3754 Commits
Author SHA1 Message Date
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>John Kennedyopen-swe[bot] <open-swe@users.noreply.github.com>
157a06dda9 chore(deps-dev): bump the minor-and-patch group across 1 directory with 5 updates (#9155)
Bumps the minor-and-patch group with 5 updates in the /libs/langgraph
directory:

| Package | From | To |
| --- | --- | --- |
| [langchain-core](https://github.com/langchain-ai/langchain) | `1.6.1`
| `1.6.5` |
| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` |
`3.16.0` |
| [syrupy](https://github.com/syrupy-project/syrupy) | `6.0.0` | `6.1.1`
|
| [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.9` |
| [ty](https://github.com/astral-sh/ty) | `0.0.75` | `0.0.84` |


Updates `langchain-core` from 1.6.1 to 1.6.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchain/releases">langchain-core's
releases</a>.</em></p>
<blockquote>
<h2>langchain-core==1.6.5</h2>
<p>Changes since langchain-core==1.6.4</p>
<p>release(core): 1.6.5 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>)
fix(core): abbreviate long tool IDs in XML buffer strings (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</p>
<h2>langchain-core==1.6.4</h2>
<p>Changes since langchain-core==1.6.3</p>
<p>release(core): 1.6.4 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40718">#40718</a>)
chore(core): deprecate chat message history (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40711">#40711</a>)
chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40634">#40634</a>)
chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40574">#40574</a>)</p>
<h2>langchain-core==1.6.3</h2>
<p>Changes since langchain-core==1.6.2</p>
<p>release(core): 1.6.3 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40407">#40407</a>)
feat(core): Allow model name and provider tracing metadata override
based on gateway response (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40406">#40406</a>)
test(core): cover the deprecated <code>.text()</code> access path (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40243">#40243</a>)
docs(core): remove stale Args/Raises entries from
FileCallbackHandler._write and ChatGeneration.set_text (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40211">#40211</a>)</p>
<h2>langchain-core==1.6.2</h2>
<p>Changes since langchain-core==1.6.1</p>
<p>release(core): 1.6.2 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40209">#40209</a>)
feat(openai): support async tools (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40208">#40208</a>)
chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40150">#40150</a>)
chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40113">#40113</a>)
fix(core): avoid mutation in google-genai standard content (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40023">#40023</a>)
fix(core): avoid mutation in bedrock converse standard content (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40022">#40022</a>)</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchain/commit/c5ab14d42a3e22865c9def909de0b11d70b0bbf0"><code>c5ab14d</code></a>
release(core): 1.6.5 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/5704d9d4813f8c0527f04e2662cf313e1350f96f"><code>5704d9d</code></a>
chore(model-profiles): refresh model profile data (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40804">#40804</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/7622d3dce760ac4be6d9aef4c653277e06064aea"><code>7622d3d</code></a>
release(openai): 1.6.6 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40800">#40800</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/2dd956b8add667dac4f97605ae441d75b8ae228e"><code>2dd956b</code></a>
docs(infra): fix AGENTS.md root setup guidance and package doc accuracy
(<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40794">#40794</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/49f4b4016b82513c3dc1623bf3daa10453861621"><code>49f4b40</code></a>
fix(openai): raise on error events in stream path (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40791">#40791</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/19cadaa1a1e0cac71f3148e2f18b414dcab17426"><code>19cadaa</code></a>
fix(core): abbreviate long tool IDs in XML buffer strings (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/798441e8b07e88e79db355db452cd9492f9628f2"><code>798441e</code></a>
chore(anthropic): fix integration test cassette (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40790">#40790</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/a476942bac3fe5e521676d0f53fabafcb7ba71b1"><code>a476942</code></a>
release(openai): 1.6.5 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40787">#40787</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/46c6bdf1b4e23028a5acc060d8b2797dbf200291"><code>46c6bdf</code></a>
release(anthropic): 1.7.4 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40786">#40786</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/290dabaff27ee379920d55d155d5055d2fe29cc8"><code>290daba</code></a>
fix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40785">#40785</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchain/compare/langchain-core==1.6.1...langchain-core==1.6.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `pytest-mock` from 3.15.1 to 3.16.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's
releases</a>.</em></p>
<blockquote>
<h2>v3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's
changelog</a>.</em></p>
<blockquote>
<h2>3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604)
&lt;https://github.com/pytest-dev/pytest-mock/pull/604&gt;</code>_:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611)
&lt;https://github.com/pytest-dev/pytest-mock/pull/611&gt;</code>_:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606)
&lt;https://github.com/pytest-dev/pytest-mock/pull/606&gt;</code>_:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547)
&lt;https://github.com/pytest-dev/pytest-mock/issues/547&gt;</code>_:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147)
&lt;https://github.com/pytest-dev/pytest-mock/issues/147&gt;</code>_:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a>
Release 3.16.0</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a>
Fix duplicate_iterators for async spies (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a>
Fix async assertion argument introspection (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a>
docs: import os in the opening usage example (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a>
Honour resetall() arguments for non-callable mocks (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `syrupy` from 6.0.0 to 6.1.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/syrupy-project/syrupy/releases">syrupy's
releases</a>.</em></p>
<blockquote>
<h2>v6.1.1</h2>
<blockquote>
<p><strong>Note:</strong> 6.1.0 was skipped due to a CI issue. Use
<strong>6.1.1</strong>.</p>
</blockquote>
<h3>Experimental <code>--snapshot-file-lock</code> for pytest-xdist</h3>
<p><code>--snapshot-update</code> under pytest-xdist can race when
multiple workers rewrite the same multi-entry amber (<code>.ambr</code>)
file, silently dropping snapshots (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1237">#1237</a>).</p>
<p>This release adds an <strong>experimental</strong> opt-in:</p>
<ul>
<li><code>--snapshot-file-lock</code> — exclusive file lock + atomic
replace around amber writes</li>
<li><code>--snapshot-file-lock-timeout</code> — max wait for the lock
(default <strong>60s</strong>)</li>
</ul>
<p>Same-machine workers only; not reliable across remote workers / NFS.
See <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1239">#1239</a>.</p>
<blockquote>
<p><strong>Callout for pytest-xdist users:</strong> please try
<code>--snapshot-file-lock</code> with <code>--snapshot-update</code>
and <a href="https://github.com/syrupy-project/syrupy/issues">open an
issue</a> if you hit problems. Locking is expected to become the default
in a future minor release.</p>
</blockquote>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/shipbyaeron"><code>@​shipbyaeron</code></a>
made their first contribution in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1236">syrupy-project/syrupy#1236</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.1">https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.1</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/syrupy-project/syrupy/blob/main/CHANGELOG.md">syrupy's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v6.1.1">v6.1.1</a>
(2026-09-13)</h2>
<h2>What's Changed</h2>
<ul>
<li>chore(deps): update dependency ruff to v0.16.4 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1225">syrupy-project/syrupy#1225</a></li>
<li>chore(deps): update dependency pytest-benchmark to v5.3.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1226">syrupy-project/syrupy#1226</a></li>
<li>chore(deps): update dependency ruff to v0.16.5 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1227">syrupy-project/syrupy#1227</a></li>
<li>chore(deps): update dependency pydantic to v2.13.5 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1228">syrupy-project/syrupy#1228</a></li>
<li>chore(deps): update dependency coverage to v7.16.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1229">syrupy-project/syrupy#1229</a></li>
<li>chore(deps): update dependency hypothesis to v6.166.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1230">syrupy-project/syrupy#1230</a></li>
<li>chore(deps): update dependency hypothesis to v6.167.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1231">syrupy-project/syrupy#1231</a></li>
<li>chore(deps): update dependency hypothesis to v6.167.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1232">syrupy-project/syrupy#1232</a></li>
<li>chore(deps): update actions/deploy-pages action to v5.0.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1234">syrupy-project/syrupy#1234</a></li>
<li>chore(deps): update dependency ruff to v0.16.6 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1235">syrupy-project/syrupy#1235</a></li>
<li>test: add coverage for read_snapshot_data_from_location returning
None by <a
href="https://github.com/shipbyaeron"><code>@​shipbyaeron</code></a> in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1236">syrupy-project/syrupy#1236</a></li>
<li>chore(deps): update dependency hypothesis to v6.168.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1238">syrupy-project/syrupy#1238</a></li>
<li>fix: opt-in file lock for concurrent amber writes under xdist by <a
href="https://github.com/noahnu"><code>@​noahnu</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1239">syrupy-project/syrupy#1239</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/shipbyaeron"><code>@​shipbyaeron</code></a>
made their first contribution in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1236">syrupy-project/syrupy#1236</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.1">https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.1</a></p>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v6.1.0">v6.1.0</a>
(2026-09-13)</h2>
<h2>What's Changed</h2>
<ul>
<li>chore(deps): update dependency ruff to v0.16.4 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1225">syrupy-project/syrupy#1225</a></li>
<li>chore(deps): update dependency pytest-benchmark to v5.3.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1226">syrupy-project/syrupy#1226</a></li>
<li>chore(deps): update dependency ruff to v0.16.5 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1227">syrupy-project/syrupy#1227</a></li>
<li>chore(deps): update dependency pydantic to v2.13.5 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1228">syrupy-project/syrupy#1228</a></li>
<li>chore(deps): update dependency coverage to v7.16.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1229">syrupy-project/syrupy#1229</a></li>
<li>chore(deps): update dependency hypothesis to v6.166.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1230">syrupy-project/syrupy#1230</a></li>
<li>chore(deps): update dependency hypothesis to v6.167.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1231">syrupy-project/syrupy#1231</a></li>
<li>chore(deps): update dependency hypothesis to v6.167.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1232">syrupy-project/syrupy#1232</a></li>
<li>chore(deps): update actions/deploy-pages action to v5.0.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1234">syrupy-project/syrupy#1234</a></li>
<li>chore(deps): update dependency ruff to v0.16.6 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1235">syrupy-project/syrupy#1235</a></li>
<li>test: add coverage for read_snapshot_data_from_location returning
None by <a
href="https://github.com/shipbyaeron"><code>@​shipbyaeron</code></a> in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1236">syrupy-project/syrupy#1236</a></li>
<li>chore(deps): update dependency hypothesis to v6.168.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1238">syrupy-project/syrupy#1238</a></li>
<li>fix: opt-in file lock for concurrent amber writes under xdist by <a
href="https://github.com/noahnu"><code>@​noahnu</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1239">syrupy-project/syrupy#1239</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/shipbyaeron"><code>@​shipbyaeron</code></a>
made their first contribution in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1236">syrupy-project/syrupy#1236</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.0">https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/2d251e73f1ebe47fe83ed71d835d3ae8580e8313"><code>2d251e7</code></a>
chore(release): 6.1.1 [skip ci]</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/9b64ec05752586c45d1097e9d25f9ee1d4e93219"><code>9b64ec0</code></a>
chore(release): 6.1.0 [skip ci]</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/5b4256eac8720075f25b0fa8491f75948001b983"><code>5b4256e</code></a>
fix: opt-in file lock for concurrent amber writes under xdist (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1239">#1239</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/d4cb1513b5d2b1b18c3b407150db22d2d8604ddd"><code>d4cb151</code></a>
chore(deps): update dependency hypothesis to v6.168.0 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1238">#1238</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/16c4cb5b8785d89e49b8076a99f58d810e02fcce"><code>16c4cb5</code></a>
test: add coverage for read_snapshot_data_from_location returning None
(<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1236">#1236</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/2e1d3ba0d39a1d87735213a32de9dd9cdb929690"><code>2e1d3ba</code></a>
chore(deps): update dependency ruff to v0.16.6 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1235">#1235</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/fcc929d4deb2302f2d37e6511015ef43a0841bc2"><code>fcc929d</code></a>
chore(deps): update actions/deploy-pages action to v5.0.1 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1234">#1234</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/4f1bad75777ecc9d916a648dd3669b2844d08f7d"><code>4f1bad7</code></a>
chore(deps): update dependency hypothesis to v6.167.1 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1232">#1232</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/24eda28579f5761cbc64713ffcee41cc73602010"><code>24eda28</code></a>
chore(deps): update dependency hypothesis to v6.167.0 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1231">#1231</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/0d7e46f9431e07810da4ef90dbe861b85fbc8469"><code>0d7e46f</code></a>
chore(deps): update dependency hypothesis to v6.166.0 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1230">#1230</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.1">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.5 to 0.16.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>Install ruff 0.16.9</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh
| sh
</code></pre>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>0.16.8</h2>
<p>Released on 2026-09-16.</p>
<h3>Bug fixes</h3>
<ul>
<li>Visit functional <code>TypedDict</code> keyword arguments correctly
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li>
<li>[<code>flake8-simplify</code>] Detect nested <code>async with</code>
under sync parent (<code>SIM117</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li>
<li>[<code>flake8-simplify</code>] Preserve operand order in
<code>SIM109</code> fix (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a>
Bump version to 0.16.9 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a>
Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a>
Update dependency astral-sh/uv to v0.12.18 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a>
[<code>flake8-comprehensions</code>] Document <code>map</code>/generator
exception behavior (<code>C417</code>...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a>
Use <code>target</code> form in <code>rooster.version_files</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a>
[ty] Prefer existing @ paths over response files in Ruff and ty (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a>
ci(github): update version number in placeholder of issue template (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a>
[ty] Propagate outer type context through cast calls (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a>
[ty] Contain rendered code within Markdown fences (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a>
authorize ruff-pre-commit dispatch via OIDC (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `ty` from 0.0.75 to 0.0.84
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/releases">ty's
releases</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's
changelog</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a>
Bump version to 0.0.84 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a>
publish to astral-sh/versions via OIDC (<a
href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a>
use oidc issued token for docs publication (<a
href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a>
Update prek dependencies (<a
href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a>
Update docker/setup-buildx-action action to v4.3.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a>
Update astral-sh/setup-uv action to v10.2.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a>
Bump version to 0.0.83 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a>
Sync the ty security mirror (<a
href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a>
Grant the versions workflow repository read access (<a
href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a>
use scoped token for release workflow (<a
href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare
view</a></li>
</ul>
</details>
<br />

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <jkennedyvz@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-10-01 11:57:28 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>John Kennedyopen-swe[bot] <open-swe@users.noreply.github.com>
5204e60579 chore(deps-dev): bump the minor-and-patch group in /libs/checkpoint-sqlite with 3 updates (#9146)
Bumps the minor-and-patch group in /libs/checkpoint-sqlite with 3
updates: [pytest-mock](https://github.com/pytest-dev/pytest-mock),
[ruff](https://github.com/astral-sh/ruff) and
[ty](https://github.com/astral-sh/ty).

Updates `pytest-mock` from 3.15.1 to 3.16.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's
releases</a>.</em></p>
<blockquote>
<h2>v3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's
changelog</a>.</em></p>
<blockquote>
<h2>3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604)
&lt;https://github.com/pytest-dev/pytest-mock/pull/604&gt;</code>_:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611)
&lt;https://github.com/pytest-dev/pytest-mock/pull/611&gt;</code>_:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606)
&lt;https://github.com/pytest-dev/pytest-mock/pull/606&gt;</code>_:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547)
&lt;https://github.com/pytest-dev/pytest-mock/issues/547&gt;</code>_:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147)
&lt;https://github.com/pytest-dev/pytest-mock/issues/147&gt;</code>_:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a>
Release 3.16.0</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a>
Fix duplicate_iterators for async spies (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a>
Fix async assertion argument introspection (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a>
docs: import os in the opening usage example (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a>
Honour resetall() arguments for non-callable mocks (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.5 to 0.16.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>Install ruff 0.16.9</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh
| sh
</code></pre>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>0.16.8</h2>
<p>Released on 2026-09-16.</p>
<h3>Bug fixes</h3>
<ul>
<li>Visit functional <code>TypedDict</code> keyword arguments correctly
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li>
<li>[<code>flake8-simplify</code>] Detect nested <code>async with</code>
under sync parent (<code>SIM117</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li>
<li>[<code>flake8-simplify</code>] Preserve operand order in
<code>SIM109</code> fix (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a>
Bump version to 0.16.9 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a>
Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a>
Update dependency astral-sh/uv to v0.12.18 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a>
[<code>flake8-comprehensions</code>] Document <code>map</code>/generator
exception behavior (<code>C417</code>...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a>
Use <code>target</code> form in <code>rooster.version_files</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a>
[ty] Prefer existing @ paths over response files in Ruff and ty (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a>
ci(github): update version number in placeholder of issue template (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a>
[ty] Propagate outer type context through cast calls (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a>
[ty] Contain rendered code within Markdown fences (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a>
authorize ruff-pre-commit dispatch via OIDC (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `ty` from 0.0.75 to 0.0.84
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/releases">ty's
releases</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's
changelog</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a>
Bump version to 0.0.84 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a>
publish to astral-sh/versions via OIDC (<a
href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a>
use oidc issued token for docs publication (<a
href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a>
Update prek dependencies (<a
href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a>
Update docker/setup-buildx-action action to v4.3.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a>
Update astral-sh/setup-uv action to v10.2.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a>
Bump version to 0.0.83 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a>
Sync the ty security mirror (<a
href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a>
Grant the versions workflow repository read access (<a
href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a>
use scoped token for release workflow (<a
href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <jkennedyvz@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-10-01 11:54:00 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>John Kennedyopen-swe[bot] <open-swe@users.noreply.github.com>
2053f0b176 chore(deps-dev): bump the minor-and-patch group in /libs/checkpoint-conformance with 2 updates (#9145)
Bumps the minor-and-patch group in /libs/checkpoint-conformance with 2
updates: [ruff](https://github.com/astral-sh/ruff) and
[ty](https://github.com/astral-sh/ty).

Updates `ruff` from 0.16.5 to 0.16.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>Install ruff 0.16.9</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh
| sh
</code></pre>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>0.16.8</h2>
<p>Released on 2026-09-16.</p>
<h3>Bug fixes</h3>
<ul>
<li>Visit functional <code>TypedDict</code> keyword arguments correctly
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li>
<li>[<code>flake8-simplify</code>] Detect nested <code>async with</code>
under sync parent (<code>SIM117</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li>
<li>[<code>flake8-simplify</code>] Preserve operand order in
<code>SIM109</code> fix (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a>
Bump version to 0.16.9 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a>
Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a>
Update dependency astral-sh/uv to v0.12.18 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a>
[<code>flake8-comprehensions</code>] Document <code>map</code>/generator
exception behavior (<code>C417</code>...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a>
Use <code>target</code> form in <code>rooster.version_files</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a>
[ty] Prefer existing @ paths over response files in Ruff and ty (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a>
ci(github): update version number in placeholder of issue template (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a>
[ty] Propagate outer type context through cast calls (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a>
[ty] Contain rendered code within Markdown fences (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a>
authorize ruff-pre-commit dispatch via OIDC (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `ty` from 0.0.75 to 0.0.84
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/releases">ty's
releases</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's
changelog</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a>
Bump version to 0.0.84 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a>
publish to astral-sh/versions via OIDC (<a
href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a>
use oidc issued token for docs publication (<a
href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a>
Update prek dependencies (<a
href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a>
Update docker/setup-buildx-action action to v4.3.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a>
Update astral-sh/setup-uv action to v10.2.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a>
Bump version to 0.0.83 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a>
Sync the ty security mirror (<a
href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a>
Grant the versions workflow repository read access (<a
href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a>
use scoped token for release workflow (<a
href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <jkennedyvz@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-10-01 11:53:48 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>John Kennedyopen-swe[bot] <open-swe@users.noreply.github.com>
c4f55715ec chore(deps): bump the minor-and-patch group in /libs/sdk-py with 5 updates (#9149)
Bumps the minor-and-patch group in /libs/sdk-py with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [langchain-core](https://github.com/langchain-ai/langchain) | `1.6.1`
| `1.6.5` |
| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` |
`3.16.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.9` |
| [ty](https://github.com/astral-sh/ty) | `0.0.75` | `0.0.84` |
| [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` |

Updates `langchain-core` from 1.6.1 to 1.6.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchain/releases">langchain-core's
releases</a>.</em></p>
<blockquote>
<h2>langchain-core==1.6.5</h2>
<p>Changes since langchain-core==1.6.4</p>
<p>release(core): 1.6.5 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>)
fix(core): abbreviate long tool IDs in XML buffer strings (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</p>
<h2>langchain-core==1.6.4</h2>
<p>Changes since langchain-core==1.6.3</p>
<p>release(core): 1.6.4 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40718">#40718</a>)
chore(core): deprecate chat message history (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40711">#40711</a>)
chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40634">#40634</a>)
chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40574">#40574</a>)</p>
<h2>langchain-core==1.6.3</h2>
<p>Changes since langchain-core==1.6.2</p>
<p>release(core): 1.6.3 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40407">#40407</a>)
feat(core): Allow model name and provider tracing metadata override
based on gateway response (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40406">#40406</a>)
test(core): cover the deprecated <code>.text()</code> access path (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40243">#40243</a>)
docs(core): remove stale Args/Raises entries from
FileCallbackHandler._write and ChatGeneration.set_text (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40211">#40211</a>)</p>
<h2>langchain-core==1.6.2</h2>
<p>Changes since langchain-core==1.6.1</p>
<p>release(core): 1.6.2 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40209">#40209</a>)
feat(openai): support async tools (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40208">#40208</a>)
chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40150">#40150</a>)
chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40113">#40113</a>)
fix(core): avoid mutation in google-genai standard content (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40023">#40023</a>)
fix(core): avoid mutation in bedrock converse standard content (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40022">#40022</a>)</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchain/commit/c5ab14d42a3e22865c9def909de0b11d70b0bbf0"><code>c5ab14d</code></a>
release(core): 1.6.5 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/5704d9d4813f8c0527f04e2662cf313e1350f96f"><code>5704d9d</code></a>
chore(model-profiles): refresh model profile data (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40804">#40804</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/7622d3dce760ac4be6d9aef4c653277e06064aea"><code>7622d3d</code></a>
release(openai): 1.6.6 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40800">#40800</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/2dd956b8add667dac4f97605ae441d75b8ae228e"><code>2dd956b</code></a>
docs(infra): fix AGENTS.md root setup guidance and package doc accuracy
(<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40794">#40794</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/49f4b4016b82513c3dc1623bf3daa10453861621"><code>49f4b40</code></a>
fix(openai): raise on error events in stream path (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40791">#40791</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/19cadaa1a1e0cac71f3148e2f18b414dcab17426"><code>19cadaa</code></a>
fix(core): abbreviate long tool IDs in XML buffer strings (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/798441e8b07e88e79db355db452cd9492f9628f2"><code>798441e</code></a>
chore(anthropic): fix integration test cassette (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40790">#40790</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/a476942bac3fe5e521676d0f53fabafcb7ba71b1"><code>a476942</code></a>
release(openai): 1.6.5 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40787">#40787</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/46c6bdf1b4e23028a5acc060d8b2797dbf200291"><code>46c6bdf</code></a>
release(anthropic): 1.7.4 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40786">#40786</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/290dabaff27ee379920d55d155d5055d2fe29cc8"><code>290daba</code></a>
fix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40785">#40785</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchain/compare/langchain-core==1.6.1...langchain-core==1.6.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `pytest-mock` from 3.15.1 to 3.16.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's
releases</a>.</em></p>
<blockquote>
<h2>v3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's
changelog</a>.</em></p>
<blockquote>
<h2>3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604)
&lt;https://github.com/pytest-dev/pytest-mock/pull/604&gt;</code>_:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611)
&lt;https://github.com/pytest-dev/pytest-mock/pull/611&gt;</code>_:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606)
&lt;https://github.com/pytest-dev/pytest-mock/pull/606&gt;</code>_:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547)
&lt;https://github.com/pytest-dev/pytest-mock/issues/547&gt;</code>_:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147)
&lt;https://github.com/pytest-dev/pytest-mock/issues/147&gt;</code>_:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a>
Release 3.16.0</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a>
Fix duplicate_iterators for async spies (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a>
Fix async assertion argument introspection (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a>
docs: import os in the opening usage example (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a>
Honour resetall() arguments for non-callable mocks (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.5 to 0.16.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>Install ruff 0.16.9</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh
| sh
</code></pre>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>0.16.8</h2>
<p>Released on 2026-09-16.</p>
<h3>Bug fixes</h3>
<ul>
<li>Visit functional <code>TypedDict</code> keyword arguments correctly
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li>
<li>[<code>flake8-simplify</code>] Detect nested <code>async with</code>
under sync parent (<code>SIM117</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li>
<li>[<code>flake8-simplify</code>] Preserve operand order in
<code>SIM109</code> fix (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a>
Bump version to 0.16.9 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a>
Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a>
Update dependency astral-sh/uv to v0.12.18 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a>
[<code>flake8-comprehensions</code>] Document <code>map</code>/generator
exception behavior (<code>C417</code>...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a>
Use <code>target</code> form in <code>rooster.version_files</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a>
[ty] Prefer existing @ paths over response files in Ruff and ty (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a>
ci(github): update version number in placeholder of issue template (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a>
[ty] Propagate outer type context through cast calls (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a>
[ty] Contain rendered code within Markdown fences (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a>
authorize ruff-pre-commit dispatch via OIDC (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `ty` from 0.0.75 to 0.0.84
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/releases">ty's
releases</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's
changelog</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a>
Bump version to 0.0.84 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a>
publish to astral-sh/versions via OIDC (<a
href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a>
use oidc issued token for docs publication (<a
href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a>
Update prek dependencies (<a
href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a>
Update docker/setup-buildx-action action to v4.3.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a>
Update astral-sh/setup-uv action to v10.2.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a>
Bump version to 0.0.83 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a>
Sync the ty security mirror (<a
href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a>
Grant the versions workflow repository read access (<a
href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a>
use scoped token for release workflow (<a
href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare
view</a></li>
</ul>
</details>
<br />

