sse-starlette 3.4.11 3.5.0
w3lib 2.4.1 2.5.0

Updates ruff from 0.16.9 to 0.16.10

Release notes

Sourced from ruff's releases.

0.16.10

Release Notes

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

Install ruff 0.16.10

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.ps1 | iex"

Download ruff 0.16.10

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.10

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

Commits
  • 3265ed1 Bump version to 0.16.10 (#29055)
  • e786964 Authorize shared PR security-review workflow to publish findings (#29052)
  • a81291e [ty] Defer uv workspace discovery until after project configuration (#28525)
  • b6a74d2 [ty] Refresh uv project metadata when uv files change (#28529)
  • 41d30df Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)
  • 317e0a3 [ty] Bound nested callable signature display (#29049)
  • 8546752 [ty] Fix member lookup on union-bounded type variables (#29018)
  • 56180bc [ty] Specialize instance members once (#29043)
  • aa9a1ff [ty] Avoid stale I/O diagnostics when closing deleted files (#28988)
  • 2d25346 [ty] Improve unresolved-import documentation (#29039)
  • Additional commits viewable in compare view

Updates fastapi from 0.141.1 to 0.142.2

Release notes

Sourced from fastapi's releases.

0.142.2

Fixes

  • 🐛 Allow startup when automatic OpenTelemetry configuration fails. PR #16418 by @​tiangolo.

0.142.1

Fixes

0.142.0

Features

Refactors

Docs

Translations

Internal

... (truncated)

Commits

Updates msgspec from 0.21.1 to 0.22.0

Release notes

Sourced from msgspec's releases.

Version 0.22.0 (2026-09-29)

  • BREAKING: Setting gc=False on a struct type that has a weakref slot, whether from weakref=True or from a base class, now raises ValueError. On CPython 3.12 and later the weakref slot is stored in a pre-header in front of the instance, so releasing an instance of a gc=False type with that slot corrupted memory, in most builds crashing the interpreter outright. The combination worked on 3.10 and 3.11, and the restriction applies there as well, so that the same class definition behaves the same way on every supported version (#1207).
  • Add frozendict support on Python 3.15+ (#1052, #1105).
  • Support passing a callable as decimal_format to msgspec.json.Encoder and msgspec.msgpack.Encoder for custom Decimal encoding (#978).
  • Support Literal[True] and Literal[False] types (#1004).
  • Publish CPython 3.15 wheels, including freethreaded builds (#1152).
  • Publish Linux riscv64 wheels (#987).
  • Support the PyEmscripten (Pyodide) platform (#1083).
  • Fix handling of PEP 695 type parameter syntax (class Foo[T]) and of types.GenericAlias instances in type annotations (#962).
  • Fix NameError when creating a Struct with an unquoted forward reference on Python 3.14 (#1165).
  • Fix a crash on incorrect typing.ClassVar annotations (#1097).
  • Fix an AttributeError when converting to a Struct type defined in a namespace without a __name__ (#1072).
  • Fix overriding an inherited field alias back to the field's own name (#1133).
  • Raise ValidationError instead of SystemError when convert receives an out-of-range int for a float target (#1162).
  • Report raw rather than the misleading any as the expected type when a non-Raw value is given for a Raw field in convert, and therefore in yaml.decode and toml.decode (#1169).
  • Fix an empty expected-type name in validation errors for a required Raw field in a TypedDict, or a Raw field with a default_factory on a dataclass or an attrs class (#1176).
  • Correct the error messages for out-of-range Meta length bounds (#1172).
  • Fix a reference leak when decoding msgpack Ext payloads (#1109).
  • Fix backing type declaration of Ext.code (#1135).
  • Fix a reference leak in msgspec.to_builtins, and therefore in yaml.encode, for array_like=True structs (#1177).
  • Fix reference leaks in typenode_collect_literal, Meta.__rich_repr__, ms_decode_bigint, and Encoder.__init__ (#1021, #1022, #1023, #1040).
  • Fix msgspec.inspect.type_info and msgspec.json.schema crashing on mixed-type Literals such as Literal[1, None] (#1080).
  • Place null last in the anyOf generated for optional unions in JSON schemas (#1028).
  • Fix minItems in the JSON schema for array_like=True structs whose fields are all optional (#1124).
  • Use [] or "" rather than a Python set or bytearray object as the JSON schema default for Struct fields with a set or bytearray

... (truncated)

Changelog

Sourced from msgspec's changelog.