Updates `starlette` from 1.6.0 to 1.7.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kludex/starlette/releases">starlette's
releases</a>.</em></p>
<blockquote>
<h2>Version 1.7.0</h2>
<p>This release adds experimental OpenTelemetry tracing, HTTP
<code>QUERY</code> support, and response trailers in
<code>TestClient</code>. Starlette now requires AnyIO 4.</p>
<blockquote>
<p>[!WARNING]
<code>OpenTelemetryMiddleware</code> is experimental. Its API and
emitted telemetry may change in minor releases without a deprecation
period.</p>
</blockquote>
<h2>Added</h2>
<ul>
<li>Add experimental <code>OpenTelemetryMiddleware</code> for HTTP
server spans, with URL exclusions and custom tracer providers <a
href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>,
<a
href="https://redirect.github.com/Kludex/starlette/pull/3463">#3463</a>,
and <a
href="https://redirect.github.com/Kludex/starlette/pull/3520">#3520</a>.</li>
<li>Expose the matched route through
<code>scope[&quot;route&quot;]</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>.</li>
<li>Support the <code>QUERY</code> HTTP method in
<code>HTTPEndpoint</code>, CORS, and OpenAPI 3.2 schema generation <a
href="https://redirect.github.com/Kludex/starlette/pull/3489">#3489</a>.</li>
<li>Capture HTTP response trailers in <code>TestClient</code> and expose
them through
<code>response.extensions[&quot;http.response.trailers&quot;]</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3563">#3563</a>.</li>
<li>Support partitioned cookies in <code>SessionMiddleware</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3510">#3510</a>.</li>
<li>Add <code>partitioned</code> to
<code>Response.delete_cookie()</code> on Python 3.14 and later <a
href="https://redirect.github.com/Kludex/starlette/pull/3376">#3376</a>.</li>
<li>Support IPv6 hosts in <code>TrustedHostMiddleware</code> and
<code>TestClient</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3471">#3471</a>.</li>
<li>Support Python 3.15 <a
href="https://redirect.github.com/Kludex/starlette/pull/3508">#3508</a>.</li>
</ul>
<h2>Changed</h2>
<ul>
<li>Require <code>anyio&gt;=4.0.0,&lt;5</code>, dropping support for
AnyIO 3 <a
href="https://redirect.github.com/Kludex/starlette/pull/3512">#3512</a>.</li>
<li>Raise <code>WebSocketDisconnected</code>, a
<code>RuntimeError</code> subclass, for disconnected WebSocket
operations <a
href="https://redirect.github.com/Kludex/starlette/pull/2767">#2767</a>.</li>
<li>Accept <code>Collection[str]</code> in <code>CORSMiddleware</code>
configuration annotations, including sets and frozensets <a
href="https://redirect.github.com/Kludex/starlette/pull/3518">#3518</a>.</li>
</ul>
<h2>Fixed</h2>
<ul>
<li>Run background tasks only after the response is sent when using
<code>BaseHTTPMiddleware</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3476">#3476</a>.</li>
<li>Return <code>400</code> for invalid multipart parser input <a
href="https://redirect.github.com/Kludex/starlette/pull/3492">#3492</a>.</li>
<li>Include <code>Vary: Origin</code> on all normal CORS responses and
vary preflight responses by all request headers that affect them <a
href="https://redirect.github.com/Kludex/starlette/pull/3516">#3516</a>
and <a
href="https://redirect.github.com/Kludex/starlette/pull/3517">#3517</a>.</li>
<li>Handle malformed <code>Host</code> headers and IPv6 authorities
consistently across URL construction, host routing, and redirect
middleware <a
href="https://redirect.github.com/Kludex/starlette/pull/3472">#3472</a>.</li>
<li>Ignore <code>Range</code> headers when <code>FileResponse</code> has
a status other than <code>200</code>, preserving its status and full
body <a
href="https://redirect.github.com/Kludex/starlette/pull/3568">#3568</a>.</li>
<li>Handle standalone <code>If-None-Match: *</code> in
<code>StaticFiles</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3201">#3201</a>.</li>
<li>Reject WebSocket requests to <code>StaticFiles</code> without
raising an assertion error <a
href="https://redirect.github.com/Kludex/starlette/pull/3532">#3532</a>.</li>
<li>Persist session mutations made with <code>popitem()</code> and
<code>|=</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3436">#3436</a>.</li>
<li>Handle empty and absent payloads in
<code>WebSocketEndpoint.decode()</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3372">#3372</a>.</li>
<li>Implement <code>identity</code> on <code>SimpleUser</code> and
<code>UnauthenticatedUser</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3271">#3271</a>.</li>
<li>Allow <code>HTTPException</code> to use non-standard status codes
without an explicit <code>detail</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3545">#3545</a>.</li>
<li>Avoid deprecated AnyIO imports in <code>TestClient</code> and add
explicit imports in <code>WSGIMiddleware</code> for AnyIO 4.15
compatibility <a
href="https://redirect.github.com/Kludex/starlette/pull/3498">#3498</a>
and <a
href="https://redirect.github.com/Kludex/starlette/pull/3501">#3501</a>.</li>
<li>Offload debug traceback rendering to a worker thread in
<code>ServerErrorMiddleware</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/2858">#2858</a>.</li>
</ul>
<p><strong>Full changelog:</strong> <a
href="https://github.com/Kludex/starlette/compare/1.6.0...1.7.0">1.6.0...1.7.0</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/Kludex/starlette/blob/main/docs/release-notes.md">starlette's
changelog</a>.</em></p>
<blockquote>
<h2>1.7.0 (September 23, 2026)</h2>
<p>This release adds experimental OpenTelemetry tracing and requires
AnyIO 4.</p>
<p>!!! warning &quot;OpenTelemetryMiddleware is experimental&quot;
Its API and emitted telemetry may change in minor releases without a
deprecation period
<a
href="https://redirect.github.com/Kludex/starlette/pull/3574">#3574</a>.</p>
<h4>Added</h4>
<ul>
<li>Add experimental <code>OpenTelemetryMiddleware</code> for HTTP
server spans, with URL exclusions and custom tracer providers <a
href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>,
<a
href="https://redirect.github.com/Kludex/starlette/pull/3463">#3463</a>,
and <a
href="https://redirect.github.com/Kludex/starlette/pull/3520">#3520</a>.</li>
<li>Expose the matched route through
<code>scope[&quot;route&quot;]</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>.</li>
<li>Support the <code>QUERY</code> HTTP method in
<code>HTTPEndpoint</code>, CORS, and OpenAPI 3.2 schema generation <a
href="https://redirect.github.com/Kludex/starlette/pull/3489">#3489</a>.</li>
<li>Capture HTTP response trailers in <code>TestClient</code> and expose
them through
<code>response.extensions[&quot;http.response.trailers&quot;]</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3563">#3563</a>.</li>
<li>Support partitioned cookies in <code>SessionMiddleware</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3510">#3510</a>.</li>
<li>Add <code>partitioned</code> to
<code>Response.delete_cookie()</code> on Python 3.14 and later <a
href="https://redirect.github.com/Kludex/starlette/pull/3376">#3376</a>.</li>
<li>Support IPv6 hosts in <code>TrustedHostMiddleware</code> and
<code>TestClient</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3471">#3471</a>.</li>
<li>Support Python 3.15 <a
href="https://redirect.github.com/Kludex/starlette/pull/3508">#3508</a>.</li>
</ul>
<h4>Changed</h4>
<ul>
<li>Require <code>anyio&gt;=4.0.0,&lt;5</code>, dropping support for
AnyIO 3 <a
href="https://redirect.github.com/Kludex/starlette/pull/3512">#3512</a>.</li>
<li>Raise <code>WebSocketDisconnected</code>, a
<code>RuntimeError</code> subclass, for disconnected WebSocket
operations <a
href="https://redirect.github.com/Kludex/starlette/pull/2767">#2767</a>.</li>
<li>Accept <code>Collection[str]</code> in <code>CORSMiddleware</code>
configuration annotations, including sets and frozensets <a
href="https://redirect.github.com/Kludex/starlette/pull/3518">#3518</a>.</li>
</ul>
<h4>Fixed</h4>
<ul>
<li>Run background tasks only after the response is sent when using
<code>BaseHTTPMiddleware</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3476">#3476</a>.</li>
<li>Return <code>400</code> for invalid multipart parser input <a
href="https://redirect.github.com/Kludex/starlette/pull/3492">#3492</a>.</li>
<li>Include <code>Vary: Origin</code> on all normal CORS responses and
vary preflight responses by all request headers that affect them <a
href="https://redirect.github.com/Kludex/starlette/pull/3516">#3516</a>
and <a
href="https://redirect.github.com/Kludex/starlette/pull/3517">#3517</a>.</li>
<li>Handle malformed <code>Host</code> headers and IPv6 authorities
consistently across URL construction, host routing, and redirect
middleware <a
href="https://redirect.github.com/Kludex/starlette/pull/3472">#3472</a>.</li>
<li>Ignore <code>Range</code> headers when <code>FileResponse</code> has
a status other than <code>200</code>, preserving its status and full
body <a
href="https://redirect.github.com/Kludex/starlette/pull/3568">#3568</a>.</li>
<li>Handle standalone <code>If-None-Match: *</code> in
<code>StaticFiles</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3201">#3201</a>.</li>
<li>Reject WebSocket requests to <code>StaticFiles</code> without
raising an assertion error <a
href="https://redirect.github.com/Kludex/starlette/pull/3532">#3532</a>.</li>
<li>Persist session mutations made with <code>popitem()</code> and
<code>|=</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3436">#3436</a>.</li>
<li>Handle empty and absent payloads in
<code>WebSocketEndpoint.decode()</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3372">#3372</a>.</li>
<li>Implement <code>identity</code> on <code>SimpleUser</code> and
<code>UnauthenticatedUser</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3271">#3271</a>.</li>
<li>Allow <code>HTTPException</code> to use non-standard status codes
without an explicit <code>detail</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/3545">#3545</a>.</li>
<li>Avoid deprecated AnyIO imports in <code>TestClient</code> and add
explicit imports in <code>WSGIMiddleware</code> for AnyIO 4.15
compatibility <a
href="https://redirect.github.com/Kludex/starlette/pull/3498">#3498</a>
and <a
href="https://redirect.github.com/Kludex/starlette/pull/3501">#3501</a>.</li>
<li>Offload debug traceback rendering to a worker thread in
<code>ServerErrorMiddleware</code> <a
href="https://redirect.github.com/Kludex/starlette/pull/2858">#2858</a>.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/Kludex/starlette/commit/2269e9a08c1edd3dfdea865710f40f84c857b623"><code>2269e9a</code></a>
Version 1.7.0 (<a
href="https://redirect.github.com/Kludex/starlette/issues/3575">#3575</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/4fe55eb2649e74fb01472bad9a1bc54fc3495904"><code>4fe55eb</code></a>
Preserve <code>FileResponse</code> status for range requests (<a
href="https://redirect.github.com/Kludex/starlette/issues/3568">#3568</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/1f08daf1627c866a4244418ea6da673d272fc8bb"><code>1f08daf</code></a>
Mark OpenTelemetryMiddleware as experimental (<a
href="https://redirect.github.com/Kludex/starlette/issues/3574">#3574</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/57de5fa9c2a98089a78d32d560e9b23e62560d5f"><code>57de5fa</code></a>
Support HTTP response trailers in TestClient (<a
href="https://redirect.github.com/Kludex/starlette/issues/3563">#3563</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/03f12b7fcf0a3e21a8da648ca0900c79472e9efe"><code>03f12b7</code></a>
Allow HTTPException to use non-standard status codes (<a
href="https://redirect.github.com/Kludex/starlette/issues/3545">#3545</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/76fd00f1e293990ea41555946a6b0f58901eaca1"><code>76fd00f</code></a>
Reject <code>WebSocket</code> requests to <code>StaticFiles</code> (<a
href="https://redirect.github.com/Kludex/starlette/issues/3532">#3532</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/f03f65c2f98c592773d691b4d309c68b83e568ef"><code>f03f65c</code></a>
docs: fix 'its not available' and 'This ensure' wording (<a
href="https://redirect.github.com/Kludex/starlette/issues/3526">#3526</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/485aca4e797d41849743cf73d5adcfd699695467"><code>485aca4</code></a>
docs: the test client is built on httpx2, not httpx (<a
href="https://redirect.github.com/Kludex/starlette/issues/3525">#3525</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/fd662b17b9cc41dca32a03509305619643f2dd61"><code>fd662b1</code></a>
Implement <code>identity</code> on <code>SimpleUser</code> and
<code>UnauthenticatedUser</code> (<a
href="https://redirect.github.com/Kludex/starlette/issues/3271">#3271</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/41db6a707f2636526847dbda0e5610e732e6b4fc"><code>41db6a7</code></a>
Stabilize CodSpeed upload buffer allocations (<a
href="https://redirect.github.com/Kludex/starlette/issues/3524">#3524</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/Kludex/starlette/compare/1.6.0...1.7.0">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <jkennedyvz@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-10-01 11:28:27 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
b36b1d58a8 chore(deps): bump tornado from 6.5.8 to 6.5.9 in /libs/langgraph (#9160)
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.8 to
6.5.9.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's
changelog</a>.</em></p>
<blockquote>
<h1>Release notes</h1>
<p>.. toctree::
:maxdepth: 2</p>
<p>releases/v6.6.0
releases/v6.5.10
releases/v6.5.9
releases/v6.5.8
releases/v6.5.7
releases/v6.5.6
releases/v6.5.5
releases/v6.5.4
releases/v6.5.3
releases/v6.5.2
releases/v6.5.1
releases/v6.5.0
releases/v6.4.2
releases/v6.4.1
releases/v6.4.0
releases/v6.3.3
releases/v6.3.2
releases/v6.3.1
releases/v6.3.0
releases/v6.2.0
releases/v6.1.0
releases/v6.0.4
releases/v6.0.3
releases/v6.0.2
releases/v6.0.1
releases/v6.0.0
releases/v5.1.1
releases/v5.1.0
releases/v5.0.2
releases/v5.0.1
releases/v5.0.0
releases/v4.5.3
releases/v4.5.2
releases/v4.5.1
releases/v4.5.0
releases/v4.4.3
releases/v4.4.2
releases/v4.4.1
releases/v4.4.0
releases/v4.3.0
releases/v4.2.1
releases/v4.2.0
releases/v4.1.0
releases/v4.0.2</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/tornadoweb/tornado/commit/75ef8b1cfa0e658aceb17c5a810ad1c74dc69bc7"><code>75ef8b1</code></a>
Merge pull request <a
href="https://redirect.github.com/tornadoweb/tornado/issues/3719">#3719</a>
from bdarnell/fixes-659</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/3590cb4566d363331c294cfa63c5035ae2c32c87"><code>3590cb4</code></a>
test: Hardcode SimpleAsyncHTTPClient in HTTP1xxLimitTestCase</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/9fc5d6d9fff435066836d165d0f1f6ebb067fb9e"><code>9fc5d6d</code></a>
test: Make tracemalloc optional in httpclient_test</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/555a2ee9a20275d6dfde879977fce58d02e7898a"><code>555a2ee</code></a>
iostream: Treat connection resets as a clean close in
read_until_close</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/3ba622f2ecb75226a8e64d4ee96b7045fc4c8a64"><code>3ba622f</code></a>
Release notes and version bump for 6.5.9</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/41eea68aba54e8ecaafc1b777dc5c104d289a290"><code>41eea68</code></a>
test: Fix some test issues only found by our custom tox config</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/ab1a778defaccd0dde9c1c419578e3a1777a9eeb"><code>ab1a778</code></a>
Merge remote-tracking branch
'bdarnell/claude/asynchttpclient-streaming-memor...</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32"><code>437ab5f</code></a>
web: Do not follow symlinks out of the static directory</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/03945136ea9746eccf61caf88edae39642e59c93"><code>0394513</code></a>
httputil: Apply the argument count limit to query strings</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/b798f8322a15ba8b6ef725d698d1037024139714"><code>b798f83</code></a>
http1connection: Return after reading the response that follows a
1xx</li>
<li>Additional commits viewable in <a
href="https://github.com/tornadoweb/tornado/compare/v6.5.8...v6.5.9">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=tornado&package-manager=uv&previous-version=6.5.8&new-version=6.5.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 09:00:10 +00:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
9829ef9e64 chore(deps): bump virtualenv from 21.2.4 to 21.7.12 in /libs/cli (#9159)
Bumps [virtualenv](https://github.com/pypa/virtualenv) from 21.2.4 to
21.7.12.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pypa/virtualenv/releases">virtualenv's
releases</a>.</em></p>
<blockquote>
<h2>21.7.12</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>🔧 chore(changelog): drop dead CVE-2026-24049 fragment by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3249">pypa/virtualenv#3249</a></li>
<li>🐛 fix(activation): escape batch quote() against injection by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3250">pypa/virtualenv#3250</a></li>
<li>🐛 fix(seed): verify downloaded wheel digests by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3251">pypa/virtualenv#3251</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/pypa/virtualenv/compare/21.7.11...21.7.12">https://github.com/pypa/virtualenv/compare/21.7.11...21.7.12</a></p>
<h2>21.7.11</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>Add OpenSSF Scorecard workflow by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3238">pypa/virtualenv#3238</a></li>
<li>Document AI-assisted contributions and licensing policy by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3239">pypa/virtualenv#3239</a></li>
<li>👷 ci(release): attest and sign release provenance by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3242">pypa/virtualenv#3242</a></li>
<li>👷 ci: harden Scorecard-scored checks in CI by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3241">pypa/virtualenv#3241</a></li>
<li>🐛 fix(ci): parallelize graalpy tests, recover crashed workers by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3240">pypa/virtualenv#3240</a></li>
<li>🐛 fix(ci): mark real-shell activation tests as slow by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3243">pypa/virtualenv#3243</a></li>
<li>👷 ci: run macOS jobs on macos-26 by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3244">pypa/virtualenv#3244</a></li>
<li>🐛 fix(activation): undo a live activation before activate.bat saves
values by <a
href="https://github.com/darrenhuai"><code>@​darrenhuai</code></a> in <a
href="https://redirect.github.com/pypa/virtualenv/pull/3245">pypa/virtualenv#3245</a></li>
<li>🐛 fix(create): keep pyvenv.cfg values on a single line by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3247">pypa/virtualenv#3247</a></li>
<li>🔧 chore(test): add opt-in Atheris fuzz harness by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3246">pypa/virtualenv#3246</a></li>
<li>📝 docs(readme): add OpenSSF Best Practices badge by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/pypa/virtualenv/pull/3248">pypa/virtualenv#3248</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/pypa/virtualenv/compare/21.7.10...21.7.11">https://github.com/pypa/virtualenv/compare/21.7.10...21.7.11</a></p>
<h2>21.7.10</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>🔧 chore: check spelling with typos in pre-commit by <a
href="https://github.com/even-even"><code>@​even-even</code></a> in <a
href="https://redirect.github.com/pypa/virtualenv/pull/3235">pypa/virtualenv#3235</a></li>
<li>🐛 fix(activation): keep and restore the user's TCL_LIBRARY and
TK_LIBRARY by <a
href="https://github.com/darrenhuai"><code>@​darrenhuai</code></a> in <a
href="https://redirect.github.com/pypa/virtualenv/pull/3234">pypa/virtualenv#3234</a></li>
<li>🐛 fix(create): skip blank and comment lines in pyvenv.cfg by <a
href="https://github.com/r3wretrhy"><code>@​r3wretrhy</code></a> in <a
href="https://redirect.github.com/pypa/virtualenv/pull/3232">pypa/virtualenv#3232</a></li>
<li>🐛 fix(activation): restore PKG_CONFIG_PATH that was not set before
by <a href="https://github.com/darrenhuai"><code>@​darrenhuai</code></a>
in <a
href="https://redirect.github.com/pypa/virtualenv/pull/3233">pypa/virtualenv#3233</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/r3wretrhy"><code>@​r3wretrhy</code></a>
made their first contribution in <a
href="https://redirect.github.com/pypa/virtualenv/pull/3232">pypa/virtualenv#3232</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/pypa/virtualenv/compare/21.7.9...21.7.10">https://github.com/pypa/virtualenv/compare/21.7.9...21.7.10</a></p>
<h2>21.7.9</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>fix(test): EncodingWarning: 'encoding' argument not specified by <a
href="https://github.com/even-even"><code>@​even-even</code></a> in <a
href="https://redirect.github.com/pypa/virtualenv/pull/3228">pypa/virtualenv#3228</a></li>
<li>🐛 fix(config): ignore a config file that fails to parse instead of
crashing by <a
href="https://github.com/darrenhuai"><code>@​darrenhuai</code></a> in <a
href="https://redirect.github.com/pypa/virtualenv/pull/3230">pypa/virtualenv#3230</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst">virtualenv's
changelog</a>.</em></p>
<blockquote>
<h1>Bugfixes - 21.7.12</h1>
<ul>
<li>Fix <code>activate.bat</code> running arbitrary commands from a
crafted <code>--prompt</code>, <code>VIRTUALENV_PROMPT</code>, or config
file
value. (:issue:<code>3250</code>)</li>
<li>Verify a downloaded seed wheel's sha256 against PyPI before seeding
it into a virtual environment, skipped when a
custom pip index is configured. (:issue:<code>3251</code>)</li>
</ul>
<hr />
<p>v21.7.11 (2026-09-17)</p>
<hr />
<h1>Bugfixes - 21.7.11</h1>
<ul>
<li>Running <code>activate.bat</code> again before
<code>deactivate</code> no longer makes <code>deactivate</code> leave
the environment's
<code>PKG_CONFIG_PATH</code>, <code>TCL_LIBRARY</code> and
<code>TK_LIBRARY</code> behind, or lose values the user had set before
the first
activation - by :user:<code>darrenhuai</code>.
(:issue:<code>3245</code>)</li>
<li>Write <code>pyvenv.cfg</code> values on a single line, so a prompt
carrying a line boundary can no longer inject configuration.
<code>--prompt</code>, the <code>VIRTUALENV_PROMPT</code> environment
variable and the config file all set the prompt, and
<code>pyvenv.cfg</code> has no escape syntax, so a newline, a carriage
return, or any other boundary <code>str.splitlines</code>
recognizes, such as <code>U+2028</code>, started a new configuration
line. Reading the file back picked up those lines as keys,
and since the last value for a key wins, they replaced anything written
earlier, including <code>home</code>. (:issue:<code>3247</code>)</li>
</ul>
<h1>Improved Documentation - 21.7.11</h1>
<ul>
<li>Document the policy for AI-assisted contributions and the licensing
rules for dependencies. (:issue:<code>3239</code>)</li>
</ul>
<h1>Misc - 21.7.11</h1>
<ul>
<li>:issue:<code>3238</code>, :issue:<code>3240</code>,
:issue:<code>3241</code>, :issue:<code>3242</code>,
:issue:<code>3243</code>, :issue:<code>3244</code>,
:issue:<code>3246</code></li>
</ul>
<hr />
<p>v21.7.10 (2026-09-15)</p>
<hr />
<h1>Bugfixes - 21.7.10</h1>
<ul>
<li>Skip blank lines, <code>#</code> comments and lines without
<code>=</code> in <code>pyvenv.cfg</code> instead of raising
<code>ValueError</code> - by
:user:<code>r3wretrhy</code>. (:issue:<code>3232</code>)</li>
<li><code>deactivate</code> in bash, fish and PowerShell unsets
<code>PKG_CONFIG_PATH</code> when activation found it unset, instead of
keeping the environment's <code>lib/pkgconfig</code>. csh activation no
longer drops a <code>PKG_CONFIG_PATH</code> the user had set.
Activation in batch, fish, nushell and PowerShell no longer adds a
trailing separator when <code>PKG_CONFIG_PATH</code> is
unset, and PowerShell and nushell build the value with the host's path
separators - by :user:<code>darrenhuai</code>.
(:issue:<code>3233</code>)</li>
<li>Activation in bash, csh, fish and PowerShell keeps the user's
<code>TCL_LIBRARY</code> and <code>TK_LIBRARY</code>, and
<code>deactivate</code>
restores them. csh and PowerShell removed both variables on every
activation, fish did so when the interpreter has</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pypa/virtualenv/commit/9666b42afc8d6103e765d77958d7bae782f5406e"><code>9666b42</code></a>
release 21.7.12</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d"><code>a01ed3e</code></a>
🐛 fix(seed): verify downloaded wheel digests (<a
href="https://redirect.github.com/pypa/virtualenv/issues/3251">#3251</a>)</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/d721ff140ce4afdc2a9b76751e4584e25d9fbea6"><code>d721ff1</code></a>
🐛 fix(activation): escape batch quote() against injection (<a
href="https://redirect.github.com/pypa/virtualenv/issues/3250">#3250</a>)</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/087a2ef8bd3aa15b562a3558b1068f603e50f77a"><code>087a2ef</code></a>
🔧 chore(changelog): drop dead CVE-2026-24049 fragment (<a
href="https://redirect.github.com/pypa/virtualenv/issues/3249">#3249</a>)</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/73e352ae02bfa52ffc0e307b04f1b6a7168c4eb0"><code>73e352a</code></a>
release 21.7.11</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/68ee5a3f27ca44912af9bd73c4c87e41978a8c08"><code>68ee5a3</code></a>
📝 docs(readme): add OpenSSF Best Practices badge (<a
href="https://redirect.github.com/pypa/virtualenv/issues/3248">#3248</a>)</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/787d1c9a0843310200f37861e6b2744a7d1e5364"><code>787d1c9</code></a>
🔧 chore(test): add opt-in Atheris fuzz harness (<a
href="https://redirect.github.com/pypa/virtualenv/issues/3246">#3246</a>)</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140"><code>a30f995</code></a>
🐛 fix(create): keep pyvenv.cfg values on a single line (<a
href="https://redirect.github.com/pypa/virtualenv/issues/3247">#3247</a>)</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/469dd28e659f7cd3e7d8cdb3f1245c125d32e817"><code>469dd28</code></a>
🐛 fix(activation): undo a live activation before activate.bat saves
values (#...</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/a045a14c76dcb71d1811fe57aa6c5f4fad2357cd"><code>a045a14</code></a>
👷 ci: run macOS jobs on macos-26 (<a
href="https://redirect.github.com/pypa/virtualenv/issues/3244">#3244</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pypa/virtualenv/compare/21.2.4...21.7.12">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=virtualenv&package-manager=uv&previous-version=21.2.4&new-version=21.7.12)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 08:59:43 +00:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
b1765f3d0f chore(deps): bump the minor-and-patch group in /libs/checkpoint-postgres with 6 updates (#9147)
Bumps the minor-and-patch group in /libs/checkpoint-postgres with 6
updates:

| Package | From | To |
| --- | --- | --- |
| [psycopg](https://github.com/psycopg/psycopg) | `3.3.4` | `3.3.6` |
| [psycopg-pool](https://github.com/psycopg/psycopg) | `3.3.1` | `3.3.3`
|
| [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.1` |
| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` |
`3.16.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.9` |
| [ty](https://github.com/astral-sh/ty) | `0.0.75` | `0.0.84` |

Updates `psycopg` from 3.3.4 to 3.3.6
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/psycopg/psycopg/blob/master/docs/news.rst">psycopg's
changelog</a>.</em></p>
<blockquote>
<p>.. currentmodule:: psycopg</p>
<p>.. index::
single: Release notes
single: News</p>
<h1><code>psycopg</code> release notes</h1>
<h2>Future releases</h2>
<p>Psycopg 3.3.7 (unreleased)
^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Fix segfault fetching arrays of strings or timestamps after closing
the
connection
(🎫<code>[#1428](https://github.com/psycopg/psycopg/issues/1428)</code>).</li>
</ul>
<h2>Current release</h2>
<p>Psycopg 3.3.6
^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.15
(🎫<code>[#1245](https://github.com/psycopg/psycopg/issues/1245)</code>).</li>
<li>Improve performance of async queries by reducing the overhead of the
<code>!wait_async()</code> function
(🎫<code>[#1331](https://github.com/psycopg/psycopg/issues/1331)</code>).</li>
<li>Don't wait forever for a query to terminate after interrupting it,
for
instance if the server is unresponsive. The fix requires libpq 17 or
newer

(🎫<code>[#1371](https://github.com/psycopg/psycopg/issues/1371)</code>).</li>
<li>Cancel a running query upon receiving <code>!SystemExit</code>
(🎫<code>[#1384](https://github.com/psycopg/psycopg/issues/1384)</code>).</li>
<li>Report <code>!None</code> instead of <code>65535</code> as the
<code>Column.precision</code> of an
:sql:<code>interval</code> column declared with a fields restriction and
no explicit
precision, such as e.g. :sql:<code>interval day to second</code>
(🎫<code>[#1397](https://github.com/psycopg/psycopg/issues/1397)</code>).</li>
<li>Fix dumping of nested subclasses of lists as arrays
(🎫<code>[#1398](https://github.com/psycopg/psycopg/issues/1398)</code>).</li>
<li>Discard prepared statements upon :sql:<code>DEALLOCATE ALL</code>
(🎫<code>[#1408](https://github.com/psycopg/psycopg/issues/1408)</code>).</li>
<li>Better guards dumping large Python <code>!int</code> to binary
numeric
(🎫<code>[#1414](https://github.com/psycopg/psycopg/issues/1414)</code>).</li>
</ul>
<p>Psycopg 3.3.5
^^^^^^^^^^^^^</p>
<ul>
<li>Discard prepared statements upon :sql:<code>ALTER *</code> or
<code>DISCARD *</code>

(🎫<code>[#1307](https://github.com/psycopg/psycopg/issues/1307)</code>).</li>
<li>Fix <code>!ProgrammingError</code> when dumping
non-<code>!None</code> values with
no <code>!NoneType</code> dumper registered in python implementation
(🎫<code>[#1325](https://github.com/psycopg/psycopg/issues/1325)</code>).</li>
<li>Fix <code>!wait_selector</code> wait function to not raise
<code>!KeyError</code>

(🎫<code>[#1327](https://github.com/psycopg/psycopg/issues/1327)</code>).</li>
<li>Fix <code>!DataError</code> messages leaking the literal
<code>{...}</code> placeholder instead</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/psycopg/psycopg/commit/a67654d1e7afbf9b3a619557838f62de1c790e7c"><code>a67654d</code></a>
chore: bump psycopg package version to 3.3.6</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/443814b3b111ac678a39fd523c1a826266fb69b5"><code>443814b</code></a>
Merge pull request <a
href="https://redirect.github.com/psycopg/psycopg/issues/1416">#1416</a>
from dvarrazzo/wait-async-perf</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/42966e9ebbda3b9c69b15c5588543c15f2aae5dd"><code>42966e9</code></a>
test: add helpful comments to some tests</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/5e8797f0c8003d8cd12a1e5c13f05fbb94c1c1d2"><code>5e8797f</code></a>
test: add reasonable connect_timeout to most tests</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/c81ba62442dfbd69e207d6914e6ae2aa27e56886"><code>c81ba62</code></a>
perf: reduce the overhead of wait_async()</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/d2bbfe4e2b1e36a20e72a18097f35a3db27296e3"><code>d2bbfe4</code></a>
refactor: use get_running_loop() in the async wait functions</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/2b1484a550e01c88fda077099678f0abb9217ecb"><code>2b1484a</code></a>
test: add a script to measure the async wait functions</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/573cf4aa70d8fdefc9d5f3eb69d5419cd6d3cd51"><code>573cf4a</code></a>
test: fix incorrect wait timing test</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/2b68990874175b8d97269218d4963b2d5c8656f3"><code>2b68990</code></a>
refactor: drop leftovers of waiting with inf interval in
wait_conn_async</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/60765dd8fc7d8df03cd75efcff485bfb3c83a0ed"><code>60765dd</code></a>
Merge pull request <a
href="https://redirect.github.com/psycopg/psycopg/issues/1414">#1414</a>
from dvarrazzo/fix-decimal-overflow</li>
<li>Additional commits viewable in <a
href="https://github.com/psycopg/psycopg/compare/3.3.4...3.3.6">compare
view</a></li>
</ul>
</details>
<br />