Version 0.22.0 (2026-09-29)

  • BREAKING: Setting gc=False on a struct type that has a weakref slot, whether from weakref=True or from a base class, now raises ValueError. On CPython 3.12 and later the weakref slot is stored in a pre-header in front of the instance, so releasing an instance of a gc=False type with that slot corrupted memory, in most builds crashing the interpreter outright. The combination worked on 3.10 and 3.11, and the restriction applies there as well, so that the same class definition behaves the same way on every supported version ({pr}1207).
  • BREAKING: Encode an object as a dataclass only when its type defines __dataclass_fields__, as dataclasses.is_dataclass does. Objects that expose it only through instance attribute access, such as proxies wrapping a dataclass instance, are now passed to enc_hook, and encoding them raises TypeError when no enc_hook is given. An enc_hook can return the wrapped instance, which is then encoded as a dataclass. Objects with a Python-level __getattr__, such as pydantic models, now reach enc_hook without that __getattr__ being called ({pr}1196).
  • Add frozendict support on Python 3.15+ ({pr}1052, {pr}1105).
  • Support passing a callable as decimal_format to msgspec.json.Encoder and msgspec.msgpack.Encoder for custom Decimal encoding ({pr}978).
  • Support Literal[True] and Literal[False] types ({pr}1004).
  • Publish CPython 3.15 wheels, including freethreaded builds ({pr}1152).
  • Publish Linux riscv64 wheels ({pr}987).
  • Support the PyEmscripten (Pyodide) platform ({pr}1083).
  • Fix handling of PEP 695 type parameter syntax (class Foo[T]) and of types.GenericAlias instances in type annotations ({pr}962).
  • Fix NameError when creating a Struct with an unquoted forward reference on Python 3.14 ({issue}1165).
  • Fix a crash on incorrect typing.ClassVar annotations ({pr}1097).
  • Raise TypeError instead of crashing when a base class of a Struct type is a C extension type that has not been initialized with PyType_Ready yet ({pr}1199).
  • Fix an AttributeError when converting to a Struct type defined in a namespace without a __name__ ({pr}1072).
  • Fix overriding an inherited field alias back to the field's own name ({pr}1133).
  • Raise ValidationError instead of SystemError when convert receives an out-of-range int for a float target ({pr}1162).
  • Report raw rather than the misleading any as the expected type when a non-Raw value is given for a Raw field in convert, and therefore in yaml.decode and toml.decode ({pr}1169).
  • Fix an empty expected-type name in validation errors for a required Raw field in a TypedDict, or a Raw field with a default_factory on a dataclass or an attrs class ({pr}1176).
  • Correct the error messages for out-of-range Meta length bounds ({pr}1172).
  • Fix a reference leak when decoding msgpack Ext payloads ({pr}1109).
  • Fix backing type declaration of Ext.code ({pr}1135).
  • Raise DecodeError instead of TypeError when a decoded msgpack map key is

... (truncated)

Commits
  • 6d3443f Fix a reference leak of a non-Struct base's type dict (#1199)
  • 2f0b50d Correct the reported signatures of several public callables (#1197)
  • 8a25471 Skip instance __dataclass_fields__ lookup for non-dataclass types (#1196)
  • 7930780 Fix reference leak when defining a Struct type (#1194)
  • 55f5cdd fix(msgpack): raise DecodeError for unhashable map keys (#1209)
  • b2d1b7a Reject gc=False on struct types with a weakref slot (#1207)
  • f2bbec5 Move the unreleased changes into the 0.22.0 changelog (#1211)
  • c23e150 Fix json schema defaults for set / bytearray default_factory fields (#1183)
  • fed9fc3 Skip recursive type alias test on Windows ARM64 with Python 3.12 (#1210)
  • e7552f0 Bump msgpack from 1.2.1 to 1.2.2 (#1202)
  • Additional commits viewable in compare view

Updates pydantic-core from 2.46.5 to 2.49.0

Commits

Updates python-dotenv from 1.2.3 to 1.2.4

Release notes

Sourced from python-dotenv's releases.

v1.2.4

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Changelog

Sourced from python-dotenv's changelog.

[1.2.4] - 2026-10-01

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Commits
  • a565c2c Bump version: 1.2.3 → 1.2.4
  • 4a7abd0 docs: add 1.2.4 release notes (#663, #698, #700)
  • f215c02 fix: dotenv get exits 0 for empty string values (#700)
  • 58f2d7c test: make test_run_with_command_flags portable and meaningful (#709)
  • e0310e5 fix: honor --no-override when expanding variables in dotenv run (#698)
  • a00cb2e docs: add CHANGELOG entry for #663 (fix #600)
  • f5485a6 fix: parse empty unquoted value with inline comment as empty string
  • See full diff in compare view

Updates sse-starlette from 3.4.11 to 3.5.0

Release notes

Sourced from sse-starlette's releases.

v3.5.0

Fixed

  • A stopped uvicorn server no longer cancels SSE streams of later servers in the same process (#211, regression since 3.1.1). Typical trigger: test suites starting a real server per test.

Behaviour change

  • AppStatus.should_exit is no longer set when sse-starlette detects uvicorn's own Server.should_exit (fallback path, e.g. uvicorn "module:app"). Streams still close on shutdown. If you read AppStatus.should_exit to detect shutdown, use shutdown_event instead.
  • A real SIGTERM/SIGINT still sets AppStatus.should_exit process-wide; see README "Testing" if your tests send real signals to an in-process server.

Upgrade note

  • If you called AppStatus.disable_automatic_graceful_drain() only to work around #211, remove it to get automatic stream draining back.

What's Changed

Full Changelog: sysid/sse-starlette@v3.4.11...v3.5.0

Commits
  • 1705b2d Bump version to 3.5.0
  • 16179fd Merge pull request #212 from sysid/fix/issue211
  • 3821353 fix(shutdown): re-resolve uvicorn server on every watcher poll
  • 6925c68 fix(tests): import httpx2 instead of removed httpx dependency
  • aa3b89e build(deps): bump starlette to 1.7.0 for anyio BlockingPortal deprecation
  • 329a72c build(deps): bump anyio, autobahn, setuptools for security advisories
  • d43a29f test(experimentation): assert consumer line counts in main thread
  • 96afe01 fix(shutdown): stop latching AppStatus.should_exit from uvicorn state
  • See full diff in compare view

Updates w3lib from 2.4.1 to 2.5.0

Changelog

Sourced from w3lib's changelog.

2.5.0 (2026-09-30)

New features:

  • Added support for Python 3.15 (#295).

  • Added :func:~w3lib.url.add_http_if_no_scheme, ported from Scrapy, which adds http as the default scheme to a URL that has none (#309).

  • w3lib.url.parse_qsl_to_bytes, :func:~w3lib.url.url_query_parameter, :func:~w3lib.url.add_or_replace_parameter, :func:~w3lib.url.add_or_replace_parameters and :func:~w3lib.url.canonicalize_url now accept a separator (or query_separator for :func:~w3lib.url.canonicalize_url) keyword argument, to support query strings that use a separator other than & (#167).

  • :func:~w3lib.html.get_base_url and :func:~w3lib.html.get_meta_refresh now accept a max_scan keyword argument, an upper bound on how much of the document they look at (#336).

  • Improved the performance of most :mod:w3lib.url functions, :func:~w3lib.url.safe_url_string in particular (#257), and of some :mod:w3lib.html functions (#256).

  • :func:~w3lib.html.get_base_url and :func:~w3lib.html.get_meta_refresh are now several times faster on typical pages, which have no <base> tag and no <meta> refresh tag (#331, #332, #334, #338).

Deprecations and removals:

  • The w3lib.util module is deprecated, and now emits a :exc:DeprecationWarning on import (#322).