Updates `psycopg-pool` from 3.3.1 to 3.3.3
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/psycopg/psycopg/blob/master/docs/news.rst">psycopg-pool's
changelog</a>.</em></p>
<blockquote>
<p>.. currentmodule:: psycopg</p>
<p>.. index::
single: Release notes
single: News</p>
<h1><code>psycopg</code> release notes</h1>
<h2>Future releases</h2>
<p>Psycopg 3.3.7 (unreleased)
^^^^^^^^^^^^^^^^^^^^^^^^^^</p>
<ul>
<li>Fix segfault fetching arrays of strings or timestamps after closing
the
connection
(🎫<code>[#1428](https://github.com/psycopg/psycopg/issues/1428)</code>).</li>
</ul>
<h2>Current release</h2>
<p>Psycopg 3.3.6
^^^^^^^^^^^^^</p>
<ul>
<li>Add support for Python 3.15
(🎫<code>[#1245](https://github.com/psycopg/psycopg/issues/1245)</code>).</li>
<li>Improve performance of async queries by reducing the overhead of the
<code>!wait_async()</code> function
(🎫<code>[#1331](https://github.com/psycopg/psycopg/issues/1331)</code>).</li>
<li>Don't wait forever for a query to terminate after interrupting it,
for
instance if the server is unresponsive. The fix requires libpq 17 or
newer

(🎫<code>[#1371](https://github.com/psycopg/psycopg/issues/1371)</code>).</li>
<li>Cancel a running query upon receiving <code>!SystemExit</code>
(🎫<code>[#1384](https://github.com/psycopg/psycopg/issues/1384)</code>).</li>
<li>Report <code>!None</code> instead of <code>65535</code> as the
<code>Column.precision</code> of an
:sql:<code>interval</code> column declared with a fields restriction and
no explicit
precision, such as e.g. :sql:<code>interval day to second</code>
(🎫<code>[#1397](https://github.com/psycopg/psycopg/issues/1397)</code>).</li>
<li>Fix dumping of nested subclasses of lists as arrays
(🎫<code>[#1398](https://github.com/psycopg/psycopg/issues/1398)</code>).</li>
<li>Discard prepared statements upon :sql:<code>DEALLOCATE ALL</code>
(🎫<code>[#1408](https://github.com/psycopg/psycopg/issues/1408)</code>).</li>
<li>Better guards dumping large Python <code>!int</code> to binary
numeric
(🎫<code>[#1414](https://github.com/psycopg/psycopg/issues/1414)</code>).</li>
</ul>
<p>Psycopg 3.3.5
^^^^^^^^^^^^^</p>
<ul>
<li>Discard prepared statements upon :sql:<code>ALTER *</code> or
<code>DISCARD *</code>

(🎫<code>[#1307](https://github.com/psycopg/psycopg/issues/1307)</code>).</li>
<li>Fix <code>!ProgrammingError</code> when dumping
non-<code>!None</code> values with
no <code>!NoneType</code> dumper registered in python implementation
(🎫<code>[#1325](https://github.com/psycopg/psycopg/issues/1325)</code>).</li>
<li>Fix <code>!wait_selector</code> wait function to not raise
<code>!KeyError</code>

(🎫<code>[#1327](https://github.com/psycopg/psycopg/issues/1327)</code>).</li>
<li>Fix <code>!DataError</code> messages leaking the literal
<code>{...}</code> placeholder instead</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/psycopg/psycopg/commit/1a8f65a371da3c691111cd4a81141f2cb698eafa"><code>1a8f65a</code></a>
chore: bump psycopg package version to 3.3.3</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/db3c43584320ab5d97e49378e5c9dc09a560b031"><code>db3c435</code></a>
Merge pull request <a
href="https://redirect.github.com/psycopg/psycopg/issues/1260">#1260</a>
from ggevay/sync-error-fix</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/0237586c415ece15102742f5941874c29fb1221c"><code>0237586</code></a>
Fix ValueError when server sends ErrorResponse during Sync after
Parse</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/cb97ef7063520cb8a0cb5236bb9791f8dc4cc454"><code>cb97ef7</code></a>
docs: fix typos</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/09c89180f94606dc70475ed863e135f021a11038"><code>09c8918</code></a>
Merge pull request <a
href="https://redirect.github.com/psycopg/psycopg/issues/1256">#1256</a>
from veeceey/fix/tstrings-error-msg-and-docs-improve...</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/9e74d9646cc3fcbb9d8940182dcdb41119c3fda7"><code>9e74d96</code></a>
fix: fix error message incorrectly generated by Claude AI</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/0db9d8bb76c48e70dffd48776406fd3ffdc89b5a"><code>0db9d8b</code></a>
fix: correct typo in tstrings error message and fix sql.rst docs</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/86a0e1b2bbf30c564c59bf3497d499e2f220ce0f"><code>86a0e1b</code></a>
chore(deps): bump pypa/cibuildwheel in the actions group</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/f5d90fa2a7836c1268c1d43d0d77c431434ad191"><code>f5d90fa</code></a>
Merge pull request <a
href="https://redirect.github.com/psycopg/psycopg/issues/1233">#1233</a>
from lysnikolaou/pgconn-critical-section</li>
<li><a
href="https://github.com/psycopg/psycopg/commit/d7dc6c7cacc2832fffa0d7e607b5fc171424571d"><code>d7dc6c7</code></a>
Merge critical section and nogil blocks into one context manager</li>
<li>Additional commits viewable in <a
href="https://github.com/psycopg/psycopg/compare/3.3.1...3.3.3">compare
view</a></li>
</ul>
</details>
<br />

Updates `anyio` from 4.14.2 to 4.15.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/agronholm/anyio/releases">anyio's
releases</a>.</em></p>
<blockquote>
<h2>4.15.1</h2>
<ul>
<li>Implemented a compatibility fix for supporting direct access of
<code>anyio.*</code> submodules from the main package even when those
submodules were not directly imported first (<!-- raw HTML omitted --><a
href="https://redirect.github.com/agronholm/anyio/issues/1311">#1311</a>
&lt;<a
href="https://redirect.github.com/agronholm/anyio/issues/1311%5C%3E">agronholm/anyio#1311</a><!--
raw HTML omitted -->)</li>
</ul>
<h2>4.15.0</h2>
<ul>
<li>
<p>Added support for the newer keyword-only arguments on
<code>anyio.Path</code> methods to match the standard library
<code>pathlib.Path</code>:</p>
<ul>
<li><code>follow_symlinks</code> on <code>exists()</code> (Python
3.12+)</li>
<li><code>follow_symlinks</code> on <code>is_dir()</code> (Python
3.13+)</li>
<li><code>follow_symlinks</code> on <code>is_file()</code> (Python
3.13+)</li>
<li><code>follow_symlinks</code> on <code>owner()</code> (Python
3.13+)</li>
<li><code>follow_symlinks</code> on <code>group()</code> (Python
3.13+)</li>
<li><code>newline</code> on <code>read_text()</code> (Python 3.13+)</li>
</ul>
<p>(<a
href="https://redirect.github.com/agronholm/anyio/pull/1286">#1286</a>,
<a
href="https://redirect.github.com/agronholm/anyio/pull/1293">#1293</a>;
PR by <a
href="https://github.com/jaideeppyne"><code>@​jaideeppyne</code></a>)</p>
</li>
<li>
<p>Added <code>amap</code>, <code>gather</code>, and
<code>as_completed</code> utility functions to simplify common patterns
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1173">#1173</a>;
PR by <a
href="https://github.com/Graeme22"><code>@​Graeme22</code></a>)</p>
</li>
<li>
<p>Added <code>--anyio-mode</code> command-line option as an alternative
to the <code>anyio_mode</code> ini setting, and fix the pytest plugin's
auto mode detection to recognize the mode when set via either
mechanism(e.g: <code>pytest_asyncio</code>). (<a
href="https://redirect.github.com/agronholm/anyio/pull/1242">#1242</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Added the <code>anyio.Future</code> synchronization primitive which
behaves similar to <code>asyncio.Future</code>, allowing tasks to wait
for a value (or exception) from another task (<a
href="https://redirect.github.com/agronholm/anyio/pull/1146">#1146</a>;
PR by <a
href="https://github.com/Vizonex"><code>@​Vizonex</code></a>)</p>
</li>
<li>
<p>Added guidance for managing multiple memory object stream producers
and consumers with cloned streams (<a
href="https://redirect.github.com/agronholm/anyio/issues/330">#330</a>;
PR by <a
href="https://github.com/nightcityblade"><code>@​nightcityblade</code></a>)</p>
</li>
<li>
<p>Added <code>StapledObjectStream.send_nowait()</code> that delegates
to the underlying <code>ObjectSendStream</code>, if it implements it (<a
href="https://redirect.github.com/agronholm/anyio/pull/1241">#1241</a>;
PR by <a
href="https://github.com/davidbrochart"><code>@​davidbrochart</code></a>)</p>
</li>
<li>
<p>Added the <code>move_on_at()</code> and <code>fail_at()</code>
functions to complement <code>move_on_after()</code> and
<code>fail_after()</code></p>
</li>
<li>
<p>Changed the default name for a task spawned with
<code>TaskGroup.create_task(func())</code> to match the default task
name for the analogous task spawned with
<code>TaskGroup.start_soon(func)</code> or
<code>TaskGroup.start(func)</code> in more situations. Previously, the
default name of a <code>TaskGroup.create_task</code> task never included
the module name. (The default name for a task spawned with
<code>TaskGroup.start_soon</code> or <code>TaskGroup.start</code>
typically includes the module name.) (<a
href="https://redirect.github.com/agronholm/anyio/pull/1234">#1234</a>;
PR by <a
href="https://github.com/gschaffner"><code>@​gschaffner</code></a>)</p>
</li>
<li>
<p>Changed the <code>anyio</code> and <code>anyio.abc</code> modules to
lazily (much like <code>810</code>) import the necessary submodules.
This is done by parsing the AST of the module and building a lookup
table from the <code>if TYPE_CHECKING:</code> block. A fallback mode has
been provided for installations where the source code is unavailable
(e.g. PyInstaller). (<a
href="https://redirect.github.com/agronholm/anyio/pull/1169">#1169</a>)</p>
</li>
<li>
<p>Fixed free-threading compatibility issues arising from the fact that
on Python 3.14 free-threading builds, newly created threads inherit the
current context by default, causing AnyIO to behave erroneously in
relation to <code>start_blocking_portal()</code> and
<code>anyio.to_thread.run_sync()</code> (<a
href="https://redirect.github.com/agronholm/anyio/pull/1224">#1224</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Fixed <code>SpooledTemporaryFile.readinto()</code> and
<code>readinto1()</code> reading twice before rollover, so the
destination buffer was overwritten by the second read and the file
position advanced twice, silently losing data (<a
href="https://redirect.github.com/agronholm/anyio/pull/1215">#1215</a>;
PR by <a
href="https://github.com/c-tonneslan"><code>@​c-tonneslan</code></a>)</p>
</li>
<li>
<p>Added a <code>reason</code> parameter to <code>fail_after</code> (and
the new <code>fail_at</code>) allowing for added exception context when
raising <code>TimeoutError</code> (<a
href="https://redirect.github.com/agronholm/anyio/pull/1227">#1227</a>;
PR by <a
href="https://github.com/Graeme22"><code>@​Graeme22</code></a>)</p>
</li>
<li>
<p>Fixed the default <code>TaskHandle.name</code> missing part of the
task name for tasks started with <code>TaskGroup.start</code> on Trio
(<a
href="https://redirect.github.com/agronholm/anyio/issues/1231">#1231</a>;
PR by <a
href="https://github.com/gschaffner"><code>@​gschaffner</code></a>)</p>
</li>
<li>
<p>Fixed <code>anyio.run</code> leaking, or at least, delaying
collection of loop and root_task due to the root task being cached in a
<code>RunVar</code>. (<a
href="https://redirect.github.com/agronholm/anyio/issues/1203">#1203</a>;
PR by <a
href="https://github.com/tapetersen"><code>@​tapetersen</code></a>)</p>
</li>
<li>
<p>Fixed <code>anyio.Path.with_stem()</code> silently producing a wrong
path (e.g. <code>Path(&quot;.txt&quot;)</code>) instead of raising
<code>ValueError</code> when given an empty stem on a path with a
non-empty suffix, unlike <code>pathlib.PurePath.with_stem</code> (<a
href="https://redirect.github.com/agronholm/anyio/pull/1200">#1200</a>;
PR by <a
href="https://github.com/Sanjays2402"><code>@​Sanjays2402</code></a>)</p>
</li>
<li>
<p>Fixed <code>UNIXSocketStream.aclose()</code> raising
<code>asyncio.InvalidStateError</code> when a concurrent receive or send
operation had just been cancelled on the asyncio backend (<a
href="https://redirect.github.com/agronholm/anyio/issues/1267">#1267</a>;
PR by <a
href="https://github.com/alloutflo"><code>@​alloutflo</code></a>)</p>
</li>
<li>
<p>Fixed the pytest plugin importing the deprecated
<code>_pytest.python.CallSpec2</code> alias, which triggers
<code>PytestRemovedIn10Warning</code> on <code>pytest&gt;=9.2</code> and
crashes pytest at startup when <code>filterwarnings = error</code> is
configured (<a
href="https://redirect.github.com/agronholm/anyio/issues/1271">#1271</a>;
PR by <a
href="https://github.com/matthewfeickert"><code>@​matthewfeickert</code></a>)</p>
</li>
<li>
<p>Fixed an asyncio worker thread race that could raise
<code>RuntimeError</code> when the event loop closed between checking
its state and scheduling the worker result (<a
href="https://redirect.github.com/agronholm/anyio/issues/1265">#1265</a>;
PR by <a
href="https://github.com/hansu650"><code>@​hansu650</code></a>)</p>
</li>
<li>
<p>Fixed <code>CapacityLimiter</code> on the asyncio backend
over-granting tokens when <code>total_tokens</code> was raised while the
limiter was over-subscribed (<a
href="https://redirect.github.com/agronholm/anyio/pull/1223">#1223</a>;
PR by <a
href="https://github.com/zelinewang"><code>@​zelinewang</code></a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/agronholm/anyio/commit/ffcd1542cd6d127980205f90a0100078849dd703"><code>ffcd154</code></a>
Bumped up the version</li>
<li><a
href="https://github.com/agronholm/anyio/commit/0ecf5ed98d294242509b043ebd1a0843e52d892f"><code>0ecf5ed</code></a>
Added a workaround for third party code accessing unimported submodules
(<a
href="https://redirect.github.com/agronholm/anyio/issues/1309">#1309</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/928366259543412a2deb1e2ba09ea45ffa92ef4f"><code>9283662</code></a>
Bumped up the version</li>
<li><a
href="https://github.com/agronholm/anyio/commit/d137692a90f76e4f71605e32ea5ca94cab3a539d"><code>d137692</code></a>
Improved the instructions for AI agents</li>
<li><a
href="https://github.com/agronholm/anyio/commit/033fc52b8fa8e90c5d0ef24b10b3860e974a6265"><code>033fc52</code></a>
Shield TemporaryDirectory cleanup from cancellation (<a
href="https://redirect.github.com/agronholm/anyio/issues/1304">#1304</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/942e9a6552cc10b5aaa779d84bfc8e2c3d5fcffc"><code>942e9a6</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/agronholm/anyio/issues/1305">#1305</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/b825c3be7cb4ca1a8000b8065d4e147843deb704"><code>b825c3b</code></a>
Fixed pyproject.toml changes not triggering the test suite</li>
<li><a
href="https://github.com/agronholm/anyio/commit/9727dc504681e2986b5bc285de9571fb467539af"><code>9727dc5</code></a>
Fixed start inconsistencies between trio and asyncio (<a
href="https://redirect.github.com/agronholm/anyio/issues/1198">#1198</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/b05fe6d160a640355c201363cab286a7d2581da8"><code>b05fe6d</code></a>
Fixed wrong type in move_on_after (<a
href="https://redirect.github.com/agronholm/anyio/issues/1297">#1297</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/44d0c93cc20079acbf38ba4dbed5ab9df323f153"><code>44d0c93</code></a>
Fixed asyncio task group coroutine cleanup (<a
href="https://redirect.github.com/agronholm/anyio/issues/1275">#1275</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/agronholm/anyio/compare/4.14.2...4.15.1">compare
view</a></li>
</ul>
</details>
<br />

Updates `pytest-mock` from 3.15.1 to 3.16.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's
releases</a>.</em></p>
<blockquote>
<h2>v3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's
changelog</a>.</em></p>
<blockquote>
<h2>3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604)
&lt;https://github.com/pytest-dev/pytest-mock/pull/604&gt;</code>_:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611)
&lt;https://github.com/pytest-dev/pytest-mock/pull/611&gt;</code>_:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606)
&lt;https://github.com/pytest-dev/pytest-mock/pull/606&gt;</code>_:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547)
&lt;https://github.com/pytest-dev/pytest-mock/issues/547&gt;</code>_:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147)
&lt;https://github.com/pytest-dev/pytest-mock/issues/147&gt;</code>_:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a>
Release 3.16.0</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a>
Fix duplicate_iterators for async spies (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a>
Fix async assertion argument introspection (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a>
docs: import os in the opening usage example (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a>
Honour resetall() arguments for non-callable mocks (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.5 to 0.16.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>Install ruff 0.16.9</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh
| sh
</code></pre>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>0.16.8</h2>
<p>Released on 2026-09-16.</p>
<h3>Bug fixes</h3>
<ul>
<li>Visit functional <code>TypedDict</code> keyword arguments correctly
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li>
<li>[<code>flake8-simplify</code>] Detect nested <code>async with</code>
under sync parent (<code>SIM117</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li>
<li>[<code>flake8-simplify</code>] Preserve operand order in
<code>SIM109</code> fix (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a>
Bump version to 0.16.9 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a>
Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a>
Update dependency astral-sh/uv to v0.12.18 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a>
[<code>flake8-comprehensions</code>] Document <code>map</code>/generator
exception behavior (<code>C417</code>...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a>
Use <code>target</code> form in <code>rooster.version_files</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a>
[ty] Prefer existing @ paths over response files in Ruff and ty (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a>
ci(github): update version number in placeholder of issue template (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a>
[ty] Propagate outer type context through cast calls (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a>
[ty] Contain rendered code within Markdown fences (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a>
authorize ruff-pre-commit dispatch via OIDC (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `ty` from 0.0.75 to 0.0.84
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/releases">ty's
releases</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's
changelog</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a>
Bump version to 0.0.84 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a>
publish to astral-sh/versions via OIDC (<a
href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a>
use oidc issued token for docs publication (<a
href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a>
Update prek dependencies (<a
href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a>
Update docker/setup-buildx-action action to v4.3.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a>
Update astral-sh/setup-uv action to v10.2.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a>
Bump version to 0.0.83 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a>
Sync the ty security mirror (<a
href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a>
Grant the versions workflow repository read access (<a
href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a>
use scoped token for release workflow (<a
href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 01:52:12 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
3a2501e8c5 chore(deps): bump the minor-and-patch group in /libs/checkpoint with 4 updates (#9148)
Bumps the minor-and-patch group in /libs/checkpoint with 4 updates:
[langchain-core](https://github.com/langchain-ai/langchain),
[pytest-mock](https://github.com/pytest-dev/pytest-mock),
[ruff](https://github.com/astral-sh/ruff) and
[ty](https://github.com/astral-sh/ty).

Updates `langchain-core` from 1.6.1 to 1.6.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchain/releases">langchain-core's
releases</a>.</em></p>
<blockquote>
<h2>langchain-core==1.6.5</h2>
<p>Changes since langchain-core==1.6.4</p>
<p>release(core): 1.6.5 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>)
fix(core): abbreviate long tool IDs in XML buffer strings (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</p>
<h2>langchain-core==1.6.4</h2>
<p>Changes since langchain-core==1.6.3</p>
<p>release(core): 1.6.4 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40718">#40718</a>)
chore(core): deprecate chat message history (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40711">#40711</a>)
chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40634">#40634</a>)
chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40574">#40574</a>)</p>
<h2>langchain-core==1.6.3</h2>
<p>Changes since langchain-core==1.6.2</p>
<p>release(core): 1.6.3 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40407">#40407</a>)
feat(core): Allow model name and provider tracing metadata override
based on gateway response (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40406">#40406</a>)
test(core): cover the deprecated <code>.text()</code> access path (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40243">#40243</a>)
docs(core): remove stale Args/Raises entries from
FileCallbackHandler._write and ChatGeneration.set_text (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40211">#40211</a>)</p>
<h2>langchain-core==1.6.2</h2>
<p>Changes since langchain-core==1.6.1</p>
<p>release(core): 1.6.2 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40209">#40209</a>)
feat(openai): support async tools (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40208">#40208</a>)
chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40150">#40150</a>)
chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40113">#40113</a>)
fix(core): avoid mutation in google-genai standard content (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40023">#40023</a>)
fix(core): avoid mutation in bedrock converse standard content (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40022">#40022</a>)</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchain/commit/c5ab14d42a3e22865c9def909de0b11d70b0bbf0"><code>c5ab14d</code></a>
release(core): 1.6.5 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/5704d9d4813f8c0527f04e2662cf313e1350f96f"><code>5704d9d</code></a>
chore(model-profiles): refresh model profile data (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40804">#40804</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/7622d3dce760ac4be6d9aef4c653277e06064aea"><code>7622d3d</code></a>
release(openai): 1.6.6 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40800">#40800</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/2dd956b8add667dac4f97605ae441d75b8ae228e"><code>2dd956b</code></a>
docs(infra): fix AGENTS.md root setup guidance and package doc accuracy
(<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40794">#40794</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/49f4b4016b82513c3dc1623bf3daa10453861621"><code>49f4b40</code></a>
fix(openai): raise on error events in stream path (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40791">#40791</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/19cadaa1a1e0cac71f3148e2f18b414dcab17426"><code>19cadaa</code></a>
fix(core): abbreviate long tool IDs in XML buffer strings (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/798441e8b07e88e79db355db452cd9492f9628f2"><code>798441e</code></a>
chore(anthropic): fix integration test cassette (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40790">#40790</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/a476942bac3fe5e521676d0f53fabafcb7ba71b1"><code>a476942</code></a>
release(openai): 1.6.5 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40787">#40787</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/46c6bdf1b4e23028a5acc060d8b2797dbf200291"><code>46c6bdf</code></a>
release(anthropic): 1.7.4 (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40786">#40786</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchain/commit/290dabaff27ee379920d55d155d5055d2fe29cc8"><code>290daba</code></a>
fix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (<a
href="https://redirect.github.com/langchain-ai/langchain/issues/40785">#40785</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchain/compare/langchain-core==1.6.1...langchain-core==1.6.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `pytest-mock` from 3.15.1 to 3.16.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's
releases</a>.</em></p>
<blockquote>
<h2>v3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's
changelog</a>.</em></p>
<blockquote>
<h2>3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604)
&lt;https://github.com/pytest-dev/pytest-mock/pull/604&gt;</code>_:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611)
&lt;https://github.com/pytest-dev/pytest-mock/pull/611&gt;</code>_:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606)
&lt;https://github.com/pytest-dev/pytest-mock/pull/606&gt;</code>_:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547)
&lt;https://github.com/pytest-dev/pytest-mock/issues/547&gt;</code>_:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147)
&lt;https://github.com/pytest-dev/pytest-mock/issues/147&gt;</code>_:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a>
Release 3.16.0</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a>
Fix duplicate_iterators for async spies (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a>
Fix async assertion argument introspection (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a>
docs: import os in the opening usage example (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a>
Honour resetall() arguments for non-callable mocks (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.5 to 0.16.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>Install ruff 0.16.9</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh
| sh
</code></pre>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>0.16.8</h2>
<p>Released on 2026-09-16.</p>
<h3>Bug fixes</h3>
<ul>
<li>Visit functional <code>TypedDict</code> keyword arguments correctly
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li>
<li>[<code>flake8-simplify</code>] Detect nested <code>async with</code>
under sync parent (<code>SIM117</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li>
<li>[<code>flake8-simplify</code>] Preserve operand order in
<code>SIM109</code> fix (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a>
Bump version to 0.16.9 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a>
Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a>
Update dependency astral-sh/uv to v0.12.18 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a>
[<code>flake8-comprehensions</code>] Document <code>map</code>/generator
exception behavior (<code>C417</code>...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a>
Use <code>target</code> form in <code>rooster.version_files</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a>
[ty] Prefer existing @ paths over response files in Ruff and ty (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a>
ci(github): update version number in placeholder of issue template (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a>
[ty] Propagate outer type context through cast calls (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a>
[ty] Contain rendered code within Markdown fences (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a>
authorize ruff-pre-commit dispatch via OIDC (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `ty` from 0.0.75 to 0.0.84
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/releases">ty's
releases</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's
changelog</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a>
Bump version to 0.0.84 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a>
publish to astral-sh/versions via OIDC (<a
href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a>
use oidc issued token for docs publication (<a
href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a>
Update prek dependencies (<a
href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a>
Update docker/setup-buildx-action action to v4.3.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a>
Update astral-sh/setup-uv action to v10.2.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a>
Bump version to 0.0.83 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a>
Sync the ty security mirror (<a
href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a>
Grant the versions workflow repository read access (<a
href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a>
use scoped token for release workflow (<a
href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 01:52:01 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
3474bbff29 chore(deps): bump the minor-and-patch group in /libs/cli/js-monorepo-example with 8 updates (#9151)
Bumps the minor-and-patch group in /libs/cli/js-monorepo-example with 8
updates:

| Package | From | To |
| --- | --- | --- |
| [turbo](https://github.com/vercel/turborepo) | `2.10.12` | `2.11.5` |
| [@eslint/eslintrc](https://github.com/eslint/eslintrc) | `3.3.6` |
`3.3.7` |
| [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.11.0` |
|
[@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin)
| `8.68.0` | `8.70.1` |
|
[@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser)
| `8.68.0` | `8.70.1` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [@langchain/core](https://github.com/langchain-ai/langchainjs) |
`1.2.9` | `1.2.13` |
|
[@langchain/langgraph](https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core)
| `1.4.13` | `1.4.18` |

Updates `turbo` from 2.10.12 to 2.11.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/turborepo/releases">turbo's
releases</a>.</em></p>
<blockquote>
<h2>Turborepo v2.11.5</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<h3>Changelog</h3>
<ul>
<li>chore: Release Turborepo 2.11.4 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/14231">vercel/turborepo#14231</a></li>
<li>test: Move Python opt-in hint into filter contracts by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14228">vercel/turborepo#14228</a></li>
<li>test: Move dependency-output summary assertion into contract by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14230">vercel/turborepo#14230</a></li>
<li>test: Move dependency-output selection and validation cases to
engine contracts by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14232">vercel/turborepo#14232</a></li>
<li>test: Move Cargo exclude-only scope coverage by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14238">vercel/turborepo#14238</a></li>
<li>test: Move Cargo cache-authority cases to contracts by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14240">vercel/turborepo#14240</a></li>
<li>test: Move JIT dependency graph scenario into engine contract by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14235">vercel/turborepo#14235</a></li>
<li>test: Move dependency-output hash cases into task-hash contracts by
<a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/14233">vercel/turborepo#14233</a></li>
<li>test: Move Cargo task-filter cases into crate contracts by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14239">vercel/turborepo#14239</a></li>
<li>test: Move JIT input hash timing cases into task-hash contracts by
<a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/14234">vercel/turborepo#14234</a></li>
<li>test: Move package input normalization cases into engine contracts
by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14236">vercel/turborepo#14236</a></li>
<li>test: Move structured startup and JIT input cases into contracts by
<a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/14237">vercel/turborepo#14237</a></li>
<li>fix: Back off remote artifact requests during outages by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14222">vercel/turborepo#14222</a></li>
<li>chore: Release Turborepo 2.11.5-canary.1 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/14245">vercel/turborepo#14245</a></li>
<li>test: Make new-package lockfile filter deterministic by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14241">vercel/turborepo#14241</a></li>
<li>test: Trim redundant Go cache builds by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14242">vercel/turborepo#14242</a></li>
<li>test: Reduce Go versioned-name test matrix by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14243">vercel/turborepo#14243</a></li>
<li>test: Move Go binary checks into contracts by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14246">vercel/turborepo#14246</a></li>
<li>test: Consolidate Go format smokes by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14244">vercel/turborepo#14244</a></li>
<li>test: Reuse Cargo build artifacts safely by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14247">vercel/turborepo#14247</a></li>
<li>test: Separate prune planning matrix from buildability smoke by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14248">vercel/turborepo#14248</a></li>
<li>feat: Bundle docs in <code>turbo</code> npm package by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14108">vercel/turborepo#14108</a></li>
<li>chore: Release Turborepo 2.11.5-canary.2 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/14249">vercel/turborepo#14249</a></li>
<li>fix: Stabilize pnpm per-workspace lockfile hashes by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14253">vercel/turborepo#14253</a></li>
<li>chore: Upgrade factory Next.js to 16.3.3 by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14254">vercel/turborepo#14254</a></li>
<li>fix: Update js-yaml to address CVE-2026-84375 by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14255">vercel/turborepo#14255</a></li>
<li>chore: Upgrade Next.js in docs and factory for CVE-2026-94545 by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14256">vercel/turborepo#14256</a></li>
<li>fix: Remove unmaintained proc-macro-error2 by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14257">vercel/turborepo#14257</a></li>
<li>refactor: Replace clap in production CLIs with usage-rs by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14259">vercel/turborepo#14259</a></li>
<li>chore: Remove tiny-gradient dependency by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14260">vercel/turborepo#14260</a></li>
<li>refactor: Replace human-panic with local crash reporting by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14261">vercel/turborepo#14261</a></li>
<li>chore: Remove unused struct_iterable dependency by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14258">vercel/turborepo#14258</a></li>
<li>fix: Sign complete on-disk artifacts after local cache writes by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14265">vercel/turborepo#14265</a></li>
<li>chore: Remove <code>derive_setters</code> dependency by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14266">vercel/turborepo#14266</a></li>
<li>chore: Remove port_scanner dependency by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14267">vercel/turborepo#14267</a></li>
<li>chore: Remove unused Rust dependency declarations by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14268">vercel/turborepo#14268</a></li>
<li>refactor: Remove unused public Rust APIs by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14269">vercel/turborepo#14269</a></li>
<li>refactor: Use workspace Rust edition across crates by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14270">vercel/turborepo#14270</a></li>
<li>chore: Clean up Rust Clippy exceptions by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14271">vercel/turborepo#14271</a></li>
<li>refactor: Group task-hash and uv generation context by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14279">vercel/turborepo#14279</a></li>
<li>refactor: Remove unused global hash wrapper by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14281">vercel/turborepo#14281</a></li>
<li>refactor: Remove unused file-hash telemetry argument by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14282">vercel/turborepo#14282</a></li>
<li>refactor: Remove dead CLI code and crate-wide allowance by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14283">vercel/turborepo#14283</a></li>
<li>refactor: Remove dead Microfrontends config code by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14284">vercel/turborepo#14284</a></li>
<li>refactor: Remove unused UI task types and dead-code allowance by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/14286">vercel/turborepo#14286</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/turborepo/commit/8492b42667210270f4169f0df8c0edf725ff2f41"><code>8492b42</code></a>
publish 2.11.5 to registry</li>
<li><a
href="https://github.com/vercel/turborepo/commit/a50ee6536eac2f7f3168cc38087ee7d8397fc0e9"><code>a50ee65</code></a>
chore: Release Turborepo 2.11.5-canary.5 (<a
href="https://redirect.github.com/vercel/turborepo/issues/14328">#14328</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/c9602f339008964f8dfaf6329491c374cf2f0a60"><code>c9602f3</code></a>
fix: Pass repository to release asset commands (<a
href="https://redirect.github.com/vercel/turborepo/issues/14327">#14327</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/8cb67669e73cf73bde0a8a9e0a9a829ddd34993f"><code>8cb6766</code></a>
fix: Isolate installer test environment (<a
href="https://redirect.github.com/vercel/turborepo/issues/14326">#14326</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/5108f6c9fda7a7aeb2d2f31c46a44bbe966970c7"><code>5108f6c</code></a>
feat: Add standalone installers URLs for <code>curl | bash</code> (<a
href="https://redirect.github.com/vercel/turborepo/issues/14325">#14325</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/a46f82a2742ef0f8e1b5f9acebfbe2544c34c528"><code>a46f82a</code></a>
chore: Release Turborepo 2.11.5-canary.4 (<a
href="https://redirect.github.com/vercel/turborepo/issues/14324">#14324</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/8427e6e5dd7efc7afdf5a332502551fc8f2eabc8"><code>8427e6e</code></a>
fix: Run standalone archive job on manual releases (<a
href="https://redirect.github.com/vercel/turborepo/issues/14323">#14323</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/7f57aa38406027a30a77d46489ebbdf9dd3ef0e5"><code>7f57aa3</code></a>
feat: Publish versioned standalone turbo archives (<a
href="https://redirect.github.com/vercel/turborepo/issues/14322">#14322</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/d6b852c53c8473ec88081e826b357feb35938e5e"><code>d6b852c</code></a>
docs: Update Turborepo schema URL example (<a
href="https://redirect.github.com/vercel/turborepo/issues/14321">#14321</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/c76ac66c4447bfe35301bee0a002d3c60e163342"><code>c76ac66</code></a>
chore: Release Turborepo 2.11.5-canary.3 (<a
href="https://redirect.github.com/vercel/turborepo/issues/14320">#14320</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/turborepo/compare/v2.10.12...v2.11.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `@eslint/eslintrc` from 3.3.6 to 3.3.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/eslint/eslintrc/releases">@​eslint/eslintrc's
releases</a>.</em></p>
<blockquote>
<h2>eslintrc: v3.3.7</h2>
<h2><a
href="https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7">3.3.7</a>
(2026-09-01)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Bump js-yaml to 4.3.1 (<a
href="https://redirect.github.com/eslint/eslintrc/issues/239">#239</a>)
(<a
href="https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9">f27e7c9</a>)</li>
<li>update js-yaml to 4.3.2 to address security vulnerability (<a
href="https://redirect.github.com/eslint/eslintrc/issues/243">#243</a>)
(<a
href="https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f">bb0d97a</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/eslint/eslintrc/blob/main/CHANGELOG.md">@​eslint/eslintrc's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7">3.3.7</a>
(2026-09-01)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Bump js-yaml to 4.3.1 (<a
href="https://redirect.github.com/eslint/eslintrc/issues/239">#239</a>)
(<a
href="https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9">f27e7c9</a>)</li>
<li>update js-yaml to 4.3.2 to address security vulnerability (<a
href="https://redirect.github.com/eslint/eslintrc/issues/243">#243</a>)
(<a
href="https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f">bb0d97a</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/eslint/eslintrc/commit/7943fa6dd55b236a539f658b88c763a4f9fbb38d"><code>7943fa6</code></a>
chore: release 3.3.7 🚀 (<a
href="https://redirect.github.com/eslint/eslintrc/issues/240">#240</a>)</li>
<li><a
href="https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f"><code>bb0d97a</code></a>
fix: update js-yaml to 4.3.2 to address security vulnerability (<a
href="https://redirect.github.com/eslint/eslintrc/issues/243">#243</a>)</li>
<li><a
href="https://github.com/eslint/eslintrc/commit/5b4abc9c74dd92b9eb782ca81d559a88906509e9"><code>5b4abc9</code></a>
docs: Update README sponsors</li>
<li><a
href="https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9"><code>f27e7c9</code></a>
fix: Bump js-yaml to 4.3.1 (<a
href="https://redirect.github.com/eslint/eslintrc/issues/239">#239</a>)</li>
<li><a
href="https://github.com/eslint/eslintrc/commit/b75e1d2425deebfd1ec7f952dda7d0c4f4d65d5c"><code>b75e1d2</code></a>
docs: Update README sponsors</li>
<li><a
href="https://github.com/eslint/eslintrc/commit/302c13310e148268f990df3edbfd10dab44f2678"><code>302c133</code></a>
docs: Update README sponsors</li>
<li><a
href="https://github.com/eslint/eslintrc/commit/e62e7661b0d9063e42a37af5551bbcb1897e188d"><code>e62e766</code></a>
docs: Update README sponsors</li>
<li><a
href="https://github.com/eslint/eslintrc/commit/cf27f9fd8f775d94500f2569a5bfb6a7de9cdb33"><code>cf27f9f</code></a>
docs: Update README sponsors</li>
<li><a
href="https://github.com/eslint/eslintrc/commit/c7f4cdf1ffa86e28b5b8bf09f9e8bc7fadbf87ff"><code>c7f4cdf</code></a>
docs: Update README sponsors</li>
<li><a
href="https://github.com/eslint/eslintrc/commit/3319822ac925e018c47fcafa351b20ea0bf6eeff"><code>3319822</code></a>
docs: Update README sponsors</li>
<li>Additional commits viewable in <a
href="https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7">compare
view</a></li>
</ul>
</details>
<br />

Updates `eslint` from 10.9.1 to 10.11.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/eslint/eslint/releases">eslint's
releases</a>.</em></p>
<blockquote>
<h2>v10.11.0</h2>
<h2>Features</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/d136fa4b0d2dd4a9e738ca1c012cc674d1441127"><code>d136fa4</code></a>
feat: object-shorthand handle quoted properties for
<code>ignoreConstructors</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/21271">#21271</a>)
(Pavel)</li>
<li><a
href="https://github.com/eslint/eslint/commit/397b3b8134b8ce1a61cbf414d4c29c945ba25690"><code>397b3b8</code></a>
feat: report unsafe labeled <code>continue</code> in
<code>no-unsafe-finally</code> rule (<a
href="https://redirect.github.com/eslint/eslint/issues/21316">#21316</a>)
(electrohyun)</li>
<li><a
href="https://github.com/eslint/eslint/commit/d3dd47f42e4cb5f9da27e3a2e741aa21e02ea1a4"><code>d3dd47f</code></a>
feat: only exempt <code>new-cap</code> built-ins that reference the
global (<a
href="https://redirect.github.com/eslint/eslint/issues/21290">#21290</a>)
(sethamus)</li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/22b09f54f67a9512d4cea39ddbab9b6973d5c476"><code>22b09f5</code></a>
fix: ignore <code>__proto__</code> properties in
<code>prefer-object-spread</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/21311">#21311</a>)
(xbinaryx)</li>
<li><a
href="https://github.com/eslint/eslint/commit/b684bb1cd7e6be03ad1b7a951baead936d9c2166"><code>b684bb1</code></a>
fix: make TimePass.parse optional in types and docs (<a
href="https://redirect.github.com/eslint/eslint/issues/21313">#21313</a>)
(ntnyq)</li>
<li><a
href="https://github.com/eslint/eslint/commit/26d11bce3e0e21f223613d4bb4be3423839b229e"><code>26d11bc</code></a>
fix: don't report <code>__proto__</code> properties in
<code>object-shorthand</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/21310">#21310</a>)
(xbinaryx)</li>
</ul>
<h2>Documentation</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/9ecfdc5319f83580cf3b81beab7e936015fef2fa"><code>9ecfdc5</code></a>
docs: note that --cache can serve stale results for cross-file rules (<a
href="https://redirect.github.com/eslint/eslint/issues/21312">#21312</a>)
(bytedoe)</li>
<li><a
href="https://github.com/eslint/eslint/commit/6c789ff39bc5420e94e8dafeb328bf2b7e3d35ab"><code>6c789ff</code></a>
docs: Update README (GitHub Actions Bot)</li>
<li><a
href="https://github.com/eslint/eslint/commit/5997825635dc9c4e81434894607ef2e3887e0ea3"><code>5997825</code></a>
docs: clarify preserve-caught-error known limitation (<a
href="https://redirect.github.com/eslint/eslint/issues/21294">#21294</a>)
(Akinyemi Toluwalase)</li>
</ul>
<h2>Chores</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/520dd77a35922fb537e2dbfb3c839d047acbdd68"><code>520dd77</code></a>
perf: Implement fast paths in critical areas (<a
href="https://redirect.github.com/eslint/eslint/issues/21210">#21210</a>)
(Nicholas C. Zakas)</li>
<li><a
href="https://github.com/eslint/eslint/commit/92086c87e042413a3d0363d8fc3fbb11db98d06a"><code>92086c8</code></a>
test: update <code>EMFILE</code> error generation for Node.js 26.9.0
compatibility (<a
href="https://redirect.github.com/eslint/eslint/issues/21330">#21330</a>)
(Francesco Trotta)</li>
<li><a
href="https://github.com/eslint/eslint/commit/9ac7eb60525ec768c2fdc6699e5a292aa913ce9e"><code>9ac7eb6</code></a>
chore: update github/codeql-action action to v4.38.0 (<a
href="https://redirect.github.com/eslint/eslint/issues/21331">#21331</a>)
(renovate[bot])</li>
<li><a
href="https://github.com/eslint/eslint/commit/24310e3a0e22b3c086ca402f88448676f2e1cfcd"><code>24310e3</code></a>
chore: update ecosystem plugins (<a
href="https://redirect.github.com/eslint/eslint/issues/21324">#21324</a>)
(ESLint Bot)</li>
<li><a
href="https://github.com/eslint/eslint/commit/45ad79e54a39b54b4ce8eb47e612bd2f72a7a651"><code>45ad79e</code></a>
ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (<a
href="https://redirect.github.com/eslint/eslint/issues/21318">#21318</a>)
(dependabot[bot])</li>
<li><a
href="https://github.com/eslint/eslint/commit/ac74e37322ebf122ada676f153dc55c81f3caab0"><code>ac74e37</code></a>
chore: Add AGENTS.md with AI disclosure requirements (<a
href="https://redirect.github.com/eslint/eslint/issues/21221">#21221</a>)
(Nicholas C. Zakas)</li>
<li><a
href="https://github.com/eslint/eslint/commit/c8326608e710e670beaf982501aed80ea104919a"><code>c832660</code></a>
chore: Upgrade Stylelint to the latest version in docs (<a
href="https://redirect.github.com/eslint/eslint/issues/21245">#21245</a>)
(Jung Hyeon Jun)</li>
<li><a
href="https://github.com/eslint/eslint/commit/f9f88fcccd965fdc162b89c4615dd4018e3cabdf"><code>f9f88fc</code></a>
chore: update ecosystem plugins (<a
href="https://redirect.github.com/eslint/eslint/issues/21308">#21308</a>)
(ESLint Bot)</li>
<li><a
href="https://github.com/eslint/eslint/commit/fc81076a5b8145360654d81cbc130cf7d25dca77"><code>fc81076</code></a>
ci: add more types integration tests (<a
href="https://redirect.github.com/eslint/eslint/issues/20395">#20395</a>)
(Nitin Kumar)</li>
</ul>
<h2>v10.10.0</h2>
<h2>Features</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/264b4346d1963701df0c398b4aeb2f6e8b2af93e"><code>264b434</code></a>
feat: add <code>d</code> and <code>v</code> flags to
<code>no-unexpected-multiline</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/21305">#21305</a>)
(Gihyeon Jeong / 정기현)</li>
<li><a
href="https://github.com/eslint/eslint/commit/c6cc6c592f30901345d94ef75e0d42c1894fae6c"><code>c6cc6c5</code></a>
feat: check <code>Object.prototype</code> property names in
<code>new-cap</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/21269">#21269</a>)
(crimsonjay0)</li>
<li><a
href="https://github.com/eslint/eslint/commit/5661fa65fde9fd4c14f0b730e3cee6a42fc657c1"><code>5661fa6</code></a>
feat: no-extra-bind false negatives with class fields and static blocks
(<a
href="https://redirect.github.com/eslint/eslint/issues/21260">#21260</a>)
(synthex-byte)</li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/bb47dc6da2399a8f76c0c0c3273e6bc314c480e5"><code>bb47dc6</code></a>
fix: update dependency file-entry-cache to v11 (<a
href="https://redirect.github.com/eslint/eslint/issues/20801">#20801</a>)
(Milos Djermanovic)</li>
<li><a
href="https://github.com/eslint/eslint/commit/427ac0a014066c36aa57fa8fa9af20fd9fb591e1"><code>427ac0a</code></a>
fix: use format strings in debug calls (<a
href="https://redirect.github.com/eslint/eslint/issues/21247">#21247</a>)
(Francesco Trotta)</li>
<li><a
href="https://github.com/eslint/eslint/commit/9d8153223dbf47b9aecdc1474202aaee4845f146"><code>9d81532</code></a>
fix: support <code>__proto__</code> in <code>/* exported */</code>
comments (<a
href="https://redirect.github.com/eslint/eslint/issues/21261">#21261</a>)
(sethamus)</li>
<li><a
href="https://github.com/eslint/eslint/commit/87e0a082438264ad90b87fd74165ab4fd90f63ef"><code>87e0a08</code></a>
fix: prefer-object-has-own autofix breaks when Object is shadowed (<a
href="https://redirect.github.com/eslint/eslint/issues/21282">#21282</a>)
(김채영)</li>
<li><a
href="https://github.com/eslint/eslint/commit/8e2cb142217f2efee1d10dcc02bfb75145ae775d"><code>8e2cb14</code></a>
fix: <code>new-cap</code> false positive for <code>UTC</code> calls with
<code>properties: false</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/21275">#21275</a>)
(Pixel)</li>
<li><a
href="https://github.com/eslint/eslint/commit/9f4a364ab0ade048dfce1f37792b1d461d866e55"><code>9f4a364</code></a>
fix: Ignore static imports in no-unreachable (<a
href="https://redirect.github.com/eslint/eslint/issues/21276">#21276</a>)
(Taha Kotil)</li>
</ul>
<h2>Documentation</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/2417cad57d7d1bc4cf3ecf0f0575cfb10ff2011c"><code>2417cad</code></a>
docs: Update README (GitHub Actions Bot)</li>
<li><a
href="https://github.com/eslint/eslint/commit/9cecb8a0a2348070abf72321965d41919c7cc626"><code>9cecb8a</code></a>
docs: document <code>\c</code> control letter escapes in
no-control-regex (<a
href="https://redirect.github.com/eslint/eslint/issues/21286">#21286</a>)
(한국)</li>
<li><a
href="https://github.com/eslint/eslint/commit/8724829f69f8ed80c876e3a5a017da199ce78739"><code>8724829</code></a>
docs: update compat table links (<a
href="https://redirect.github.com/eslint/eslint/issues/21263">#21263</a>)
(fnx)</li>
<li><a
href="https://github.com/eslint/eslint/commit/5634542be580750ffb1a5766470f9e9c72719696"><code>5634542</code></a>
docs: Clarify eqeqeq suggestion behavior (<a
href="https://redirect.github.com/eslint/eslint/issues/21256">#21256</a>)
(Müslüm Yılmaz)</li>
</ul>
<h2>Chores</h2>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/b3d876b46083d67899eb1d9613118c1c583632a2"><code>b3d876b</code></a>
chore: disable npm audit in ecosystem tests (<a
href="https://redirect.github.com/eslint/eslint/issues/21306">#21306</a>)
(Francesco Trotta)</li>
<li><a
href="https://github.com/eslint/eslint/commit/1696682791661c13167eb905da2f38d1b8f4a3bf"><code>1696682</code></a>
ci: restore EMFILE test on Node.js 26 (<a
href="https://redirect.github.com/eslint/eslint/issues/21297">#21297</a>)
(Marry (Subin Yang))</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/eslint/eslint/commit/3c0b7c6e1fe2dec778b97a996018126f22d437ae"><code>3c0b7c6</code></a>
10.11.0</li>
<li><a
href="https://github.com/eslint/eslint/commit/321f0a70dd908ed461b11142e17fbdc0c0f1f198"><code>321f0a7</code></a>
Build: changelog update for 10.11.0</li>
<li><a
href="https://github.com/eslint/eslint/commit/520dd77a35922fb537e2dbfb3c839d047acbdd68"><code>520dd77</code></a>
perf: Implement fast paths in critical areas (<a
href="https://redirect.github.com/eslint/eslint/issues/21210">#21210</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/9ecfdc5319f83580cf3b81beab7e936015fef2fa"><code>9ecfdc5</code></a>
docs: note that --cache can serve stale results for cross-file rules (<a
href="https://redirect.github.com/eslint/eslint/issues/21312">#21312</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/92086c87e042413a3d0363d8fc3fbb11db98d06a"><code>92086c8</code></a>
test: update <code>EMFILE</code> error generation for Node.js 26.9.0
compatibility (<a
href="https://redirect.github.com/eslint/eslint/issues/21330">#21330</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/9ac7eb60525ec768c2fdc6699e5a292aa913ce9e"><code>9ac7eb6</code></a>
chore: update github/codeql-action action to v4.38.0 (<a
href="https://redirect.github.com/eslint/eslint/issues/21331">#21331</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/22b09f54f67a9512d4cea39ddbab9b6973d5c476"><code>22b09f5</code></a>
fix: ignore <code>__proto__</code> properties in
<code>prefer-object-spread</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/21311">#21311</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/24310e3a0e22b3c086ca402f88448676f2e1cfcd"><code>24310e3</code></a>
chore: update ecosystem plugins (<a
href="https://redirect.github.com/eslint/eslint/issues/21324">#21324</a>)</li>
<li><a
href="https://github.com/eslint/eslint/commit/d136fa4b0d2dd4a9e738ca1c012cc674d1441127"><code>d136fa4</code></a>
feat: object-shorthand handle quoted properties for
<code>ignoreConstructors</code> (<a
href="https://redirect.github.com/eslint/eslint/issues/21">#21</a>...</li>
<li><a
href="https://github.com/eslint/eslint/commit/45ad79e54a39b54b4ce8eb47e612bd2f72a7a651"><code>45ad79e</code></a>
ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (<a
href="https://redirect.github.com/eslint/eslint/issues/21318">#21318</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/eslint/eslint/compare/v10.9.1...v10.11.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `@typescript-eslint/eslint-plugin` from 8.68.0 to 8.70.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/typescript-eslint/typescript-eslint/releases">@​typescript-eslint/eslint-plugin's
releases</a>.</em></p>
<blockquote>
<h2>v8.70.1</h2>
<h2>8.70.1 (2026-09-21)</h2>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>ast-spec:</strong> narrow import attribute keys to
identifiers and strings (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12879">#12879</a>)</li>
<li><strong>eslint-plugin:</strong> [no-useless-default-assignment]
avoid false positives on tuples with a rest element (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12768">#12768</a>)</li>
<li><strong>eslint-plugin:</strong> [no-unnecessary-type-parameters]
handle type precedence in the suggestion fixer (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12637">#12637</a>)</li>
<li><strong>eslint-plugin:</strong> [no-explicit-any] use unknown[] for
bare any rest parameters (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12818">#12818</a>)</li>
<li><strong>eslint-plugin:</strong> [no-generated-empty-object-type]
don't report a mapped type whose keys are not resolved yet (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12854">#12854</a>)</li>
<li><strong>eslint-plugin:</strong> [no-misused-spread] omit WeakMap
spread suggestions (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12850">#12850</a>)</li>
<li><strong>eslint-plugin:</strong> [no-unnecessary-type-assertion]
false positive for empty object asserted to a type alias of Record (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12869">#12869</a>)</li>
<li><strong>eslint-plugin:</strong> [no-meaningless-void-operator] allow
void on assignment expressions (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12873">#12873</a>)</li>
<li><strong>eslint-plugin:</strong> [await-thenable] prevent autofix
from breaking code when removing <code>await</code> (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12716">#12716</a>)</li>
<li><strong>eslint-plugin:</strong>
[no-unnecessary-parameter-property-assignment] account for parameter
reassignment (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12880">#12880</a>)</li>
<li><strong>eslint-plugin:</strong> [unbound-method] treat
Intl.Collator.prototype.compare as spec-bound (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12845">#12845</a>)</li>
<li><strong>eslint-plugin:</strong> [no-unnecessary-condition] handle
union-keyed index access on the left-hand side of nullish assignment (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12747">#12747</a>)</li>
<li><strong>eslint-plugin:</strong> [no-useless-default-assignment]
convert the fixer to a suggestion fixer (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12826">#12826</a>)</li>
<li><strong>eslint-plugin:</strong> [no-misused-promises] handle
multiple Promise constituents (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12904">#12904</a>)</li>
<li><strong>rule-tester:</strong> test the final autofix output instead
of the first pass (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12867">#12867</a>)</li>
<li><strong>scope-manager:</strong> merge implicit global definitions
(<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12809">#12809</a>)</li>
<li><strong>type-utils:</strong> match package specifiers on whole path
components (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12838">#12838</a>)</li>
<li><strong>typescript-estree:</strong> resolve symlinked paths when
matching files to projects (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12725">#12725</a>)</li>
<li><strong>typescript-estree:</strong> add missing <code>&lt;</code>
token opening type arguments (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12821">#12821</a>)</li>
<li><strong>typescript-estree:</strong> require string literal import
attribute values (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12894">#12894</a>)</li>
<li><strong>website:</strong> prevent playground from breaking down
after opening link with the .js file type (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12777">#12777</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Amin <a
href="https://github.com/amiin-dev"><code>@​amiin-dev</code></a></li>
<li>Brad Zacher <a
href="https://github.com/bradzacher"><code>@​bradzacher</code></a></li>
<li>Cameron</li>
<li>Diptajoy Mistry <a
href="https://github.com/diptomistry"><code>@​diptomistry</code></a></li>
<li>Evyatar Daud <a
href="https://github.com/StyleShit"><code>@​StyleShit</code></a></li>
<li>Grit <a
href="https://github.com/Grit03"><code>@​Grit03</code></a></li>
<li>Hugo <a
href="https://github.com/hugop95"><code>@​hugop95</code></a></li>
<li>Josh Goldberg ✨</li>
<li>Michael Naumov <a
href="https://github.com/mnaoumov"><code>@​mnaoumov</code></a></li>
<li>Mikhail Baev <a
href="https://github.com/baevm"><code>@​baevm</code></a></li>
<li>Om Rawat</li>
<li>overlookmotel</li>
<li>Sanath <a
href="https://github.com/sansynx"><code>@​sansynx</code></a></li>
<li>Shinji</li>
<li>stoicism <a
href="https://github.com/stoicism02"><code>@​stoicism02</code></a></li>
<li>Vinccool96</li>
<li>Younsang Na <a
href="https://github.com/nayounsang"><code>@​nayounsang</code></a></li>
<li>김채영 <a
href="https://github.com/cchaeyoung"><code>@​cchaeyoung</code></a></li>
<li>송재욱</li>
</ul>
<p>See <a
href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.1">GitHub
Releases</a> for more information.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md">@​typescript-eslint/eslint-plugin's
changelog</a>.</em></p>
<blockquote>
<h2>8.70.1 (2026-09-21)</h2>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>eslint-plugin:</strong> [no-misused-promises] handle
multiple Promise constituents (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12904">#12904</a>)</li>
<li><strong>eslint-plugin:</strong> [no-useless-default-assignment]
convert the fixer to a suggestion fixer (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12826">#12826</a>)</li>
<li><strong>eslint-plugin:</strong> [no-unnecessary-condition] handle
union-keyed index access on the left-hand side of nullish assignment (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12747">#12747</a>)</li>
<li><strong>eslint-plugin:</strong> [unbound-method] treat
Intl.Collator.prototype.compare as spec-bound (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12845">#12845</a>)</li>
<li><strong>eslint-plugin:</strong>
[no-unnecessary-parameter-property-assignment] account for parameter
reassignment (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12880">#12880</a>)</li>
<li><strong>eslint-plugin:</strong> [await-thenable] prevent autofix
from breaking code when removing <code>await</code> (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12716">#12716</a>)</li>
<li><strong>eslint-plugin:</strong> [no-meaningless-void-operator] allow
void on assignment expressions (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12873">#12873</a>)</li>
<li><strong>eslint-plugin:</strong> [no-unnecessary-type-assertion]
false positive for empty object asserted to a type alias of Record (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12869">#12869</a>)</li>
<li><strong>eslint-plugin:</strong> [no-misused-spread] omit WeakMap
spread suggestions (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12850">#12850</a>)</li>
<li><strong>eslint-plugin:</strong> [no-generated-empty-object-type]
don't report a mapped type whose keys are not resolved yet (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12854">#12854</a>)</li>
<li><strong>eslint-plugin:</strong> [no-explicit-any] use unknown[] for
bare any rest parameters (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12818">#12818</a>)</li>
<li><strong>eslint-plugin:</strong> [no-unnecessary-type-parameters]
handle type precedence in the suggestion fixer (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12637">#12637</a>)</li>
<li><strong>eslint-plugin:</strong> [no-useless-default-assignment]
avoid false positives on tuples with a rest element (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12768">#12768</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Brad Zacher <a
href="https://github.com/bradzacher"><code>@​bradzacher</code></a></li>
<li>Diptajoy Mistry <a
href="https://github.com/diptomistry"><code>@​diptomistry</code></a></li>
<li>Grit <a
href="https://github.com/Grit03"><code>@​Grit03</code></a></li>
<li>Hugo <a
href="https://github.com/hugop95"><code>@​hugop95</code></a></li>
<li>Michael Naumov <a
href="https://github.com/mnaoumov"><code>@​mnaoumov</code></a></li>
<li>Mikhail Baev <a
href="https://github.com/baevm"><code>@​baevm</code></a></li>
<li>Om Rawat</li>
<li>Sanath <a
href="https://github.com/sansynx"><code>@​sansynx</code></a></li>
<li>Shinji</li>
<li>Vinccool96</li>
<li>김채영 <a
href="https://github.com/cchaeyoung"><code>@​cchaeyoung</code></a></li>
<li>송재욱</li>
</ul>
<p>See <a
href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.1">GitHub
Releases</a> for more information.</p>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
<h2>8.70.0 (2026-09-07)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>eslint-plugin:</strong> [no-generated-empty-object-type] add
rule (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12730">#12730</a>)</li>
</ul>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>eslint-plugin:</strong> [no-deprecated] report deprecated
imported values used in object shorthand properties (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780">#12780</a>)</li>
<li><strong>eslint-plugin:</strong> [no-unnecessary-condition] no false
positive on RHS of a nested logical expression (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12728">#12728</a>)</li>
<li><strong>eslint-plugin:</strong> [member-ordering] don't report
fields that read fields declared before them (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12729">#12729</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/23d38ceeb8fb1237f55cb62fc2b54419e1fa1ed7"><code>23d38ce</code></a>
chore(release): publish 8.70.1</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/9d82e4b1d9011da31d62d14387bb5a539853fafa"><code>9d82e4b</code></a>
chore: expand eslint-plugin rules test files glob (<a
href="https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin/issues/12878">#12878</a>)</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/f7482f636b89b8eab966b4191ce4a53a3f4b4d9c"><code>f7482f6</code></a>
fix(eslint-plugin): [no-misused-promises] handle multiple Promise
constituent...</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/267304477e04538614fe72ad71e7e13082eb7a90"><code>2673044</code></a>
docs(eslint-plugin): [prefer-promise-reject-errors] add option sections
and e...</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/8f141a2ba63d539465eb4e4604f7d79f6f50ce14"><code>8f141a2</code></a>
fix(eslint-plugin): [no-useless-default-assignment] convert the fixer to
a su...</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/479cd85ff82b81dbec9989621681257ebc317a69"><code>479cd85</code></a>
chore: enable assertion option <code>requireData</code> for all rule
tests (<a
href="https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin/issues/12816">#12816</a>)</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/f3c190c5b5cfa9edaba15fa3f944a76a7364b3ed"><code>f3c190c</code></a>
fix(eslint-plugin): [no-unnecessary-condition] handle union-keyed index
acces...</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/b1993dfd3c45b2c2d83058627499f1dfec5d6d2c"><code>b1993df</code></a>
fix(eslint-plugin): [unbound-method] treat
Intl.Collator.prototype.compare as...</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/da394bc9c21afe97f456040da723d2c558f99658"><code>da394bc</code></a>
fix(eslint-plugin): [no-unnecessary-parameter-property-assignment]
account fo...</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/4a742ff890b7cca8cbf79e78a9a3b345913094c6"><code>4a742ff</code></a>
fix(eslint-plugin): [await-thenable] prevent autofix from breaking code
when ...</li>
<li>Additional commits viewable in <a
href="https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/eslint-plugin">compare
view</a></li>
</ul>
</details>
<br />

Updates `@typescript-eslint/parser` from 8.68.0 to 8.70.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/typescript-eslint/typescript-eslint/releases">@​typescript-eslint/parser's
releases</a>.</em></p>
<blockquote>
<h2>v8.70.1</h2>
<h2>8.70.1 (2026-09-21)</h2>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>ast-spec:</strong> narrow import attribute keys to
identifiers and strings (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12879">#12879</a>)</li>
<li><strong>eslint-plugin:</strong> [no-useless-default-assignment]
avoid false positives on tuples with a rest element (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12768">#12768</a>)</li>
<li><strong>eslint-plugin:</strong> [no-unnecessary-type-parameters]
handle type precedence in the suggestion fixer (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12637">#12637</a>)</li>
<li><strong>eslint-plugin:</strong> [no-explicit-any] use unknown[] for
bare any rest parameters (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12818">#12818</a>)</li>
<li><strong>eslint-plugin:</strong> [no-generated-empty-object-type]
don't report a mapped type whose keys are not resolved yet (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12854">#12854</a>)</li>
<li><strong>eslint-plugin:</strong> [no-misused-spread] omit WeakMap
spread suggestions (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12850">#12850</a>)</li>
<li><strong>eslint-plugin:</strong> [no-unnecessary-type-assertion]
false positive for empty object asserted to a type alias of Record (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12869">#12869</a>)</li>
<li><strong>eslint-plugin:</strong> [no-meaningless-void-operator] allow
void on assignment expressions (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12873">#12873</a>)</li>
<li><strong>eslint-plugin:</strong> [await-thenable] prevent autofix
from breaking code when removing <code>await</code> (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12716">#12716</a>)</li>
<li><strong>eslint-plugin:</strong>
[no-unnecessary-parameter-property-assignment] account for parameter
reassignment (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12880">#12880</a>)</li>
<li><strong>eslint-plugin:</strong> [unbound-method] treat
Intl.Collator.prototype.compare as spec-bound (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12845">#12845</a>)</li>
<li><strong>eslint-plugin:</strong> [no-unnecessary-condition] handle
union-keyed index access on the left-hand side of nullish assignment (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12747">#12747</a>)</li>
<li><strong>eslint-plugin:</strong> [no-useless-default-assignment]
convert the fixer to a suggestion fixer (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12826">#12826</a>)</li>
<li><strong>eslint-plugin:</strong> [no-misused-promises] handle
multiple Promise constituents (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12904">#12904</a>)</li>
<li><strong>rule-tester:</strong> test the final autofix output instead
of the first pass (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12867">#12867</a>)</li>
<li><strong>scope-manager:</strong> merge implicit global definitions
(<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12809">#12809</a>)</li>
<li><strong>type-utils:</strong> match package specifiers on whole path
components (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12838">#12838</a>)</li>
<li><strong>typescript-estree:</strong> resolve symlinked paths when
matching files to projects (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12725">#12725</a>)</li>
<li><strong>typescript-estree:</strong> add missing <code>&lt;</code>
token opening type arguments (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12821">#12821</a>)</li>
<li><strong>typescript-estree:</strong> require string literal import
attribute values (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12894">#12894</a>)</li>
<li><strong>website:</strong> prevent playground from breaking down
after opening link with the .js file type (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12777">#12777</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Amin <a
href="https://github.com/amiin-dev"><code>@​amiin-dev</code></a></li>
<li>Brad Zacher <a
href="https://github.com/bradzacher"><code>@​bradzacher</code></a></li>
<li>Cameron</li>
<li>Diptajoy Mistry <a
href="https://github.com/diptomistry"><code>@​diptomistry</code></a></li>
<li>Evyatar Daud <a
href="https://github.com/StyleShit"><code>@​StyleShit</code></a></li>
<li>Grit <a
href="https://github.com/Grit03"><code>@​Grit03</code></a></li>
<li>Hugo <a
href="https://github.com/hugop95"><code>@​hugop95</code></a></li>
<li>Josh Goldberg ✨</li>
<li>Michael Naumov <a
href="https://github.com/mnaoumov"><code>@​mnaoumov</code></a></li>
<li>Mikhail Baev <a
href="https://github.com/baevm"><code>@​baevm</code></a></li>
<li>Om Rawat</li>
<li>overlookmotel</li>
<li>Sanath <a
href="https://github.com/sansynx"><code>@​sansynx</code></a></li>
<li>Shinji</li>
<li>stoicism <a
href="https://github.com/stoicism02"><code>@​stoicism02</code></a></li>
<li>Vinccool96</li>
<li>Younsang Na <a
href="https://github.com/nayounsang"><code>@​nayounsang</code></a></li>
<li>김채영 <a
href="https://github.com/cchaeyoung"><code>@​cchaeyoung</code></a></li>
<li>송재욱</li>
</ul>
<p>See <a
href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.1">GitHub
Releases</a> for more information.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md">@​typescript-eslint/parser's
changelog</a>.</em></p>
<blockquote>
<h2>8.70.1 (2026-09-21)</h2>
<p>This was a version bump only for parser to align it with other
projects, there were no code changes.</p>
<p>See <a
href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.1">GitHub
Releases</a> for more information.</p>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
<h2>8.70.0 (2026-09-07)</h2>
<p>This was a version bump only for parser to align it with other
projects, there were no code changes.</p>
<p>See <a
href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0">GitHub
Releases</a> for more information.</p>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
<h2>8.69.0 (2026-08-31)</h2>
<p>This was a version bump only for parser to align it with other
projects, there were no code changes.</p>
<p>See <a
href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.69.0">GitHub
Releases</a> for more information.</p>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/23d38ceeb8fb1237f55cb62fc2b54419e1fa1ed7"><code>23d38ce</code></a>
chore(release): publish 8.70.1</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/7ee76085c22e923c0036b8e0733a3ca7dfd82b60"><code>7ee7608</code></a>
chore(release): publish 8.70.0</li>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/9a6e546823e5d8f2dc015df2aa66c0230615e209"><code>9a6e546</code></a>
chore(release): publish 8.69.0</li>
<li>See full diff in <a
href="https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/parser">compare
view</a></li>
</ul>
</details>
<br />

Updates `prettier` from 3.9.6 to 3.9.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/prettier/prettier/releases">prettier's
releases</a>.</em></p>
<blockquote>
<h2>3.9.9</h2>
<ul>
<li>Markdown: Fix text with <code>$</code> been incorrectly parsed as
math syntax (<a
href="https://redirect.github.com/prettier/prettier/pull/20140">#20140</a>
by <a href="https://github.com/fisker"><code>@​fisker</code></a>)</li>
</ul>
<p>🔗 <a
href="https://github.com/prettier/prettier/blob/3.9.9/CHANGELOG.md#399">Changelog</a></p>
<h2>3.9.8</h2>
<ul>
<li>Markdown: Don't let Liquid objects interrupt paragraphs (<a
href="https://redirect.github.com/prettier/prettier/pull/20087">#20087</a>
by <a href="https://github.com/seiyab"><code>@​seiyab</code></a>)</li>
</ul>
<p>🔗 <a
href="https://github.com/prettier/prettier/blob/3.9.8/CHANGELOG.md#398">Changelog</a></p>
<h2>3.9.7</h2>
<ul>
<li>Support Angular 22.2</li>
<li>Fix regressions in v3.9</li>
</ul>
<p>🔗 <a
href="https://github.com/prettier/prettier/blob/3.9.7/CHANGELOG.md#397">Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md">prettier's
changelog</a>.</em></p>
<blockquote>
<h1>3.9.9</h1>
<p><a
href="https://github.com/prettier/prettier/compare/3.9.8...3.9.9">diff</a></p>
<h4>Markdown: Fix text with <code>$</code> been incorrectly parsed as
math syntax (<a
href="https://redirect.github.com/prettier/prettier/pull/20140">#20140</a>
by <a href="https://github.com/fisker"><code>@​fisker</code></a>)</h4>
<!-- raw HTML omitted -->
<pre lang="md"><code>&lt;!-- Input --&gt;
**Uses $FOO** from `a.sh` and `b.sh`, plus `$BAR` from `c.sh`, before
anything else runs here.
<p>&lt;!-- Prettier 3.9.8 --&gt;
<strong>Uses $FOO</strong> from <code>a.sh</code> and <code>b.sh</code>,
plus <code>$BAR</code>from<code>c.sh</code>, before anything else runs
here.</p>
<p>&lt;!-- Prettier 3.9.9 --&gt;
<strong>Uses $FOO</strong> from <code>a.sh</code> and <code>b.sh</code>,
plus <code>$BAR</code> from <code>c.sh</code>, before anything else runs
here.
</code></pre></p>
<h1>3.9.8</h1>
<p><a
href="https://github.com/prettier/prettier/compare/3.9.7...3.9.8">diff</a></p>
<h4>Markdown: Don't let Liquid objects interrupt paragraphs (<a
href="https://redirect.github.com/prettier/prettier/pull/20087">#20087</a>
by <a href="https://github.com/seiyab"><code>@​seiyab</code></a>)</h4>
<!-- raw HTML omitted -->
<pre lang="markdown"><code>&lt;!-- Input --&gt;
If `module` is not a
[`WebAssembly.Module`](https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module)
object instance, a
{{jsxref(&quot;TypeError&quot;)}} is thrown.
<p>&lt;!-- Prettier 3.9.7 --&gt;
If <code>module</code> is not a <a
href="https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module"><code>WebAssembly.Module</code></a>
object instance, a</p>
<p>{{jsxref(&quot;TypeError&quot;)}} is thrown.</p>
<p>&lt;!-- Prettier 3.9.8 --&gt;
If <code>module</code> is not a <a
href="https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module"><code>WebAssembly.Module</code></a>
object instance, a
{{jsxref(&quot;TypeError&quot;)}} is thrown.
</code></pre></p>
<h1>3.9.7</h1>
<p><a
href="https://github.com/prettier/prettier/compare/3.9.6...3.9.7">diff</a></p>
<h4>Markdown: Prevent indentation drift in list-item code blocks (<a
href="https://redirect.github.com/prettier/prettier/pull/19647">#19647</a>,
<a
href="https://redirect.github.com/prettier/prettier/pull/19990">#19990</a>
by <a
href="https://github.com/Austin1serb"><code>@​Austin1serb</code></a>, <a
href="https://github.com/giaBaoJS"><code>@​giaBaoJS</code></a>)</h4>
<!-- raw HTML omitted -->
<pre lang="markdown"><code>&lt;!-- Input --&gt;
- [x] short first line.
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/prettier/prettier/commit/cdd17f2288b28b170a76416c72dac56e3ea5daff"><code>cdd17f2</code></a>
Release 3.9.9</li>
<li><a
href="https://github.com/prettier/prettier/commit/dc7b8968e678f51ea00e2be3fe8c717d114691a3"><code>dc7b896</code></a>
Disable <code>singleDollarTextMath</code> in
<code>mdast-util-math</code> (<a
href="https://redirect.github.com/prettier/prettier/issues/20140">#20140</a>)</li>
<li><a
href="https://github.com/prettier/prettier/commit/f9be58fb8ec62dd47197ea19a30aac5ad26dfee0"><code>f9be58f</code></a>
Git blame ignore 3.9.8</li>
<li><a
href="https://github.com/prettier/prettier/commit/88470cb79ca3b757dd6b93906d9a992aa1a456c3"><code>88470cb</code></a>
Bump Prettier dependency to 3.9.8</li>
<li><a
href="https://github.com/prettier/prettier/commit/9559cab39eb5082c99a27e8829760c055adba841"><code>9559cab</code></a>
Clean changelog_unreleased</li>
<li><a
href="https://github.com/prettier/prettier/commit/4fc8ee87465de8d54780273a6996d74e8e9da827"><code>4fc8ee8</code></a>
Update dependents count</li>
<li><a
href="https://github.com/prettier/prettier/commit/4f2ab6765d7cb29408a2abdac75d023d64d44107"><code>4f2ab67</code></a>
Release 3.9.8</li>
<li><a
href="https://github.com/prettier/prettier/commit/3d82af8b15b8e89de20dd05cc65f66ab6d4ce8b0"><code>3d82af8</code></a>
Update Regex related dependencies (<a
href="https://redirect.github.com/prettier/prettier/issues/20082">#20082</a>)</li>
<li><a
href="https://github.com/prettier/prettier/commit/5ec8db1745c2bdcca3706ab8cfbbe5c11fc457c1"><code>5ec8db1</code></a>
[3.9.x] Markdown: Don't let Liquid objects interrupt paragraphs (<a
href="https://redirect.github.com/prettier/prettier/issues/20087">#20087</a>)</li>
<li><a
href="https://github.com/prettier/prettier/commit/5b142ed2bce0095161bf6865af30df2d5ba99466"><code>5b142ed</code></a>
Release Release <code>@​prettier/plugin-hermes</code><a
href="https://github.com/0"><code>@​0</code></a>.2.3,
<code>@​prettier/plugin-oxc</code><a
href="https://github.com/0"><code>@​0</code></a>.2.3, an...</li>
<li>Additional commits viewable in <a
href="https://github.com/prettier/prettier/compare/3.9.6...3.9.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/core` from 1.2.9 to 1.2.13
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/core's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.2.13</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11714">#11714</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/a83dfb14f8e17fcb66dc7a915f0cf8ed7b0dffa1"><code>a83dfb1</code></a>
Thanks <a href="https://github.com/ccurme"><code>@​ccurme</code></a>! -
Abbreviate long tool-call IDs when formatting chat messages as strings,
keeping original messages unchanged.</li>
</ul>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.2.12</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11675">#11675</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/030a726639e0147488bc8c23c063a2e72b004c2e"><code>030a726</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
Preserve structured tool arguments in tracer run inputs.</li>
</ul>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.2.11</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11603">#11603</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/fec9cd87b01976014dd549bd2cf7849aee89a566"><code>fec9cd8</code></a>
Thanks <a
href="https://github.com/thushanth-bengre-langchain"><code>@​thushanth-bengre-langchain</code></a>!
- fix(core): build streaming <code>llmOutput.tokenUsage</code> from the
fully-accumulated chunk instead of whichever individual chunk's
<code>usage_metadata</code> arrived last</p>
<p>Affects both core streaming paths —
<code>.stream()</code>/<code>.streamEvents()</code>
(<code>_streamIterator</code>) and
<code>.invoke()</code>/<code>.generate()</code> when a
streaming-preferring callback is attached
(<code>_generateWithCache</code>'s <code>hasStreamingHandler</code>
branch). Previously, <code>llmOutput.tokenUsage</code> was overwritten
by each chunk in turn, so only the last chunk carrying
<code>usage_metadata</code> won — correct for providers that emit one
cumulative total on a final chunk, but wrong for providers (e.g.
<code>@langchain/google</code>, <code>@langchain/anthropic</code>) that
emit <code>usage_metadata</code> as a per-chunk delta across multiple
chunks, where the values must be summed.</p>
<p>Note for provider authors: this assumes each streamed chunk's
<code>usage_metadata</code> is either a per-chunk delta or appears only
on a single final chunk. A provider that instead repeats a cumulative
total on every chunk will now see it summed (and inflated) in
<code>llmOutput.tokenUsage</code>, matching the existing behavior of the
correctly-working <code>message.usage_metadata</code> field.</p>
<p>Also fixes <code>@langchain/google</code>'s <code>invoke({streaming:
true})</code> path (no streaming-preferring callback attached), where
<code>llmOutput</code> was never populated at all.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11590">#11590</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/ffebdc2f00f3290d19f85e5afd6a297920ae584c"><code>ffebdc2</code></a>
Thanks <a
href="https://github.com/thushanth-bengre-langchain"><code>@​thushanth-bengre-langchain</code></a>!
- Fix OpenAI Responses API replay under Zero Data Retention when a
response contains more than one reasoning item, for both v0 and v1. In
v0, the default replay path now reuses
<code>response_metadata.output</code> directly, preserving every
reasoning item's <code>id</code>/<code>encrypted_content</code> in
original order. In v1, <code>AIMessage.contentBlocks</code>
(<code>outputVersion: &quot;v1&quot;</code>) is fixed the same way.
<code>additional_kwargs.reasoning</code> is unchanged.</p>
</li>
</ul>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.2.10</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10047">#10047</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/ff1248fd49dacdb35f5da128278cd777068481d7"><code>ff1248f</code></a>
Thanks <a
href="https://github.com/afirstenberg"><code>@​afirstenberg</code></a>!
- fix(core): BaseMessage.text use contentBlocks</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/c8d12783ecc31a0816f3a47da1040fbd3c08fdbc"><code>c8d1278</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11729">#11729</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5d509ad4b8a5ed9dd4b83020b4c103ac8a69859c"><code>5d509ad</code></a>
fix(openai): send in-memory prompt cache retention as in_memory (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11735">#11735</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/663b9a2076c5b274435c77524ad7730450b34f34"><code>663b9a2</code></a>
feat(openai): support explicit prompt caching (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11232">#11232</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/7735b219221d6ae63eb5445fb67d26c18fce9c46"><code>7735b21</code></a>
chore(infra): drop held mcp-adapters 2.0 changeset to unblock main
releases (...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/34edee1153f0fa40ba6997c8ff7bd45834ca8ce8"><code>34edee1</code></a>
fix(langchain): return failed returnDirect tool calls to the model (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11712">#11712</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/0fcb98b4306a771c940e78d6881d0be9f88507c1"><code>0fcb98b</code></a>
fix(textsplitters): use char length for loc.lines with custom
lengthFunction ...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/e4a3d1bd0c6753d4e1739a7f10064f48e6bc49ec"><code>e4a3d1b</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11683">#11683</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/a9ada857f22c4b746801e77...

_Description has been truncated_

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 01:51:50 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
7c8be00fd6 chore(deps): bump the minor-and-patch group in /libs/cli with 5 updates (#9153)
Bumps the minor-and-patch group in /libs/cli with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.4.4` |
`0.4.5` |
| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` |
`3.16.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.9` |
| [ty](https://github.com/astral-sh/ty) | `0.0.75` | `0.0.84` |
| [hatch](https://github.com/pypa/hatch) | `1.18.0` | `1.18.1` |

Updates `langgraph-sdk` from 0.4.4 to 0.4.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langgraph/releases">langgraph-sdk's
releases</a>.</em></p>
<blockquote>
<h2>langgraph-sdk==0.4.5</h2>
<p>Changes since sdk==0.4.4</p>
<ul>
<li>release(sdk-py): 0.4.5 (<a
href="https://redirect.github.com/langchain-ai/langgraph/issues/8988">#8988</a>)</li>
<li>release(langgraph): 1.2.12 (<a
href="https://redirect.github.com/langchain-ai/langgraph/issues/8987">#8987</a>)</li>
<li>chore(deps): bump anyio from 4.14.2 to 4.15.1 in /libs/sdk-py (<a
href="https://redirect.github.com/langchain-ai/langgraph/issues/8997">#8997</a>)</li>
<li>chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/cli (<a
href="https://redirect.github.com/langchain-ai/langgraph/issues/8998">#8998</a>)</li>
<li>chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/sdk-py (<a
href="https://redirect.github.com/langchain-ai/langgraph/issues/8994">#8994</a>)</li>
<li>feat(langgraph): add response_schema to interrupt() (<a
href="https://redirect.github.com/langchain-ai/langgraph/issues/8886">#8886</a>)</li>
<li>chore(deps): bump the minor-and-patch group across 1 directory with
7 updates (<a
href="https://redirect.github.com/langchain-ai/langgraph/issues/8779">#8779</a>)</li>
<li>chore(deps): bump websockets from 16.0 to 16.1.1 in /libs/sdk-py in
the major group (<a
href="https://redirect.github.com/langchain-ai/langgraph/issues/8781">#8781</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langgraph/commit/6fb2a93212ceeb432c13148849082af0775318a1"><code>6fb2a93</code></a>
langgraph: release 0.4.5 (<a
href="https://redirect.github.com/langchain-ai/langgraph/issues/4709">#4709</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraph/commit/3f8944c1fc560c6b8d700110c7b7764e5c769beb"><code>3f8944c</code></a>
checkpoint: release 2.0.26 (<a
href="https://redirect.github.com/langchain-ai/langgraph/issues/4708">#4708</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraph/commit/e79f3ceedc2508e18b7753d793a90e60ffad0b74"><code>e79f3ce</code></a>
Improve how we match cached writes for async imperative tasks (<a
href="https://redirect.github.com/langchain-ai/langgraph/issues/4691">#4691</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraph/commit/3bdb7d09beae7e1fcfebe86aa91b18e5a93d2cc1"><code>3bdb7d0</code></a>
Lint</li>
<li><a
href="https://github.com/langchain-ai/langgraph/commit/3acf63a918c6f5f59e9a3a4e2c629314e4f6099a"><code>3acf63a</code></a>
Lint</li>
<li><a
href="https://github.com/langchain-ai/langgraph/commit/f51e5e2bd73f1678353bf7e01b09daf1c67cbd0f"><code>f51e5e2</code></a>
Improve how we match cached writes for async imperative tasks</li>
<li>See full diff in <a
href="https://github.com/langchain-ai/langgraph/compare/0.4.4...0.4.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `pytest-mock` from 3.15.1 to 3.16.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's
releases</a>.</em></p>
<blockquote>
<h2>v3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's
changelog</a>.</em></p>
<blockquote>
<h2>3.16.0</h2>
<p><em>2026-09-27</em></p>
<ul>
<li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604)
&lt;https://github.com/pytest-dev/pytest-mock/pull/604&gt;</code>_:
Fixed <code>duplicate_iterators=True</code> for async functions spied
with <code>mocker.spy</code>.</li>
<li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611)
&lt;https://github.com/pytest-dev/pytest-mock/pull/611&gt;</code>_:
Fixed async mock assertion introspection to use awaited arguments
instead of the latest call's arguments.</li>
<li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606)
&lt;https://github.com/pytest-dev/pytest-mock/pull/606&gt;</code>_:
<code>mocker.resetall(return_value=True, side_effect=True)</code> now
also applies to non-callable mocks, such as those returned by
<code>mocker.create_autospec(SomeClass, instance=True)</code>.
Previously both arguments were silently ignored for them.</li>
<li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547)
&lt;https://github.com/pytest-dev/pytest-mock/issues/547&gt;</code>_:
Added <code>SpyType</code> for annotating <code>mocker.spy</code>
results.</li>
<li>Dropped support for EOL Python 3.9.</li>
<li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147)
&lt;https://github.com/pytest-dev/pytest-mock/issues/147&gt;</code>_:
Removed handling of <code>RuntimeError: stop called on unstarted
patcher</code>, which can no longer occur in the supported Python
versions.</li>
<li>Added support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a>
Release 3.16.0</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a>
Fix duplicate_iterators for async spies (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a>
Fix async assertion argument introspection (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a>
docs: import os in the opening usage example (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a>
Honour resetall() arguments for non-callable mocks (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.5 to 0.16.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>Install ruff 0.16.9</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh
| sh
</code></pre>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.9</h2>
<p>Released on 2026-09-24.</p>
<h3>Preview features</h3>
<ul>
<li>[<code>ruff</code>] Avoid false positives for overloaded division
(<code>RUF069</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-bugbear</code>] Avoid false positives for calls with
keyword arguments (<code>B009</code>, <code>B010</code>,
<code>B043</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li>
<li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in
deferred annotations (<code>TID255</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>Update LibCST-based fixes for Python 3.15 (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li>
<li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message
(<code>PYI002</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Fix horizontal overflow on the rules documentation page (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li>
<li>Update rules table with category information (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li>
<li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code>
checks return types in addition to arguments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li>
<li>[<code>flake8-bugbear</code>] Document type-checker interaction
(<code>B010</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li>
<li>[<code>flake8-comprehensions</code>] Document
<code>map</code>/generator exception behavior (<code>C417</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li>
<li>[<code>ruff</code>] Mention related isort settings
(<code>RUF022</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/qinpei-dev"><code>@​qinpei-dev</code></a></li>
<li><a
href="https://github.com/sanjayrohith"><code>@​sanjayrohith</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/webdevsamran"><code>@​webdevsamran</code></a></li>
<li><a
href="https://github.com/zaniebot"><code>@​zaniebot</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/spaceone"><code>@​spaceone</code></a></li>
<li><a
href="https://github.com/IbrahimKhan12"><code>@​IbrahimKhan12</code></a></li>
<li><a
href="https://github.com/devtechedge"><code>@​devtechedge</code></a></li>
<li><a
href="https://github.com/GruffElixir"><code>@​GruffElixir</code></a></li>
</ul>
<h2>0.16.8</h2>
<p>Released on 2026-09-16.</p>
<h3>Bug fixes</h3>
<ul>
<li>Visit functional <code>TypedDict</code> keyword arguments correctly
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li>
<li>[<code>flake8-simplify</code>] Detect nested <code>async with</code>
under sync parent (<code>SIM117</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li>
<li>[<code>flake8-simplify</code>] Preserve operand order in
<code>SIM109</code> fix (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a>
Bump version to 0.16.9 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a>
Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a>
Update dependency astral-sh/uv to v0.12.18 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a>
[<code>flake8-comprehensions</code>] Document <code>map</code>/generator
exception behavior (<code>C417</code>...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a>
Use <code>target</code> form in <code>rooster.version_files</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a>
[ty] Prefer existing @ paths over response files in Ruff and ty (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a>
ci(github): update version number in placeholder of issue template (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a>
[ty] Propagate outer type context through cast calls (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a>
[ty] Contain rendered code within Markdown fences (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a>
authorize ruff-pre-commit dispatch via OIDC (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `ty` from 0.0.75 to 0.0.84
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/releases">ty's
releases</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<h2>Release Notes</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's
changelog</a>.</em></p>
<blockquote>
<h2>0.0.84</h2>
<p>Released on 2026-09-24.</p>
<p>This release addresses <a
href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>,
a use-after-free vulnerability during incremental type checking that can
result in arbitrary code execution when analyzing a specially crafted
Python project. Users who run ty on untrusted code should upgrade to
0.0.84 or newer.</p>
<h3>Bug fixes</h3>
<ul>
<li>Fix stale diagnostics from the LSP server after toggling
<code>showSyntaxErrors</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li>
</ul>
<h3>LSP server</h3>
<ul>
<li>Complete string keys from dictionary initializers (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li>
<li>Support LSP requests against closed documents (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li>
<li>Select projects for external files using import search paths (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li>
<li>Use workspace editor settings for external files (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Avoid repeated subtyping checks for materialized recursive protocols
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li>
<li>Skip reading notebooks when discovering scripts (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li>
</ul>
<h3>Core type checking</h3>
<ul>
<li>Avoid incorrect simplification of <code>TypeIs</code>
materializations (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li>
<li>Fix disjointness of generic class types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li>
<li>Fix staticmethod shadowing through generic receivers and unions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li>
<li>Infer callable signatures from bounded type variables (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li>
<li>Infer constant membership in inline list and set literals (e.g.
<code>&quot;foo&quot; in [&quot;foo&quot;]</code> is now inferred as
<code>Literal[True]</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li>
<li>Infer through optional generic containers in the legacy solver (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li>
<li>Preserve call narrowing during cyclic inference (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li>
<li>Preserve intersections of type guard return types (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li>
<li>Use subtyping for constraint-set implication (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li>
</ul>
<h3>Configuration</h3>
<ul>
<li>Disable <code>invalid-legacy-positional-parameter</code> by default
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Only consider reachable definitions when determining whether a
condition should be exempted from
<code>redundant-condition(-strict)</code> due to the condition being
defined relative to <code>sys.version_info</code>,
<code>sys.platform</code>, <code>os.name</code> or
<code>typing.TYPE_CHECKING</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/ibraheemdev"><code>@​ibraheemdev</code></a></li>
<li><a href="https://github.com/zsol"><code>@​zsol</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a
href="https://github.com/lerebear"><code>@​lerebear</code></a></li>
<li><a
href="https://github.com/MichaReiser"><code>@​MichaReiser</code></a></li>
<li><a
href="https://github.com/ewdurbin"><code>@​ewdurbin</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a>
Bump version to 0.0.84 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a>
publish to astral-sh/versions via OIDC (<a
href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a>
use oidc issued token for docs publication (<a
href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a>
Update prek dependencies (<a
href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a>
Update docker/setup-buildx-action action to v4.3.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a>
Update astral-sh/setup-uv action to v10.2.0 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a>
Bump version to 0.0.83 (<a
href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a>
Sync the ty security mirror (<a
href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a>
Grant the versions workflow repository read access (<a
href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li>
<li><a
href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a>
use scoped token for release workflow (<a
href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare
view</a></li>
</ul>
</details>
<br />

Updates `hatch` from 1.18.0 to 1.18.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pypa/hatch/releases">hatch's
releases</a>.</em></p>
<blockquote>
<h2>Hatch v1.18.1</h2>
<p><em><strong>Added:</strong></em></p>
<ul>
<li>Apply context formatting to the <code>lock-filename</code>
environment option so fields such as <code>{env_name}</code> and
<code>{matrix:...}</code> are resolved when computing the lock file
path.</li>
</ul>
<p><em><strong>Fixed:</strong></em></p>
<ul>
<li>
<p>Consolidate extras and feature resolution into a single code path,
fixing regressions where environment and project extras could be dropped
or resolved inconsistently, and always validate undefined features.</p>
</li>
<li>
<p>Normalize hyphens in the plugin name when building environment option
environment variable names in <code>get_env_var()</code>, so options for
hyphenated plugins resolve to the correct variable.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pypa/hatch/commit/4b17561f822b1b416403a61855374892ecbe11de"><code>4b17561</code></a>
release Hatch v1.18.1 (<a
href="https://redirect.github.com/pypa/hatch/issues/2426">#2426</a>)</li>
<li><a
href="https://github.com/pypa/hatch/commit/b6aaa1a3cac6be652ac90c8c79612bddcca733ea"><code>b6aaa1a</code></a>
release Hatchling v1.32.1 (<a
href="https://redirect.github.com/pypa/hatch/issues/2425">#2425</a>)</li>
<li><a
href="https://github.com/pypa/hatch/commit/47f333a98228c326786d3919f346bd7b74d9cf8f"><code>47f333a</code></a>
Prepare for hatch and hatchling releases (<a
href="https://redirect.github.com/pypa/hatch/issues/2424">#2424</a>)</li>
<li><a
href="https://github.com/pypa/hatch/commit/d5f7bfe813dd4d81520def23b43f5d46aad1899c"><code>d5f7bfe</code></a>
Fix version metadata to preserve leading zeros in CalVer (<a
href="https://redirect.github.com/pypa/hatch/issues/2398">#2398</a>)</li>
<li><a
href="https://github.com/pypa/hatch/commit/cbfc465e019ff51460f80ebbc35370e476aed6b9"><code>cbfc465</code></a>
Context formatting support for <code>lock-filename</code> (<a
href="https://redirect.github.com/pypa/hatch/issues/2412">#2412</a>)</li>
<li><a
href="https://github.com/pypa/hatch/commit/929362c909899556ae4efd1f61a3b078677ad235"><code>929362c</code></a>
Mark a few more tests that require Internet access (<a
href="https://redirect.github.com/pypa/hatch/issues/2400">#2400</a>)</li>
<li><a
href="https://github.com/pypa/hatch/commit/c9d4e8a82a81835e1ed8b29e6885631d7f5aecb3"><code>c9d4e8a</code></a>
Fix env var formatting in <code>get_env_var()</code> function (<a
href="https://redirect.github.com/pypa/hatch/issues/2397">#2397</a>)</li>
<li><a
href="https://github.com/pypa/hatch/commit/84023e0b77ddec3aa3015cd9b57f78f00da2cb18"><code>84023e0</code></a>
Some type fixes (<a
href="https://redirect.github.com/pypa/hatch/issues/1138">#1138</a>)</li>
<li><a
href="https://github.com/pypa/hatch/commit/ed8e30bebf98f2fe4d70c18a32a50a8160c391cb"><code>ed8e30b</code></a>
Refactor extras so that the logic is in one place (<a
href="https://redirect.github.com/pypa/hatch/issues/2382">#2382</a>)</li>
<li>See full diff in <a
href="https://github.com/pypa/hatch/compare/hatch-v1.18.0...hatch-v1.18.1">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 01:51:40 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
e9bde462f2 chore(deps-dev): bump types-requests from 2.33.0.20260712 to 2.33.0.20260906 in /libs/langgraph (#9156)
Bumps [types-requests](https://github.com/python/typeshed) from
2.33.0.20260712 to 2.33.0.20260906.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/python/typeshed/commits">compare view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=types-requests&package-manager=uv&previous-version=2.33.0.20260712&new-version=2.33.0.20260906)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 01:51:29 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
4be610c6bc chore(deps): bump pyjwt from 2.15.0 to 2.15.1 in /libs/langgraph (#9140)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.15.0 to 2.15.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/releases">pyjwt's
releases</a>.</em></p>
<blockquote>
<h2>2.15.1</h2>
<p>See the <a
href="https://github.com/jpadilla/pyjwt/blob/2.15.1/CHANGELOG.rst">2.15.1
changelog</a> for complete release details.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's
changelog</a>.</em></p>
<blockquote>
<h2><code>v2.15.1
&lt;https://github.com/jpadilla/pyjwt/compare/2.15.0...2.15.1&gt;</code>__</h2>
<p>Fixed</p>
<pre><code>
- Accept trailing Base64URL ``=`` padding when decoding JWS segments, so
  tokens issued by AWS ALB and similar systems verify instead of raising
  ``DecodeError: Invalid crypto padding``. Non-alphabet junk such as
``!!!!`` remains rejected
(`[#1209](https://github.com/jpadilla/pyjwt/issues/1209)
&lt;https://github.com/jpadilla/pyjwt/issues/1209&gt;`__).
</code></pre>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/7d5ef55e42ce42221f58dc49943e92ccad1fa66a"><code>7d5ef55</code></a>
chore: prepare 2.15.1 release</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/7bf32526738fe837387bdedd4849a4a525c33a79"><code>7bf3252</code></a>
Accept canonical Base64URL padding in JWT segments (<a
href="https://redirect.github.com/jpadilla/pyjwt/issues/1216">#1216</a>)</li>
<li>See full diff in <a
href="https://github.com/jpadilla/pyjwt/compare/2.15.0...2.15.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pyjwt&package-manager=uv&previous-version=2.15.0&new-version=2.15.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 12:28:57 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>John Kennedy
98b10ba0ff chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/checkpoint-conformance (#9133)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[#5044](https://github.com/urllib3/urllib3/issues/5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[#4945](https://github.com/urllib3/urllib3/issues/4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[#5092](https://github.com/urllib3/urllib3/issues/5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=urllib3&package-manager=uv&previous-version=2.7.0&new-version=2.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com>
2026-09-30 18:50:53 +00:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
ffe4e8cd6d chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/langgraph (#9138)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[#5044](https://github.com/urllib3/urllib3/issues/5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[#4945](https://github.com/urllib3/urllib3/issues/4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[#5092](https://github.com/urllib3/urllib3/issues/5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=urllib3&package-manager=uv&previous-version=2.7.0&new-version=2.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 11:43:51 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
f75add0ee9 chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/cli (#9137)
[//]: # (dependabot-start)
⚠️  **Dependabot is rebasing this PR** ⚠️ 

Rebasing might not happen immediately, so don't worry if this takes some
time.

Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.

---

[//]: # (dependabot-end)

Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[#5044](https://github.com/urllib3/urllib3/issues/5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[#4945](https://github.com/urllib3/urllib3/issues/4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[#5092](https://github.com/urllib3/urllib3/issues/5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=urllib3&package-manager=uv&previous-version=2.7.0&new-version=2.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 11:43:37 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
902be1eb2b chore(deps): bump the uv group across 2 directories with 1 update (#9136)
Bumps the uv group with 1 update in the /libs/cli/uv-examples/monorepo
directory: [urllib3](https://github.com/urllib3/urllib3).
Bumps the uv group with 1 update in the /libs/cli/uv-examples/simple
directory: [urllib3](https://github.com/urllib3/urllib3).

Updates `urllib3` from 2.7.0 to 2.8.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[#5044](https://github.com/urllib3/urllib3/issues/5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[#4945](https://github.com/urllib3/urllib3/issues/4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[#5092](https://github.com/urllib3/urllib3/issues/5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `urllib3` from 2.7.0 to 2.8.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[#5044](https://github.com/urllib3/urllib3/issues/5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[#4945](https://github.com/urllib3/urllib3/issues/4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[#5092](https://github.com/urllib3/urllib3/issues/5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 11:43:23 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
3b969324db chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/checkpoint-sqlite (#9135)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[#5044](https://github.com/urllib3/urllib3/issues/5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[#4945](https://github.com/urllib3/urllib3/issues/4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[#5092](https://github.com/urllib3/urllib3/issues/5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=urllib3&package-manager=uv&previous-version=2.7.0&new-version=2.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 11:43:08 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
e43f0f5f1e chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/sdk-py (#9134)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[#5044](https://github.com/urllib3/urllib3/issues/5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[#4945](https://github.com/urllib3/urllib3/issues/4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[#5092](https://github.com/urllib3/urllib3/issues/5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=urllib3&package-manager=uv&previous-version=2.7.0&new-version=2.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 11:42:51 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
8ccdedcc1b chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/checkpoint-postgres (#9132)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[#5044](https://github.com/urllib3/urllib3/issues/5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[#4945](https://github.com/urllib3/urllib3/issues/4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[#5092](https://github.com/urllib3/urllib3/issues/5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=urllib3&package-manager=uv&previous-version=2.7.0&new-version=2.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 11:42:38 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
7ea31e5e45 chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/checkpoint (#9131)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[#5044](https://github.com/urllib3/urllib3/issues/5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[#4945](https://github.com/urllib3/urllib3/issues/4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[#5092](https://github.com/urllib3/urllib3/issues/5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=urllib3&package-manager=uv&previous-version=2.7.0&new-version=2.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 11:42:23 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
313e0e7e0a chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/prebuilt (#9130)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/releases">urllib3's
releases</a>.</em></p>
<blockquote>
<h2>2.8.0</h2>
<h2>🚀 urllib3 is fundraising for HTTP/2 support</h2>
<p><a
href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3
is raising ~$40,000 USD</a> to release HTTP/2 support and ensure
long-term sustainable maintenance of the project. If your company or
organization uses Python and would benefit from HTTP/2 support in
Requests, pip, cloud SDKs, and thousands of other projects <a
href="https://opencollective.com/urllib3">please consider contributing
financially</a> to ensure HTTP/2 support is developed sustainably and
maintained for the long-haul.</p>
<p>Thank you for your support.</p>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden. (High severity, GHSA-8988-9cw3-xx77)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size line of unbounded length in memory. (High
severity, GHSA-vxq7-64xx-v4gw)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity, GHSA-gh4c-6fx4-qh6g)</li>
</ul>
<blockquote>
<p>[!IMPORTANT]
urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.</p>
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>. Destination client certificates
and identity overrides no longer apply to HTTPS forwarding proxy
connections.</p>
</blockquote>
<blockquote>
<p>[!NOTE]
CVE IDs had not yet been assigned to these advisories at the time of
release due to a backlog at GitHub's CNA.</p>
</blockquote>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option <code>allowed_methods</code> to retry any verb. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience properties to the
result of <code>parse_url()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li>
</ul>
<h2>Bugfixes</h2>
<ul>
<li>
<p>Fixed response header handling to replace obsolete folded header
lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112,
preventing raw CRLF sequences from appearing in header values such as
<code>Set-Cookie</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p>
</li>
<li>
<p>Fixed usage of <code>proxy_ssl_context</code> with
<code>ProxyManager</code> when
<code>use_forwarding_for_https=True</code>. Passing
<code>ssl_context</code> instead of <code>proxy_ssl_context</code> for
HTTPS proxies in this configuration now emits a
<code>FutureWarning</code> and will raise an error in v3.0. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p>
</li>
<li>
<p>Changed behavior of the default <code>ConnectionPool.pool</code>
initialization. <code>LifoQueue</code> is now resolved from the
<code>queue</code> module after the <code>ConnectionPool</code> is
instantiated instead of using the default cached <code>QueueCls</code>
class property. This is done because sometimes the
<code>queue.LifoQueue</code> is monkey-patched late in the program, such
as by gevent. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p>
</li>
<li>
<p>Raised <code>UnrewindableBodyError</code> instead of
<code>ValueError</code> when retrying a request whose body had
<code>tell()</code> but not <code>seek()</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p>
</li>
<li>
<p>Decoded percent-encoded SOCKS proxy credentials before authenticating
with the proxy server. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread
response data in 64 KiB chunks (same as the default <code>amt</code>
when doing <code>HTTPResponse.stream(...)</code>). (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p>
</li>
<li>
<p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms
accepted by <code>socket.connect</code>, such as hex
(<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal
integers (<code>2130706433</code>), ensuring SSL certificate
verification uses the correct mode for these addresses. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading
<code>FullPoolError</code> instead of <code>ValueError</code> when
called with an invalid <code>timeout</code> argument on a pool created
with <code>block=True</code>. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p>
</li>
<li>
<p>Fixed port-zero handling to preserve explicit <code>:0</code> values
instead of substituting the default ports 80 or 443 in URL parsing, pool
selection, proxy configuration, <code>connection_from_url()</code>, and
HTTP/2 request authority. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>,
<a
href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p>
</li>
<li>
<p>Fixed a bug where <code>PoolManager</code> passed the
<code>assert_hostname</code> and <code>assert_fingerprint</code>
parameters to HTTP connection pools. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy
forwarding to strip URL fragments from absolute request targets before
sending requests. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p>
</li>
<li>
<p>Added safeguards to the proxy tunneling code to prevent potential
security issues when handling invalid characters in the proxy host and
HTTP headers. This change affects users of Python 3.10, Python 3.11, and
Python 3.12 when the standard library does not contain the fix; those on
newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the
same security fixes. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p>
</li>
<li>
<p>Fixed <code>HTTPSConnection.connect()</code> overriding
<code>ProxyConfig.ssl_context</code>'s certificate policy and proxy
identity checks with the target connection's TLS settings when
forwarding through an HTTPS proxy.</p>
<p><code>HTTPSConnection</code> no longer applies target SNI,
assertions, or client credentials to forwarding proxy handshakes and
continues to use its <code>ssl_context</code> as a fallback when an
HTTPS proxy forwards an HTTP target. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p>
</li>
<li>
<p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax,
rejecting invalid host input such as raw spaces and control characters,
malformed percent-encodings, and percent-encoded control characters in
HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel
targets. Host normalization now also follows RFC 3986 normalization
rules for percent-encoded octets by decoding percent-encoded unreserved
characters and uppercasing the hexadecimal digits of retained
percent-encoded octets. (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's
changelog</a>.</em></p>
<blockquote>
<h1>2.8.0 (2026-09-15)</h1>
<h2>Security</h2>
<p>Fixed the following security issues:</p>
<ul>
<li>The TLS configuration for HTTPS proxies could be ignored or
overridden.
(High severity, <code>GHSA-8988-9cw3-xx77
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77&gt;</code>__)</li>
<li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code>
could buffer a chunk-size
line of unbounded length in memory. (High severity,
<code>GHSA-vxq7-64xx-v4gw
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw&gt;</code>__)</li>
<li>Chunked Deflate streaming could enter an infinite loop. (Medium
severity,
<code>GHSA-gh4c-6fx4-qh6g
&lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g&gt;</code>__)</li>
</ul>
<p>.. caution::</p>
<pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being
ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.
<p>Configure proxy CA certificates and client certificates in
<code>proxy_ssl_context</code>, and proxy identity checks with
<code>proxy_assert_hostname</code> or
<code>proxy_assert_fingerprint</code>.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.
</code></pre></p>
<h2>Deprecations &amp; Removals</h2>
<ul>
<li>Deprecated using an empty collection as the <code>Retry</code>
option
<code>allowed_methods</code> to retry any verb.
(<code>[#5044](https://github.com/urllib3/urllib3/issues/5044)
&lt;https://github.com/urllib3/urllib3/issues/5044&gt;</code>__)</li>
</ul>
<h2>Features</h2>
<ul>
<li>Added <code>Url.auth_decoded</code> and
<code>Url.auth_decoded_joined</code> convenience
properties to the result of <code>parse_url()</code>.
(<code>[#4945](https://github.com/urllib3/urllib3/issues/4945)
&lt;https://github.com/urllib3/urllib3/issues/4945&gt;</code>__)</li>
<li>Added <code>basic_auth_encoding</code> and
<code>proxy_basic_auth_encoding</code> parameters to
<code>urllib3.util.make_headers()</code>.
(<code>[#5092](https://github.com/urllib3/urllib3/issues/5092)
&lt;https://github.com/urllib3/urllib3/issues/5092&gt;</code>__)</li>
</ul>
<h2>Bugfixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a>
Release 2.8.0</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a>
Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for
brotlicffi (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a>
Fix <code>nox -s docs</code> warning (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a>
Fix loading unencrypted client keys with a password in pyOpenSSL (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a>
Test pickling of <code>InvalidChunkLength</code> (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a>
Share security policy between GitHub and Read the Docs (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a>
Add policy on duplicate pull requests (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li>
<li><a
href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a>
Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a
href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=urllib3&package-manager=uv&previous-version=2.7.0&new-version=2.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 11:42:08 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
b9919ace32 chore(deps): bump pyjwt from 2.13.0 to 2.15.0 in /libs/cli (#9129)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/releases">pyjwt's
releases</a>.</em></p>
<blockquote>
<h2>2.15.0</h2>
<p>See the <a
href="https://github.com/jpadilla/pyjwt/blob/2.15.0/CHANGELOG.rst">2.15.0
changelog</a> for complete release details.</p>
<h2>2.14.0</h2>
<p>See the <a
href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0
changelog</a> for the complete release details and related security
advisories.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's
changelog</a>.</em></p>
<blockquote>
<h2><code>v2.15.0
&lt;https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&gt;</code>__</h2>
<p>Security</p>
<pre><code>
- Wrap recursion errors from deeply nested JWT payloads in
``DecodeError``
  instead of exposing a raw ``RecursionError``.
<p>Added</p>
<pre><code>
- Support Python 3.15 by @kytta in
`[#1202](https://github.com/jpadilla/pyjwt/issues/1202)
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1202&amp;gt;`__

Changed
</code></pre>
<ul>
<li><code>JWKSetCache</code> now stores the parsed <code>PyJWKSet</code>
rather than the raw JWKS
payload, so a cache hit no longer re-parses every key.
<code>JWKSetCache.put()</code>
accepts either form and raises <code>PyJWKSetError</code> for anything
else. As a
result, <code>PyJWKClient.get_jwk_set()</code> returns the same
<code>PyJWKSet</code> instance
for as long as it stays cached, rather than a freshly built one per call
in
<code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208)
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;</code>__</li>
<li><code>PyJWKClient.fetch_data()</code> now raises
<code>PyJWKClientError(&amp;quot;The JWKS endpoint did not return a JSON
object&amp;quot;)</code> when
the endpoint response is not a JSON object, instead of returning it for
<code>get_jwk_set()</code> to reject. Callers reaching the JWKS through
<code>get_jwk_set()</code> see the same error as before in
<code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208)
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;</code>__</li>
</ul>
<p>Fixed</p>
<pre><code>
- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()``
instead
of raising ``PyJWKClientError(&amp;quot;The JWKS endpoint did not return
a JSON
object&amp;quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the
cached value,
so callers pre-populating the cache to avoid a network round-trip could
not
read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914)
&amp;lt;https://github.com/jpadilla/pyjwt/issues/914&amp;gt;`__ and
`[#1208](https://github.com/jpadilla/pyjwt/issues/1208)
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;`__
- ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
``fetch_data()`` override that filters or transforms the JWKS is no
longer
  undone by the next cache hit in
`[#1208](https://github.com/jpadilla/pyjwt/issues/1208)
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;`__
- Raise the documented ``PyJWTError`` subclass instead of leaking a
  ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
  non-numeric, non-string value such as a list, dict, or ``null``.
- Reject OKP JWK private keys when their public ``x`` component does not
  match the private ``d`` component.
- Treat malformed JWK Set members as unusable keys rather than letting
``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that
is not
&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt; 
&lt;/code&gt;&lt;/pre&gt;
&lt;/blockquote&gt;
&lt;p&gt;... (truncated)&lt;/p&gt;
&lt;/details&gt;
&lt;details&gt;
&lt;summary&gt;Commits&lt;/summary&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68&quot;&gt;&lt;code&gt;1d41a64&lt;/code&gt;&lt;/a&gt;
chore: prepare 2.15.0 release&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3&quot;&gt;&lt;code&gt;9bc0665&lt;/code&gt;&lt;/a&gt;
fix: make recursive payload tests deterministic&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b&quot;&gt;&lt;code&gt;5fde08a&lt;/code&gt;&lt;/a&gt;
fix: normalize recursive JWT payload errors&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19&quot;&gt;&lt;code&gt;171062d&lt;/code&gt;&lt;/a&gt;
utils: mention bytes in force_bytes type error (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1173&quot;&gt;#1173&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6&quot;&gt;&lt;code&gt;c9d4d53&lt;/code&gt;&lt;/a&gt;
docs/conf: drop duplicate 'and' from read() docstring (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1174&quot;&gt;#1174&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53&quot;&gt;&lt;code&gt;2763752&lt;/code&gt;&lt;/a&gt;
Add support for Python 3.15 (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1202&quot;&gt;#1202&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5&quot;&gt;&lt;code&gt;4adcd02&lt;/code&gt;&lt;/a&gt;
Catch http.client.HTTPException in PyJWKClient.fetch_data (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1201&quot;&gt;#1201&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097&quot;&gt;&lt;code&gt;9e501d9&lt;/code&gt;&lt;/a&gt;
fix: correct docstring typo in _validate_jti (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1179&quot;&gt;#1179&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2&quot;&gt;&lt;code&gt;4047c44&lt;/code&gt;&lt;/a&gt;
docs: clarify JWK certificate member handling (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1212&quot;&gt;#1212&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9&quot;&gt;&lt;code&gt;f4e2b59&lt;/code&gt;&lt;/a&gt;
[pre-commit.ci] pre-commit autoupdate (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1210&quot;&gt;#1210&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Additional commits viewable in &lt;a
href=&quot;https://github.com/jpadilla/pyjwt/compare/2.13.0...2.15.0&quot;&gt;compare
view&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/details&gt;

&lt;br /&gt;</code></pre>


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pyjwt&package-manager=uv&previous-version=2.13.0&new-version=2.15.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 11:41:54 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
4217373227 chore(deps): bump pyjwt from 2.14.0 to 2.15.0 in /libs/langgraph (#9139)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.14.0 to 2.15.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/releases">pyjwt's
releases</a>.</em></p>
<blockquote>
<h2>2.15.0</h2>
<p>See the <a
href="https://github.com/jpadilla/pyjwt/blob/2.15.0/CHANGELOG.rst">2.15.0
changelog</a> for complete release details.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's
changelog</a>.</em></p>
<blockquote>
<h2><code>v2.15.0
&lt;https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&gt;</code>__</h2>
<p>Security</p>
<pre><code>
- Wrap recursion errors from deeply nested JWT payloads in
``DecodeError``
  instead of exposing a raw ``RecursionError``.
<p>Added</p>
<pre><code>
- Support Python 3.15 by @kytta in
`[#1202](https://github.com/jpadilla/pyjwt/issues/1202)
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1202&amp;gt;`__

Changed
</code></pre>
<ul>
<li><code>JWKSetCache</code> now stores the parsed <code>PyJWKSet</code>
rather than the raw JWKS
payload, so a cache hit no longer re-parses every key.
<code>JWKSetCache.put()</code>
accepts either form and raises <code>PyJWKSetError</code> for anything
else. As a
result, <code>PyJWKClient.get_jwk_set()</code> returns the same
<code>PyJWKSet</code> instance
for as long as it stays cached, rather than a freshly built one per call
in
<code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208)
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;</code>__</li>
<li><code>PyJWKClient.fetch_data()</code> now raises
<code>PyJWKClientError(&amp;quot;The JWKS endpoint did not return a JSON
object&amp;quot;)</code> when
the endpoint response is not a JSON object, instead of returning it for
<code>get_jwk_set()</code> to reject. Callers reaching the JWKS through
<code>get_jwk_set()</code> see the same error as before in
<code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208)
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;</code>__</li>
</ul>
<p>Fixed</p>
<pre><code>
- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()``
instead
of raising ``PyJWKClientError(&amp;quot;The JWKS endpoint did not return
a JSON
object&amp;quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the
cached value,
so callers pre-populating the cache to avoid a network round-trip could
not
read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914)
&amp;lt;https://github.com/jpadilla/pyjwt/issues/914&amp;gt;`__ and
`[#1208](https://github.com/jpadilla/pyjwt/issues/1208)
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;`__
- ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
``fetch_data()`` override that filters or transforms the JWKS is no
longer
  undone by the next cache hit in
`[#1208](https://github.com/jpadilla/pyjwt/issues/1208)
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1208&amp;gt;`__
- Raise the documented ``PyJWTError`` subclass instead of leaking a
  ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
  non-numeric, non-string value such as a list, dict, or ``null``.
- Reject OKP JWK private keys when their public ``x`` component does not
  match the private ``d`` component.
- Treat malformed JWK Set members as unusable keys rather than letting
``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that
is not
&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt; 
&lt;/code&gt;&lt;/pre&gt;
&lt;/blockquote&gt;
&lt;p&gt;... (truncated)&lt;/p&gt;
&lt;/details&gt;
&lt;details&gt;
&lt;summary&gt;Commits&lt;/summary&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68&quot;&gt;&lt;code&gt;1d41a64&lt;/code&gt;&lt;/a&gt;
chore: prepare 2.15.0 release&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3&quot;&gt;&lt;code&gt;9bc0665&lt;/code&gt;&lt;/a&gt;
fix: make recursive payload tests deterministic&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b&quot;&gt;&lt;code&gt;5fde08a&lt;/code&gt;&lt;/a&gt;
fix: normalize recursive JWT payload errors&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19&quot;&gt;&lt;code&gt;171062d&lt;/code&gt;&lt;/a&gt;
utils: mention bytes in force_bytes type error (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1173&quot;&gt;#1173&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6&quot;&gt;&lt;code&gt;c9d4d53&lt;/code&gt;&lt;/a&gt;
docs/conf: drop duplicate 'and' from read() docstring (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1174&quot;&gt;#1174&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53&quot;&gt;&lt;code&gt;2763752&lt;/code&gt;&lt;/a&gt;
Add support for Python 3.15 (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1202&quot;&gt;#1202&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5&quot;&gt;&lt;code&gt;4adcd02&lt;/code&gt;&lt;/a&gt;
Catch http.client.HTTPException in PyJWKClient.fetch_data (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1201&quot;&gt;#1201&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097&quot;&gt;&lt;code&gt;9e501d9&lt;/code&gt;&lt;/a&gt;
fix: correct docstring typo in _validate_jti (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1179&quot;&gt;#1179&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2&quot;&gt;&lt;code&gt;4047c44&lt;/code&gt;&lt;/a&gt;
docs: clarify JWK certificate member handling (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1212&quot;&gt;#1212&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9&quot;&gt;&lt;code&gt;f4e2b59&lt;/code&gt;&lt;/a&gt;
[pre-commit.ci] pre-commit autoupdate (&lt;a
href=&quot;https://redirect.github.com/jpadilla/pyjwt/issues/1210&quot;&gt;#1210&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Additional commits viewable in &lt;a
href=&quot;https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&quot;&gt;compare
view&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/details&gt;

&lt;br /&gt;</code></pre>


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pyjwt&package-manager=uv&previous-version=2.14.0&new-version=2.15.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 11:39:14 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
65ab10f017 chore(deps): bump pyjwt from 2.13.0 to 2.14.0 in /libs/langgraph (#9126)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.14.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/releases">pyjwt's
releases</a>.</em></p>
<blockquote>
<h2>2.14.0</h2>
<p>See the <a
href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0
changelog</a> for the complete release details and related security
advisories.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's
changelog</a>.</em></p>
<blockquote>
<h2><code>v2.14.0
&lt;https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0&gt;</code>__</h2>
<p>Security</p>
<pre><code>
- Harden HMAC key validation against public-key material supplied as
JWK,
  JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See
`GHSA-r6x4-923q-g947
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947&gt;`__,
`GHSA-ffc3-869f-jxw9
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9&gt;`__,
`GHSA-p4g4-x82p-q773
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773&gt;`__,
and `GHSA-w2cx-738m-mc7w
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w&gt;`__.
- Reject automatic redirects when ``PyJWKClient`` fetches a JWKS,
preventing
  redirected destinations from being treated as trusted key sources. See
`GHSA-9v7f-9g4p-ffgj
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj&gt;`__.
- Limit repeated JWKS refreshes caused by unknown key IDs while
preserving
  normal key-rotation behavior. See
`GHSA-2gx3-rcp4-g85q
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q&gt;`__.
- Handle deeply nested and malformed JWS/JWK input without uncaught
recursion
  errors or whole-set parsing failures. See
`GHSA-8wjv-2p76-3863
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863&gt;`__
and `GHSA-w6j9-cwv2-h6wq
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq&gt;`__.
- Enforce compact JWS encoding rules during decoding. See
`GHSA-hxm8-2xgr-2p9m
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m&gt;`__.
- Reject detached-payload arguments for attached JWS inputs. Thanks to
`@xclow3n
&lt;https://github.com/xclow3n&gt;`__ for reporting this behavior; fixed
in commit
`37b54877
&lt;https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122&gt;`__.
<p>Fixed</p>
<pre><code>
- Apply HMAC key validation consistently when keys are loaded through
  ``PyJWK`` and ``PyJWKClient``. See
`GHSA-pxh4-856f-4h89
&amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&amp;gt;`__.
- Reject empty HMAC keys when represented as JWKs.
See `GHSA-pxh4-856f-4h89
&amp;lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&amp;gt;`__.
&lt;/code&gt;&lt;/pre&gt;
&lt;/blockquote&gt;
&lt;/details&gt;
&lt;details&gt;
&lt;summary&gt;Commits&lt;/summary&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df&quot;&gt;&lt;code&gt;c6fe464&lt;/code&gt;&lt;/a&gt;
release: prepare v2.14.0&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42&quot;&gt;&lt;code&gt;f541302&lt;/code&gt;&lt;/a&gt;
style: apply Ruff formatting&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95&quot;&gt;&lt;code&gt;801cd12&lt;/code&gt;&lt;/a&gt;
fix: reject public JWK container HMAC keys&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb&quot;&gt;&lt;code&gt;af8181c&lt;/code&gt;&lt;/a&gt;
fix: reject empty HMAC keys from JWKs&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1&quot;&gt;&lt;code&gt;ba4853a&lt;/code&gt;&lt;/a&gt;
Throttle repeated PyJWKClient refreshes&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499&quot;&gt;&lt;code&gt;2798504&lt;/code&gt;&lt;/a&gt;
fix: reject DER public keys as HMAC secrets&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07&quot;&gt;&lt;code&gt;8b4e233&lt;/code&gt;&lt;/a&gt;
fix: reject loader-accepted PEM variants&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258&quot;&gt;&lt;code&gt;1f8180a&lt;/code&gt;&lt;/a&gt;
fix: format JWS tests&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab&quot;&gt;&lt;code&gt;cff1ac5&lt;/code&gt;&lt;/a&gt;
Fix redirect handler return annotation&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56&quot;&gt;&lt;code&gt;0a795b8&lt;/code&gt;&lt;/a&gt;
Reject redirects in PyJWKClient fetches&lt;/li&gt;
&lt;li&gt;Additional commits viewable in &lt;a
href=&quot;https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0&quot;&gt;compare
view&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/details&gt;

&lt;br /&gt;</code></pre>


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pyjwt&package-manager=uv&previous-version=2.13.0&new-version=2.14.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-30 09:53:24 -07:00
eb69f67b65 fix(checkpoint-sqlite): walk delta ancestors by parent pointer (#8557)
## Summary

The sqlite delta history silently drops a parent checkpoint whose id sorts above its child's,
losing that parent's stored value and its pending writes. The channel hydrates short with no error.

Fixes #8550

## Problem

Stage 1 walked ancestors with:

```sql
WHERE thread_id = ? AND checkpoint_ns = ? AND checkpoint_id <= ?
ORDER BY checkpoint_id DESC
```

Ancestry is defined by the `parent_checkpoint_id` column. These two predicates add a second
requirement: that every child's id sorts above its parent's. The contract promises monotonic ids,
but that only holds within one process, so ids from processes with different clocks can break it.

When the requirement is violated the parent is excluded from the stream and its seed and writes go
with it. Dropping the range filter alone does not fix it: in `checkpoint_id DESC` order that parent
arrives *before* the target, so the walk streams past it before it has started.

## Fix

A recursive CTE anchored at the target, following `parent_checkpoint_id`:

```sql
WITH RECURSIVE ancestors(checkpoint_id, parent_checkpoint_id, type, checkpoint) AS (
    SELECT ... FROM checkpoints
    WHERE thread_id = ? AND checkpoint_ns = ? AND checkpoint_id = ?
    UNION ALL
    SELECT c.... FROM ancestors a CROSS JOIN checkpoints c
      ON c.checkpoint_id = a.parent_checkpoint_id
    WHERE c.thread_id = ? AND c.checkpoint_ns = ?
)
SELECT checkpoint_id, type, checkpoint FROM ancestors
```

Rows now arrive in walk order (target, parent, grandparent, ...), so `step_walk_with_row` no longer
needs its off-path skip or its `parent_cid` tracking; both are removed. The query reads only true
ancestors, where the old one read every row at or below the target including sibling branches.

`CROSS JOIN` pins the join order. The saver never runs `ANALYZE`, and with a plain `JOIN` sqlite put
`checkpoints` as the outer loop, scanning the whole thread on every recursion step. With `ancestors`
outside, each step is one primary key lookup. Through `get_delta_channel_history`:

| chain length | plain `JOIN` | `CROSS JOIN` |
| -- | -- | -- |
| 1000 | 0.032s | 0.001s |
| 2000 | 0.124s | 0.003s |
| 4000 | 0.475s | 0.006s |

## Cycle guard

Following pointers can loop where a bounded id scan could not, and a loop is reachable through
`put` alone: `put` writes with `INSERT OR REPLACE`, so re-putting an existing checkpoint id under a
descendant's config repoints that checkpoint at its own descendant. The walk stops on a repeated
`checkpoint_id` (one set insert per row, no depth ceiling that could truncate a long migrated
thread). sqlite yields recursive rows lazily, so abandoning the cursor ends the recursion.

`test_walk_terminates_when_put_makes_the_parent_chain_cycle` fails by hanging, not by asserting, if
the guard regresses (confirmed by deleting the guard locally). The package has no `pytest-timeout`,
so the CI job timeout is the backstop.

## Postgres

No equivalent change needed. It pages the whole thread with no id bound and follows parent pointers
in Python, and its upsert never rewrites `parent_checkpoint_id`, so it can neither miss this parent
nor form the loop. `BaseCheckpointSaver` and `InMemorySaver` also walk parent pointers.

## Test plan

New `libs/checkpoint-sqlite/tests/test_delta_parent_walk.py`:

- [x] Sync and async, parametrised over both id orders; the sync case also asserts equality with
      `BaseCheckpointSaver` on the same rows. `parent_id_sorts_above_child` is the bug,
      `parent_id_sorts_below_child` the control.
- [x] `test_walk_reaches_root_of_long_chain_with_descending_ids`: 40 checkpoints, only stored value
      at the root.
- [x] `test_walk_terminates_when_put_makes_the_parent_chain_cycle`.
- [x] `test_walk_step_looks_up_the_parent_by_primary_key`: asserts the recursive step's
      `EXPLAIN QUERY PLAN` is a key lookup, so a plain `JOIN` can't come back. Fails with it.
- [x] On `main`: 3 of the 6 walk tests fail (both `parent_id_sorts_above_child` cases and the long
      chain). The cycle test passes on `main` too, since the old bounded scan could not loop; it
      guards the new path.
- [x] #8550's repro returns `{'writes': [('task', 'ch', 'write-root')], 'seed': 'seed'}` sync and
      async (was `{'writes': []}` on `main`).
- [x] `libs/checkpoint-sqlite`: `make format`, `make lint` clean; full suite 125 passed, 2 skipped.
- [x] `libs/langgraph`: `-k "delta or sqlite"` 739 passed, 1 skipped.

Thanks to @lylelllll for the report, the minimal repro, the base-saver comparison that isolated it
to the fast path, and for suggesting the recursive CTE.




Co-authored-by: lylelllll <59271327+lylelllll@users.noreply.github.com>
2026-09-30 12:17:02 -04:00
c0279f0910 fix(checkpoint-postgres): derive the delta walk cursor once the target loads (#8556)
## Summary

`get_delta_channel_history` on Postgres returns an empty history for any `DeltaChannel` on a
target checkpoint that is not within the first stage-1 pagination page (1024 rows) of the thread.
No exception, no warning: the channel just hydrates empty.

Fixes #8448

## Problem

Stage 1 pages `checkpoints` newest-first from the head of the thread, and after each page
`_try_advance_walks` tries to move every not-yet-seeded channel's walk along the partial
`parent_of` map accumulated so far. The walk starts at the target's parent:

```python
if ch not in walk_cursor_by_ch:
    walk_cursor_by_ch[ch] = parent_of.get(target_id)
```

The target can be any checkpoint in the thread, not just the head, so on the first page
`parent_of` frequently has no row for it yet. `.get` then returns `None`, which is also what a
target with no parent returns, and the two are stored identically. Because the initialisation is
guarded by `ch not in walk_cursor_by_ch`, it never runs again: once the walk is parked at `None`
it stays there even after the target's real row and real parent load on a later page.

The result is an empty chain and no seed. Downstream `channels_from_checkpoint` does

```python
replay_ch = delta_spec.from_checkpoint(history.get("seed", MISSING))
replay_ch.replay_writes(history["writes"])
```

so `get_state`, `get_state_history` and `update_state` against an older checkpoint reconstruct a
`messages` channel as `[]` on a thread with hundreds of real messages.

## Fix

Start the walk only once `target_id` is actually present in `parent_of`, so "the target has not
loaded yet" stops sharing a representation with "the target is a root":

```python
if ch not in walk_cursor_by_ch:
    if target_id not in parent_of:
        continue
    walk_cursor_by_ch[ch] = parent_of[target_id]
```

`_try_advance_walks` is a static method on `BasePostgresSaver`, so `PostgresSaver` and
`AsyncPostgresSaver` are both covered by the one change.

## Why it's safe

`continue` leaves the channel exactly as it was, so a later page retries. The three existing
stop conditions are untouched: a channel that finds its seed still seeds, one that reaches a real
root still parks at `None`, and one waiting on an ancestor still keeps its cursor. Paging still
terminates on a short page, which is what ends the run for a target that really is a root.

## Long-term

The sibling sqlite implementation avoids this class of bug differently, by starting its stage-1
scan at the target (`checkpoint_id <= ?`) instead of at the head. Postgres could adopt the same
bound and would then never fetch a checkpoint newer than the target at all, which looks like the
bigger win on a long thread. It makes the read path depend on ancestors always sorting below their
descendants, though, which sqlite already assumes but the Postgres fast path currently does not.
#8550 now reports that assumption as a bug in sqlite, on the grounds that ancestry is defined by
`parent_checkpoint_id` and the contract does not require ids to be monotonic, so the bound is the
wrong direction to move Postgres in. Paging the full thread and following parent pointers is what
keeps this path correct when ids are not monotonic, and with this fix Postgres returns the right
history for #8550's scenario at every page size.

## Test plan

New `libs/checkpoint-postgres/tests/test_delta_pagination.py`. Page size is monkeypatched rather
than writing 1024+ real checkpoints per case, since the only thing that decides the behaviour is
which page the target lands on.

- [x] `test_async_target_older_than_the_first_page` and its sync twin, parametrised over page
      sizes `[_DELTA_PAGE_SIZE, 3, 2, 1]`. The thread has 8 checkpoints with a snapshot at step 1
      and the target at step 4, so every size at or below 3 leaves the target off the first page.
      The real page size is the control.
- [x] `test_root_target_has_no_history_and_still_terminates` covers the case where a `None` cursor
      is the correct answer, at page size 1 so the paging loop runs the length of the thread.
- [x] 6 of the 9 fail on `main` (`expected a snapshot seed, got '<missing>'`); the 3 that pass are
      the two controls and the root case.
- [x] `make format`, `make lint_package`, `make lint_tests` clean.
- [x] Full `libs/checkpoint-postgres` suite, rebased on current `main`: 279 passed, 3 skipped on Postgres 16.
- [x] Graph-level repro with `_DELTA_PAGE_SIZE = 5`: 10 invocations, then `get_state` on the 8th-newest
      checkpoint returns `[]` on `main` and the full history on this branch.

Thanks to @Navneet-Scaler for the report, the mechanism write-up, and the fix in #8453, which this
matches.




Co-authored-by: Navneet-Scaler <147032454+Navneet-Scaler@users.noreply.github.com>
2026-09-30 12:16:55 -04:00
John KennedyGitHubopen-swe[bot] <open-swe@users.noreply.github.com>
07b33185ea fix: reject credential-bearing Git dependencies (#8542)
## Description
Reject Git HTTP dependency URLs containing userinfo before Docker
generation so credentials cannot persist in Dockerfiles or image layers.
Validation now covers local requirement/package metadata and uv
pyproject/lock inputs while keeping errors token-free.

## Test Plan
- [x] Validate credentialed raw, local-manifest, and uv-managed Git URLs
are rejected without echoing secrets
- [x] Validate credential-free HTTPS and SSH Git URLs remain supported

Made by [Open
SWE](https://openswe.vercel.app/agents/81b07455-ece4-3ddc-9955-d7a5bea78d2c)

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-27 21:34:53 +00:00
Hugo DURANDandGitHub 7daa3ab49d feat(cli): place self-hosted deployments on a listener (#9056)
Follow-up to #8482. `langgraph deploy --push-to` can now create a
deployment in a workspace that
deploys through a listener in the customer's own cluster, which is the
hybrid case. Before this,
creation in such a workspace was impossible from the CLI: the control
plane rejected it and the CLI
told the user to go and create the deployment in the UI first.

## Changes
- Smart Auto-Placement: The CLI now proactively checks your workspace.
If you only have one listener and one Kubernetes namespace configured
(and are using the managed cloud control plane), it automatically routes
your deployment there. No extra flags needed.
- New Disambiguation Flags: If your workspace has multiple listeners or
namespaces, the CLI will ask you to choose. You can now pass
--listener-id and --k8s-namespace to tell it exactly where to deploy.
- Failing Fast: The CLI now validates your listener and namespace
choices before it starts building and pushing the heavy Docker image. If
you provide an invalid ID, it stops immediately instead of wasting your
time and bandwidth.
- Fixed a Duplication Bug: Previously, if you had many deployments with
similar names, a pagination issue could hide your existing deployment
from the CLI, causing it to accidentally create a duplicate. The CLI now
queries the server for the exact deployment name to guarantee this
doesn't happen.
- Cleaner Errors: Error messages from the control plane are now stripped
of their clunky HTTP envelopes so you get clear, readable sentences when
something goes wrong.

## Testing

Deployment on 3 paths, hybrid, self-hosted, nominal
2026-09-23 13:56:01 -04:00
Sreekara YachamaneniandGitHub e868c3ccfd feat(cli): clarify agent flags and support env defaults (#9063)
Agent deployment options now print a private-beta notice. Rename
`--environment` to `--agent-environment` and accept `LANGSMITH_AGENT_ID`
/ `LANGSMITH_AGENT_ENVIRONMENT` as process-environment defaults for
deploy and list. Explicit flags take precedence, and the backend payload
is unchanged.

Validation: formatting and lint pass. A local smoke check verified
environment-only deployment, explicit flag precedence, list defaults,
and structured JSON output. Full CLI suite: 411 passed; the two known
Docker failures remain (`test_dockerfile_command_with_docker_compose`
and `test_build_generate_proper_build_context`). No new tests added; the
existing test invocation uses the renamed flag.
2026-09-23 17:53:46 +00:00
Sreekara YachamaneniandGitHub 1211af45b1 feat(cli): Update langgraph deploy command to use agent_id and environment args (#9055)
- Accept agent_id and environment args for `lanngraph deploy`
  - Validate both arguments present or none
- If agent arguments present, make sure deployment_id and name are not
present
2026-09-22 16:28:36 -04:00
Randall HidajatGitHubHari Dhanushkodiopen-swe[bot] <open-swe@users.noreply.github.com>Hugo Durand
1afaca35a0 feat(cli): add --image-uri flag for self-hosted deployments (#8482)
Adds `--image-uri <uri>` to `langgraph deploy` so self-hosted LangSmith
customers can build, push, and deploy in one command without needing to
script the three steps manually.

When `--image-uri` is provided the CLI:
- Builds the image tagged to the provided URI (same Docker build path as
the local build flow)
- Pushes using whatever Docker credentials are already in the
environment (e.g. WIF, `aws ecr get-login-password`) — no auth handling
in the CLI
- PATCHes the deployment with `source_revision_config.image_uri` (no
`revision_source`, which the self-hosted control plane rejects for
`external_docker` deployments)

Also fixes two self-hosted-specific issues uncovered during testing:
- `LANGSMITH_ENDPOINT` is now used as a fallback when
`LANGGRAPH_HOST_URL` isn't set — the CLI strips the `/api/v1` path and
appends `/api-host` to reach the control plane
- The httpx client now builds full URLs via string concatenation rather
than relying on httpx base_url merging, which silently dropped the
`/api-host` path prefix when paths started with `/`
- The "Check status at" URL after a deploy now correctly points to the
self-hosted LangSmith UI instead of `smith.langchain.com`

**How did you verify your code works?**
Tested end-to-end against a self-hosted LangSmith instance using ECR as
the registry. `langgraph deploy --image-uri <ecr-uri>` successfully
built, pushed, and triggered a deployment revision. Confirmed the
existing SaaS flow (`langgraph deploy` without `--image-uri`) is
unaffected — the new flag is opt-in and the `LANGSMITH_ENDPOINT`
fallback only activates when `LANGGRAPH_HOST_URL` is unset and
`LANGSMITH_ENDPOINT` is present.

---------

Co-authored-by: Hari Dhanushkodi <hari-dhanushkodi@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Hugo Durand <hugo.durand@langchain.dev>
2026-09-22 11:50:02 -04:00
Elior Nataf LackritzandGitHub 49cce0ca85 release(sdk-py): 0.4.5 (#8988)
Bumps the Python SDK version from 0.4.4 to 0.4.5. Adds `response_schema`
to the `Interrupt` TypedDict (#8886).
2026-09-21 10:38:26 -04:00
Elior Nataf LackritzandGitHub 19273fa88b release(langgraph): 1.2.12 (#8987)
Bumps langgraph from 1.2.11 to 1.2.12. Ships `response_schema` on
`interrupt()` (#8886).
2026-09-21 10:38:21 -04:00
John KennedyGitHubopen-swe[bot] <open-swe@users.noreply.github.com>
ed384f3a12 fix(cli): remediate AnyIO vulnerabilities in example lockfiles (#9022)
- Upgrade AnyIO from 4.13.0 to 4.14.2 in both uv example lockfiles,
fixing GHSA-82r6-8w77-94w6 (TLS certificate spoofing) and
GHSA-5p39-cfhj-2xmp (process-pool hangs).
- Remove the orphaned examples Poetry lockfile left behind by the uv
migration; current example tooling does not consume it.
- Addresses all six currently open Dependabot alerts without changing
unrelated dependencies.

Made by [Open SWE](https://github.com/langchain-ai/open-swe) · [view
thread](https://openswe.vercel.app/agents/37d08f4f-9fe6-51be-adc9-d58aa9e6e010)
· openai:gpt-6-astra (medium)

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-20 12:50:31 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
aa742fb31e chore(deps): bump anyio from 4.14.2 to 4.15.1 in /libs/sdk-py (#8997)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.14.2 to 4.15.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/agronholm/anyio/releases">anyio's
releases</a>.</em></p>
<blockquote>
<h2>4.15.1</h2>
<ul>
<li>Implemented a compatibility fix for supporting direct access of
<code>anyio.*</code> submodules from the main package even when those
submodules were not directly imported first (<!-- raw HTML omitted --><a
href="https://redirect.github.com/agronholm/anyio/issues/1311">#1311</a>
&lt;<a
href="https://redirect.github.com/agronholm/anyio/issues/1311%5C%3E">agronholm/anyio#1311</a><!--
raw HTML omitted -->)</li>
</ul>
<h2>4.15.0</h2>
<ul>
<li>
<p>Added support for the newer keyword-only arguments on
<code>anyio.Path</code> methods to match the standard library
<code>pathlib.Path</code>:</p>
<ul>
<li><code>follow_symlinks</code> on <code>exists()</code> (Python
3.12+)</li>
<li><code>follow_symlinks</code> on <code>is_dir()</code> (Python
3.13+)</li>
<li><code>follow_symlinks</code> on <code>is_file()</code> (Python
3.13+)</li>
<li><code>follow_symlinks</code> on <code>owner()</code> (Python
3.13+)</li>
<li><code>follow_symlinks</code> on <code>group()</code> (Python
3.13+)</li>
<li><code>newline</code> on <code>read_text()</code> (Python 3.13+)</li>
</ul>
<p>(<a
href="https://redirect.github.com/agronholm/anyio/pull/1286">#1286</a>,
<a
href="https://redirect.github.com/agronholm/anyio/pull/1293">#1293</a>;
PR by <a
href="https://github.com/jaideeppyne"><code>@​jaideeppyne</code></a>)</p>
</li>
<li>
<p>Added <code>amap</code>, <code>gather</code>, and
<code>as_completed</code> utility functions to simplify common patterns
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1173">#1173</a>;
PR by <a
href="https://github.com/Graeme22"><code>@​Graeme22</code></a>)</p>
</li>
<li>
<p>Added <code>--anyio-mode</code> command-line option as an alternative
to the <code>anyio_mode</code> ini setting, and fix the pytest plugin's
auto mode detection to recognize the mode when set via either
mechanism(e.g: <code>pytest_asyncio</code>). (<a
href="https://redirect.github.com/agronholm/anyio/pull/1242">#1242</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Added the <code>anyio.Future</code> synchronization primitive which
behaves similar to <code>asyncio.Future</code>, allowing tasks to wait
for a value (or exception) from another task (<a
href="https://redirect.github.com/agronholm/anyio/pull/1146">#1146</a>;
PR by <a
href="https://github.com/Vizonex"><code>@​Vizonex</code></a>)</p>
</li>
<li>
<p>Added guidance for managing multiple memory object stream producers
and consumers with cloned streams (<a
href="https://redirect.github.com/agronholm/anyio/issues/330">#330</a>;
PR by <a
href="https://github.com/nightcityblade"><code>@​nightcityblade</code></a>)</p>
</li>
<li>
<p>Added <code>StapledObjectStream.send_nowait()</code> that delegates
to the underlying <code>ObjectSendStream</code>, if it implements it (<a
href="https://redirect.github.com/agronholm/anyio/pull/1241">#1241</a>;
PR by <a
href="https://github.com/davidbrochart"><code>@​davidbrochart</code></a>)</p>
</li>
<li>
<p>Added the <code>move_on_at()</code> and <code>fail_at()</code>
functions to complement <code>move_on_after()</code> and
<code>fail_after()</code></p>
</li>
<li>
<p>Changed the default name for a task spawned with
<code>TaskGroup.create_task(func())</code> to match the default task
name for the analogous task spawned with
<code>TaskGroup.start_soon(func)</code> or
<code>TaskGroup.start(func)</code> in more situations. Previously, the
default name of a <code>TaskGroup.create_task</code> task never included
the module name. (The default name for a task spawned with
<code>TaskGroup.start_soon</code> or <code>TaskGroup.start</code>
typically includes the module name.) (<a
href="https://redirect.github.com/agronholm/anyio/pull/1234">#1234</a>;
PR by <a
href="https://github.com/gschaffner"><code>@​gschaffner</code></a>)</p>
</li>
<li>
<p>Changed the <code>anyio</code> and <code>anyio.abc</code> modules to
lazily (much like <code>810</code>) import the necessary submodules.
This is done by parsing the AST of the module and building a lookup
table from the <code>if TYPE_CHECKING:</code> block. A fallback mode has
been provided for installations where the source code is unavailable
(e.g. PyInstaller). (<a
href="https://redirect.github.com/agronholm/anyio/pull/1169">#1169</a>)</p>
</li>
<li>
<p>Fixed free-threading compatibility issues arising from the fact that
on Python 3.14 free-threading builds, newly created threads inherit the
current context by default, causing AnyIO to behave erroneously in
relation to <code>start_blocking_portal()</code> and
<code>anyio.to_thread.run_sync()</code> (<a
href="https://redirect.github.com/agronholm/anyio/pull/1224">#1224</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Fixed <code>SpooledTemporaryFile.readinto()</code> and
<code>readinto1()</code> reading twice before rollover, so the
destination buffer was overwritten by the second read and the file
position advanced twice, silently losing data (<a
href="https://redirect.github.com/agronholm/anyio/pull/1215">#1215</a>;
PR by <a
href="https://github.com/c-tonneslan"><code>@​c-tonneslan</code></a>)</p>
</li>
<li>
<p>Added a <code>reason</code> parameter to <code>fail_after</code> (and
the new <code>fail_at</code>) allowing for added exception context when
raising <code>TimeoutError</code> (<a
href="https://redirect.github.com/agronholm/anyio/pull/1227">#1227</a>;
PR by <a
href="https://github.com/Graeme22"><code>@​Graeme22</code></a>)</p>
</li>
<li>
<p>Fixed the default <code>TaskHandle.name</code> missing part of the
task name for tasks started with <code>TaskGroup.start</code> on Trio
(<a
href="https://redirect.github.com/agronholm/anyio/issues/1231">#1231</a>;
PR by <a
href="https://github.com/gschaffner"><code>@​gschaffner</code></a>)</p>
</li>
<li>
<p>Fixed <code>anyio.run</code> leaking, or at least, delaying
collection of loop and root_task due to the root task being cached in a
<code>RunVar</code>. (<a
href="https://redirect.github.com/agronholm/anyio/issues/1203">#1203</a>;
PR by <a
href="https://github.com/tapetersen"><code>@​tapetersen</code></a>)</p>
</li>
<li>
<p>Fixed <code>anyio.Path.with_stem()</code> silently producing a wrong
path (e.g. <code>Path(&quot;.txt&quot;)</code>) instead of raising
<code>ValueError</code> when given an empty stem on a path with a
non-empty suffix, unlike <code>pathlib.PurePath.with_stem</code> (<a
href="https://redirect.github.com/agronholm/anyio/pull/1200">#1200</a>;
PR by <a
href="https://github.com/Sanjays2402"><code>@​Sanjays2402</code></a>)</p>
</li>
<li>
<p>Fixed <code>UNIXSocketStream.aclose()</code> raising
<code>asyncio.InvalidStateError</code> when a concurrent receive or send
operation had just been cancelled on the asyncio backend (<a
href="https://redirect.github.com/agronholm/anyio/issues/1267">#1267</a>;
PR by <a
href="https://github.com/alloutflo"><code>@​alloutflo</code></a>)</p>
</li>
<li>
<p>Fixed the pytest plugin importing the deprecated
<code>_pytest.python.CallSpec2</code> alias, which triggers
<code>PytestRemovedIn10Warning</code> on <code>pytest&gt;=9.2</code> and
crashes pytest at startup when <code>filterwarnings = error</code> is
configured (<a
href="https://redirect.github.com/agronholm/anyio/issues/1271">#1271</a>;
PR by <a
href="https://github.com/matthewfeickert"><code>@​matthewfeickert</code></a>)</p>
</li>
<li>
<p>Fixed an asyncio worker thread race that could raise
<code>RuntimeError</code> when the event loop closed between checking
its state and scheduling the worker result (<a
href="https://redirect.github.com/agronholm/anyio/issues/1265">#1265</a>;
PR by <a
href="https://github.com/hansu650"><code>@​hansu650</code></a>)</p>
</li>
<li>
<p>Fixed <code>CapacityLimiter</code> on the asyncio backend
over-granting tokens when <code>total_tokens</code> was raised while the
limiter was over-subscribed (<a
href="https://redirect.github.com/agronholm/anyio/pull/1223">#1223</a>;
PR by <a
href="https://github.com/zelinewang"><code>@​zelinewang</code></a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/agronholm/anyio/commit/ffcd1542cd6d127980205f90a0100078849dd703"><code>ffcd154</code></a>
Bumped up the version</li>
<li><a
href="https://github.com/agronholm/anyio/commit/0ecf5ed98d294242509b043ebd1a0843e52d892f"><code>0ecf5ed</code></a>
Added a workaround for third party code accessing unimported submodules
(<a
href="https://redirect.github.com/agronholm/anyio/issues/1309">#1309</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/928366259543412a2deb1e2ba09ea45ffa92ef4f"><code>9283662</code></a>
Bumped up the version</li>
<li><a
href="https://github.com/agronholm/anyio/commit/d137692a90f76e4f71605e32ea5ca94cab3a539d"><code>d137692</code></a>
Improved the instructions for AI agents</li>
<li><a
href="https://github.com/agronholm/anyio/commit/033fc52b8fa8e90c5d0ef24b10b3860e974a6265"><code>033fc52</code></a>
Shield TemporaryDirectory cleanup from cancellation (<a
href="https://redirect.github.com/agronholm/anyio/issues/1304">#1304</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/942e9a6552cc10b5aaa779d84bfc8e2c3d5fcffc"><code>942e9a6</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/agronholm/anyio/issues/1305">#1305</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/b825c3be7cb4ca1a8000b8065d4e147843deb704"><code>b825c3b</code></a>
Fixed pyproject.toml changes not triggering the test suite</li>
<li><a
href="https://github.com/agronholm/anyio/commit/9727dc504681e2986b5bc285de9571fb467539af"><code>9727dc5</code></a>
Fixed start inconsistencies between trio and asyncio (<a
href="https://redirect.github.com/agronholm/anyio/issues/1198">#1198</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/b05fe6d160a640355c201363cab286a7d2581da8"><code>b05fe6d</code></a>
Fixed wrong type in move_on_after (<a
href="https://redirect.github.com/agronholm/anyio/issues/1297">#1297</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/44d0c93cc20079acbf38ba4dbed5ab9df323f153"><code>44d0c93</code></a>
Fixed asyncio task group coroutine cleanup (<a
href="https://redirect.github.com/agronholm/anyio/issues/1275">#1275</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/agronholm/anyio/compare/4.14.2...4.15.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=anyio&package-manager=uv&previous-version=4.14.2&new-version=4.15.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-18 23:31:43 +00:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
b58044ac7a chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/cli (#8998)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.13.0 to 4.14.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/agronholm/anyio/releases">anyio's
releases</a>.</em></p>
<blockquote>
<h2>4.14.2</h2>
<ul>
<li>Changed <code>ByteReceiveStream.receive()</code> implementations to
raise a <code>ValueError</code> when <code>max_bytes</code> is not a
positive integer (<a
href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting
<code>float(&quot;inf&quot;)</code> when the limiter was instantiated
outside of an event loop. The adapter setter checked for infinity by
identity (<code>value is math.inf</code>), so only the exact
<code>math.inf</code> singleton was accepted, while every backend setter
(using <code>math.isinf()</code>) accepts any positive infinity (<a
href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>;
PR by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a>).</li>
<li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker
function writes enough data to <code>sys.stderr</code> to fill the
(undrained) pipe buffer. The worker process now redirects
<code>sys.stderr</code> to <code>os.devnull</code> as well, matching the
documented behavior</li>
<li>Fixed <code>TLSStream.wrap()</code> matching an internationalized
(unicode) host name against the peer certificate using IDNA 2003 (via
the standard library) instead of IDNA 2008, which could cause the host
name to be matched against the wrong certificate (<a
href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li>
<li>Fixed <code>anyio.open_process()</code> (and
<code>run_process()</code>) ignoring the <code>extra_groups</code>
argument, as it mistakenly passed the value of the <code>group</code>
argument instead (<a
href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li>
<li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and
<code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising
<code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on
the <code>trio</code> backend when there are no tokens available (<a
href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li>
<li>Fixed <code>CapacityLimiter</code> on the asyncio backend
over-granting tokens (<code>borrowed_tokens</code> exceeding
<code>total_tokens</code> and <code>available_tokens</code> going
negative) when a non-blocking acquire was made in the window between a
token being released and the notified waiter resuming. The freed token
is now reserved for the woken waiter right away, so the non-blocking
acquire correctly raises <code>WouldBlock</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>;
PR by <a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a>)</li>
<li>Fixed unnecessary CPU spin when delivering cancellation from
<code>CancelScope</code> on asyncio under certain conditions, including
improper cancel scope nesting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li>
</ul>
<h2>4.14.1</h2>
<ul>
<li>Fixed teardown of higher-scoped async fixtures failing on asyncio
with <code>RuntimeError: Attempted to exit cancel scope in a different
task than it was entered in</code> when an async test raise an outcome
exception (e.g., <code>pytest.skip()</code>,
<code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a
href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of
<code>0</code> when the limiter was instantiated outside of an event
loop, contradicting the documented behavior of allowing 0 total tokens
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>;
PR by <a
href="https://github.com/nyxst4ck"><code>@​nyxst4ck</code></a>)</li>
</ul>
<h2>4.14.0</h2>
<ul>
<li>
<p>Added support for Python 3.15</p>
</li>
<li>
<p>Added an asynchronous implementation of the <code>itertools</code>
module (<a
href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>;
PR by <a href="https://github.com/11kkw"><code>@​11kkw</code></a>)</p>
</li>
<li>
<p>Added the <code>local_port</code> parameter to
<code>connect_tcp()</code> to allow binding to a specific local port
before connecting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>;
PR by <a
href="https://github.com/nullwiz"><code>@​nullwiz</code></a>)</p>
</li>
<li>
<p>Added support for custom capacity limiters in async path and file I/O
functions and classes</p>
</li>
<li>
<p>Added the <code>create_task()</code> task group method for easier
asyncio migration (returns a <code>TaskHandle</code>) (<a
href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p>
</li>
<li>
<p>Changed <code>TaskGroup.start_soon()</code> to return a
<code>TaskHandle</code></p>
</li>
<li>
<p>Added an option for <code>TaskGroup.start()</code> to return a
<code>TaskHandle</code> (which then contains the start value in the
<code>start_value</code> property)</p>
</li>
<li>
<p>Added the <code>cancel()</code> convenience method to
<code>TaskGroup</code> as a shortcut for cancelling the task group's
cancel scope</p>
</li>
<li>
<p>Improved the error message when a known backend is not installed to
suggest the install command (<a
href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Improved <code>anyio.Path</code> to preserve subclass types by
returning <code>Self</code> in methods that return path objects (<a
href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Changed the parameter type annotation in
<code>anyio.Path.write_bytes()</code> to accept any
<code>ReadableBuffer</code>, thus allowing it to accept
<code>bytearray</code> and <code>memoryview</code> to match
<code>pathlib.Path.write_bytes()</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>;
PR by <a href="https://github.com/SAY-5"><code>@​SAY-5</code></a>)</p>
</li>
<li>
<p>Changed several type annotations to only accept callables returning
coroutine-like objects instead of arbitrary awaitables:</p>
<ul>
<li><code>TaskGroup.start_soon()</code></li>
<li><code>TaskGroup.start()</code></li>
<li><code>anyio.from_thread.run()</code></li>
</ul>
<p>This reverts an earlier change from v3.7.0 which was made in error.
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p>
</li>
<li>
<p>Changed <code>anyio.run</code> to support callables returning
arbitrary awaitables at runtime on all backends. Previously, this only
worked on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>;
PR by <a
href="https://github.com/gschaffner"><code>@​gschaffner</code></a>)</p>
</li>
<li>
<p>Changed several classes (and their subclasses) to have
<code>__slots__</code> (with <code>__weakref__</code>):</p>
<ul>
<li><code>anyio.CancelScope</code></li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a>
Bumped up the version</li>
<li><a
href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a>
Fixed 100% CPU spin on cancel scope misuse (<a
href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a>
Fix CapacityLimiter over-granting tokens on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a>
Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less
flaky</li>
<li><a
href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a>
Relaxed timeouts to fix test flakiness</li>
<li><a
href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a>
Fix test flakiness caused by slow callback duration logging</li>
<li><a
href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a>
Fixed CapacityLimiter raising trio.WouldBlock instead of
anyio.WouldBlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li>
<li><a
href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a>
Pin setup-uv to a commit sha across downstream jobs (<a
href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a>
Fixed stderr writes in a worker subprocess causing a deadlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a>
Fix flaky test_tcp_listener_same_port using a hardcoded port (<a
href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/agronholm/anyio/compare/4.13.0...4.14.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=anyio&package-manager=uv&previous-version=4.13.0&new-version=4.14.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-18 23:29:43 +00:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
daa514a988 chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/checkpoint-conformance (#8996)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.13.0 to 4.14.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/agronholm/anyio/releases">anyio's
releases</a>.</em></p>
<blockquote>
<h2>4.14.2</h2>
<ul>
<li>Changed <code>ByteReceiveStream.receive()</code> implementations to
raise a <code>ValueError</code> when <code>max_bytes</code> is not a
positive integer (<a
href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting
<code>float(&quot;inf&quot;)</code> when the limiter was instantiated
outside of an event loop. The adapter setter checked for infinity by
identity (<code>value is math.inf</code>), so only the exact
<code>math.inf</code> singleton was accepted, while every backend setter
(using <code>math.isinf()</code>) accepts any positive infinity (<a
href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>;
PR by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a>).</li>
<li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker
function writes enough data to <code>sys.stderr</code> to fill the
(undrained) pipe buffer. The worker process now redirects
<code>sys.stderr</code> to <code>os.devnull</code> as well, matching the
documented behavior</li>
<li>Fixed <code>TLSStream.wrap()</code> matching an internationalized
(unicode) host name against the peer certificate using IDNA 2003 (via
the standard library) instead of IDNA 2008, which could cause the host
name to be matched against the wrong certificate (<a
href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li>
<li>Fixed <code>anyio.open_process()</code> (and
<code>run_process()</code>) ignoring the <code>extra_groups</code>
argument, as it mistakenly passed the value of the <code>group</code>
argument instead (<a
href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li>
<li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and
<code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising
<code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on
the <code>trio</code> backend when there are no tokens available (<a
href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li>
<li>Fixed <code>CapacityLimiter</code> on the asyncio backend
over-granting tokens (<code>borrowed_tokens</code> exceeding
<code>total_tokens</code> and <code>available_tokens</code> going
negative) when a non-blocking acquire was made in the window between a
token being released and the notified waiter resuming. The freed token
is now reserved for the woken waiter right away, so the non-blocking
acquire correctly raises <code>WouldBlock</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>;
PR by <a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a>)</li>
<li>Fixed unnecessary CPU spin when delivering cancellation from
<code>CancelScope</code> on asyncio under certain conditions, including
improper cancel scope nesting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li>
</ul>
<h2>4.14.1</h2>
<ul>
<li>Fixed teardown of higher-scoped async fixtures failing on asyncio
with <code>RuntimeError: Attempted to exit cancel scope in a different
task than it was entered in</code> when an async test raise an outcome
exception (e.g., <code>pytest.skip()</code>,
<code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a
href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of
<code>0</code> when the limiter was instantiated outside of an event
loop, contradicting the documented behavior of allowing 0 total tokens
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>;
PR by <a
href="https://github.com/nyxst4ck"><code>@​nyxst4ck</code></a>)</li>
</ul>
<h2>4.14.0</h2>
<ul>
<li>
<p>Added support for Python 3.15</p>
</li>
<li>
<p>Added an asynchronous implementation of the <code>itertools</code>
module (<a
href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>;
PR by <a href="https://github.com/11kkw"><code>@​11kkw</code></a>)</p>
</li>
<li>
<p>Added the <code>local_port</code> parameter to
<code>connect_tcp()</code> to allow binding to a specific local port
before connecting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>;
PR by <a
href="https://github.com/nullwiz"><code>@​nullwiz</code></a>)</p>
</li>
<li>
<p>Added support for custom capacity limiters in async path and file I/O
functions and classes</p>
</li>
<li>
<p>Added the <code>create_task()</code> task group method for easier
asyncio migration (returns a <code>TaskHandle</code>) (<a
href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p>
</li>
<li>
<p>Changed <code>TaskGroup.start_soon()</code> to return a
<code>TaskHandle</code></p>
</li>
<li>
<p>Added an option for <code>TaskGroup.start()</code> to return a
<code>TaskHandle</code> (which then contains the start value in the
<code>start_value</code> property)</p>
</li>
<li>
<p>Added the <code>cancel()</code> convenience method to
<code>TaskGroup</code> as a shortcut for cancelling the task group's
cancel scope</p>
</li>
<li>
<p>Improved the error message when a known backend is not installed to
suggest the install command (<a
href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Improved <code>anyio.Path</code> to preserve subclass types by
returning <code>Self</code> in methods that return path objects (<a
href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Changed the parameter type annotation in
<code>anyio.Path.write_bytes()</code> to accept any
<code>ReadableBuffer</code>, thus allowing it to accept
<code>bytearray</code> and <code>memoryview</code> to match
<code>pathlib.Path.write_bytes()</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>;
PR by <a href="https://github.com/SAY-5"><code>@​SAY-5</code></a>)</p>
</li>
<li>
<p>Changed several type annotations to only accept callables returning
coroutine-like objects instead of arbitrary awaitables:</p>
<ul>
<li><code>TaskGroup.start_soon()</code></li>
<li><code>TaskGroup.start()</code></li>
<li><code>anyio.from_thread.run()</code></li>
</ul>
<p>This reverts an earlier change from v3.7.0 which was made in error.
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p>
</li>
<li>
<p>Changed <code>anyio.run</code> to support callables returning
arbitrary awaitables at runtime on all backends. Previously, this only
worked on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>;
PR by <a
href="https://github.com/gschaffner"><code>@​gschaffner</code></a>)</p>
</li>
<li>
<p>Changed several classes (and their subclasses) to have
<code>__slots__</code> (with <code>__weakref__</code>):</p>
<ul>
<li><code>anyio.CancelScope</code></li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a>
Bumped up the version</li>
<li><a
href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a>
Fixed 100% CPU spin on cancel scope misuse (<a
href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a>
Fix CapacityLimiter over-granting tokens on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a>
Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less
flaky</li>
<li><a
href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a>
Relaxed timeouts to fix test flakiness</li>
<li><a
href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a>
Fix test flakiness caused by slow callback duration logging</li>
<li><a
href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a>
Fixed CapacityLimiter raising trio.WouldBlock instead of
anyio.WouldBlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li>
<li><a
href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a>
Pin setup-uv to a commit sha across downstream jobs (<a
href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a>
Fixed stderr writes in a worker subprocess causing a deadlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a>
Fix flaky test_tcp_listener_same_port using a hardcoded port (<a
href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/agronholm/anyio/compare/4.13.0...4.14.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=anyio&package-manager=uv&previous-version=4.13.0&new-version=4.14.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-18 15:36:37 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
022043a679 chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint (#8995)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.12.1 to 4.14.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/agronholm/anyio/releases">anyio's
releases</a>.</em></p>
<blockquote>
<h2>4.14.2</h2>
<ul>
<li>Changed <code>ByteReceiveStream.receive()</code> implementations to
raise a <code>ValueError</code> when <code>max_bytes</code> is not a
positive integer (<a
href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting
<code>float(&quot;inf&quot;)</code> when the limiter was instantiated
outside of an event loop. The adapter setter checked for infinity by
identity (<code>value is math.inf</code>), so only the exact
<code>math.inf</code> singleton was accepted, while every backend setter
(using <code>math.isinf()</code>) accepts any positive infinity (<a
href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>;
PR by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a>).</li>
<li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker
function writes enough data to <code>sys.stderr</code> to fill the
(undrained) pipe buffer. The worker process now redirects
<code>sys.stderr</code> to <code>os.devnull</code> as well, matching the
documented behavior</li>
<li>Fixed <code>TLSStream.wrap()</code> matching an internationalized
(unicode) host name against the peer certificate using IDNA 2003 (via
the standard library) instead of IDNA 2008, which could cause the host
name to be matched against the wrong certificate (<a
href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li>
<li>Fixed <code>anyio.open_process()</code> (and
<code>run_process()</code>) ignoring the <code>extra_groups</code>
argument, as it mistakenly passed the value of the <code>group</code>
argument instead (<a
href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li>
<li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and
<code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising
<code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on
the <code>trio</code> backend when there are no tokens available (<a
href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li>
<li>Fixed <code>CapacityLimiter</code> on the asyncio backend
over-granting tokens (<code>borrowed_tokens</code> exceeding
<code>total_tokens</code> and <code>available_tokens</code> going
negative) when a non-blocking acquire was made in the window between a
token being released and the notified waiter resuming. The freed token
is now reserved for the woken waiter right away, so the non-blocking
acquire correctly raises <code>WouldBlock</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>;
PR by <a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a>)</li>
<li>Fixed unnecessary CPU spin when delivering cancellation from
<code>CancelScope</code> on asyncio under certain conditions, including
improper cancel scope nesting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li>
</ul>
<h2>4.14.1</h2>
<ul>
<li>Fixed teardown of higher-scoped async fixtures failing on asyncio
with <code>RuntimeError: Attempted to exit cancel scope in a different
task than it was entered in</code> when an async test raise an outcome
exception (e.g., <code>pytest.skip()</code>,
<code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a
href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of
<code>0</code> when the limiter was instantiated outside of an event
loop, contradicting the documented behavior of allowing 0 total tokens
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>;
PR by <a
href="https://github.com/nyxst4ck"><code>@​nyxst4ck</code></a>)</li>
</ul>
<h2>4.14.0</h2>
<ul>
<li>
<p>Added support for Python 3.15</p>
</li>
<li>
<p>Added an asynchronous implementation of the <code>itertools</code>
module (<a
href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>;
PR by <a href="https://github.com/11kkw"><code>@​11kkw</code></a>)</p>
</li>
<li>
<p>Added the <code>local_port</code> parameter to
<code>connect_tcp()</code> to allow binding to a specific local port
before connecting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>;
PR by <a
href="https://github.com/nullwiz"><code>@​nullwiz</code></a>)</p>
</li>
<li>
<p>Added support for custom capacity limiters in async path and file I/O
functions and classes</p>
</li>
<li>
<p>Added the <code>create_task()</code> task group method for easier
asyncio migration (returns a <code>TaskHandle</code>) (<a
href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p>
</li>
<li>
<p>Changed <code>TaskGroup.start_soon()</code> to return a
<code>TaskHandle</code></p>
</li>
<li>
<p>Added an option for <code>TaskGroup.start()</code> to return a
<code>TaskHandle</code> (which then contains the start value in the
<code>start_value</code> property)</p>
</li>
<li>
<p>Added the <code>cancel()</code> convenience method to
<code>TaskGroup</code> as a shortcut for cancelling the task group's
cancel scope</p>
</li>
<li>
<p>Improved the error message when a known backend is not installed to
suggest the install command (<a
href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Improved <code>anyio.Path</code> to preserve subclass types by
returning <code>Self</code> in methods that return path objects (<a
href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Changed the parameter type annotation in
<code>anyio.Path.write_bytes()</code> to accept any
<code>ReadableBuffer</code>, thus allowing it to accept
<code>bytearray</code> and <code>memoryview</code> to match
<code>pathlib.Path.write_bytes()</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>;
PR by <a href="https://github.com/SAY-5"><code>@​SAY-5</code></a>)</p>
</li>
<li>
<p>Changed several type annotations to only accept callables returning
coroutine-like objects instead of arbitrary awaitables:</p>
<ul>
<li><code>TaskGroup.start_soon()</code></li>
<li><code>TaskGroup.start()</code></li>
<li><code>anyio.from_thread.run()</code></li>
</ul>
<p>This reverts an earlier change from v3.7.0 which was made in error.
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p>
</li>
<li>
<p>Changed <code>anyio.run</code> to support callables returning
arbitrary awaitables at runtime on all backends. Previously, this only
worked on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>;
PR by <a
href="https://github.com/gschaffner"><code>@​gschaffner</code></a>)</p>
</li>
<li>
<p>Changed several classes (and their subclasses) to have
<code>__slots__</code> (with <code>__weakref__</code>):</p>
<ul>
<li><code>anyio.CancelScope</code></li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a>
Bumped up the version</li>
<li><a
href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a>
Fixed 100% CPU spin on cancel scope misuse (<a
href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a>
Fix CapacityLimiter over-granting tokens on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a>
Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less
flaky</li>
<li><a
href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a>
Relaxed timeouts to fix test flakiness</li>
<li><a
href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a>
Fix test flakiness caused by slow callback duration logging</li>
<li><a
href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a>
Fixed CapacityLimiter raising trio.WouldBlock instead of
anyio.WouldBlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li>
<li><a
href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a>
Pin setup-uv to a commit sha across downstream jobs (<a
href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a>
Fixed stderr writes in a worker subprocess causing a deadlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a>
Fix flaky test_tcp_listener_same_port using a hardcoded port (<a
href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/agronholm/anyio/compare/4.12.1...4.14.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=anyio&package-manager=uv&previous-version=4.12.1&new-version=4.14.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-18 15:24:38 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
d7b99cc3ab chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/sdk-py (#8994)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.12.1 to 4.14.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/agronholm/anyio/releases">anyio's
releases</a>.</em></p>
<blockquote>
<h2>4.14.2</h2>
<ul>
<li>Changed <code>ByteReceiveStream.receive()</code> implementations to
raise a <code>ValueError</code> when <code>max_bytes</code> is not a
positive integer (<a
href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting
<code>float(&quot;inf&quot;)</code> when the limiter was instantiated
outside of an event loop. The adapter setter checked for infinity by
identity (<code>value is math.inf</code>), so only the exact
<code>math.inf</code> singleton was accepted, while every backend setter
(using <code>math.isinf()</code>) accepts any positive infinity (<a
href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>;
PR by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a>).</li>
<li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker
function writes enough data to <code>sys.stderr</code> to fill the
(undrained) pipe buffer. The worker process now redirects
<code>sys.stderr</code> to <code>os.devnull</code> as well, matching the
documented behavior</li>
<li>Fixed <code>TLSStream.wrap()</code> matching an internationalized
(unicode) host name against the peer certificate using IDNA 2003 (via
the standard library) instead of IDNA 2008, which could cause the host
name to be matched against the wrong certificate (<a
href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li>
<li>Fixed <code>anyio.open_process()</code> (and
<code>run_process()</code>) ignoring the <code>extra_groups</code>
argument, as it mistakenly passed the value of the <code>group</code>
argument instead (<a
href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li>
<li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and
<code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising
<code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on
the <code>trio</code> backend when there are no tokens available (<a
href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li>
<li>Fixed <code>CapacityLimiter</code> on the asyncio backend
over-granting tokens (<code>borrowed_tokens</code> exceeding
<code>total_tokens</code> and <code>available_tokens</code> going
negative) when a non-blocking acquire was made in the window between a
token being released and the notified waiter resuming. The freed token
is now reserved for the woken waiter right away, so the non-blocking
acquire correctly raises <code>WouldBlock</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>;
PR by <a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a>)</li>
<li>Fixed unnecessary CPU spin when delivering cancellation from
<code>CancelScope</code> on asyncio under certain conditions, including
improper cancel scope nesting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li>
</ul>
<h2>4.14.1</h2>
<ul>
<li>Fixed teardown of higher-scoped async fixtures failing on asyncio
with <code>RuntimeError: Attempted to exit cancel scope in a different
task than it was entered in</code> when an async test raise an outcome
exception (e.g., <code>pytest.skip()</code>,
<code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a
href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of
<code>0</code> when the limiter was instantiated outside of an event
loop, contradicting the documented behavior of allowing 0 total tokens
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>;
PR by <a
href="https://github.com/nyxst4ck"><code>@​nyxst4ck</code></a>)</li>
</ul>
<h2>4.14.0</h2>
<ul>
<li>
<p>Added support for Python 3.15</p>
</li>
<li>
<p>Added an asynchronous implementation of the <code>itertools</code>
module (<a
href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>;
PR by <a href="https://github.com/11kkw"><code>@​11kkw</code></a>)</p>
</li>
<li>
<p>Added the <code>local_port</code> parameter to
<code>connect_tcp()</code> to allow binding to a specific local port
before connecting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>;
PR by <a
href="https://github.com/nullwiz"><code>@​nullwiz</code></a>)</p>
</li>
<li>
<p>Added support for custom capacity limiters in async path and file I/O
functions and classes</p>
</li>
<li>
<p>Added the <code>create_task()</code> task group method for easier
asyncio migration (returns a <code>TaskHandle</code>) (<a
href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p>
</li>
<li>
<p>Changed <code>TaskGroup.start_soon()</code> to return a
<code>TaskHandle</code></p>
</li>
<li>
<p>Added an option for <code>TaskGroup.start()</code> to return a
<code>TaskHandle</code> (which then contains the start value in the
<code>start_value</code> property)</p>
</li>
<li>
<p>Added the <code>cancel()</code> convenience method to
<code>TaskGroup</code> as a shortcut for cancelling the task group's
cancel scope</p>
</li>
<li>
<p>Improved the error message when a known backend is not installed to
suggest the install command (<a
href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Improved <code>anyio.Path</code> to preserve subclass types by
returning <code>Self</code> in methods that return path objects (<a
href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Changed the parameter type annotation in
<code>anyio.Path.write_bytes()</code> to accept any
<code>ReadableBuffer</code>, thus allowing it to accept
<code>bytearray</code> and <code>memoryview</code> to match
<code>pathlib.Path.write_bytes()</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>;
PR by <a href="https://github.com/SAY-5"><code>@​SAY-5</code></a>)</p>
</li>
<li>
<p>Changed several type annotations to only accept callables returning
coroutine-like objects instead of arbitrary awaitables:</p>
<ul>
<li><code>TaskGroup.start_soon()</code></li>
<li><code>TaskGroup.start()</code></li>
<li><code>anyio.from_thread.run()</code></li>
</ul>
<p>This reverts an earlier change from v3.7.0 which was made in error.
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p>
</li>
<li>
<p>Changed <code>anyio.run</code> to support callables returning
arbitrary awaitables at runtime on all backends. Previously, this only
worked on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>;
PR by <a
href="https://github.com/gschaffner"><code>@​gschaffner</code></a>)</p>
</li>
<li>
<p>Changed several classes (and their subclasses) to have
<code>__slots__</code> (with <code>__weakref__</code>):</p>
<ul>
<li><code>anyio.CancelScope</code></li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a>
Bumped up the version</li>
<li><a
href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a>
Fixed 100% CPU spin on cancel scope misuse (<a
href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a>
Fix CapacityLimiter over-granting tokens on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a>
Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less
flaky</li>
<li><a
href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a>
Relaxed timeouts to fix test flakiness</li>
<li><a
href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a>
Fix test flakiness caused by slow callback duration logging</li>
<li><a
href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a>
Fixed CapacityLimiter raising trio.WouldBlock instead of
anyio.WouldBlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li>
<li><a
href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a>
Pin setup-uv to a commit sha across downstream jobs (<a
href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a>
Fixed stderr writes in a worker subprocess causing a deadlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a>
Fix flaky test_tcp_listener_same_port using a hardcoded port (<a
href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/agronholm/anyio/compare/4.12.1...4.14.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=anyio&package-manager=uv&previous-version=4.12.1&new-version=4.14.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-18 15:24:34 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
b19edd783b chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint-sqlite (#8993)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.12.1 to 4.14.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/agronholm