  • The undocumented w3lib_replace codec error handler is no longer registered (#318).

Security and correctness fixes:

  • :func:~w3lib.url.safe_url_string, :func:~w3lib.url.canonicalize_url and w3lib.url.parse_url no longer disagree with how browsers and :mod:urllib.parse read a URL in the following cases, which could let a URL resolve to a different host or path than the one these functions reported:

    • \ is now treated like / in the authority and path of special-scheme URLs (#285).

    • An NFKC-normalized backslash in the host is now rejected, like other normalized authority delimiters already were (#280).

... (truncated)

Commits
  • 537c5d4 Bump version: 2.4.1 → 2.5.0
  • 1bc3dfc Release notes for 2.5.0 (#260)
  • 8c153f2 Merge pull request #353 from uchiha-bug-hunter/html-scanners-ascii-whitespace
  • 7caeccd End start tag names on [\s/>] instead of \b in remove_tags_with_content
  • 916476f match only ASCII whitespace in the html tag and refresh regexes
  • d5d5e4f Merge pull request #352 from scrapy/dot-segments-linear
  • fc3d1cb Make _remove_dot_segments() linear and skip ineligible URLs early.
  • 4d7db49 Find the URL delimiters with str.find() in _urlsplit(). (#351)
  • 9c1d9cb Benchmark URL functions on a long URL with a cold _urlsplit cache. (#350)
  • 0a98564 Merge pull request #349 from uchiha-bug-hunter/base-url-href-attribute
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-minor-patch group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.9` | `0.16.10` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.141.1` | `0.142.2` |
| [msgspec](https://github.com/msgspec/msgspec) | `0.21.1` | `0.22.0` |
| [pydantic-core](https://github.com/pydantic/pydantic) | `2.46.5` | `2.49.0` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.3` | `1.2.4` |
| [sse-starlette](https://github.com/sysid/sse-starlette) | `3.4.11` | `3.5.0` |
| [w3lib](https://github.com/scrapy/w3lib) | `2.4.1` | `2.5.0` |


Updates `ruff` from 0.16.9 to 0.16.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.9...0.16.10)

Updates `fastapi` from 0.141.1 to 0.142.2
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.141.1...0.142.2)

Updates `msgspec` from 0.21.1 to 0.22.0
- [Release notes](https://github.com/msgspec/msgspec/releases)
- [Changelog](https://github.com/msgspec/msgspec/blob/main/docs/changelog.md)
- [Commits](msgspec/msgspec@0.21.1...0.22.0)

Updates `pydantic-core` from 2.46.5 to 2.49.0
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/main/HISTORY.md)
- [Commits](https://github.com/pydantic/pydantic/commits)

Updates `python-dotenv` from 1.2.3 to 1.2.4
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.3...v1.2.4)

Updates `sse-starlette` from 3.4.11 to 3.5.0
- [Release notes](https://github.com/sysid/sse-starlette/releases)
- [Commits](sysid/sse-starlette@v3.4.11...v3.5.0)

Updates `w3lib` from 2.4.1 to 2.5.0
- [Release notes](https://github.com/scrapy/w3lib/releases)
- [Changelog](https://github.com/scrapy/w3lib/blob/master/NEWS)
- [Commits](scrapy/w3lib@v2.4.1...v2.5.0)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: fastapi
  dependency-version: 0.142.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: msgspec
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: pydantic-core
  dependency-version: 2.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: python-dotenv
  dependency-version: 1.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: sse-starlette
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: w3lib
  dependency-version: 2.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 5, 2026
@tunjayoff

Copy link
Copy Markdown
Owner

Superseded by #148: same updates, but pydantic-core stays at 2.46.5 (pydantic 2.13.5 requires exactly that version, so this PR could not be installed) and opentelemetry-api 1.45.0, the new dependency of fastapi 0.142, is pinned.

@tunjayoff tunjayoff closed this Oct 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/pip/python-minor-patch-b144a6d27a branch October 6, 2026 15:50
tunjayoff added a commit that referenced this pull request Oct 6, 2026
chore(deps): python minor/patch group with pydantic-core and opentelemetry-api pins [supersedes #144]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant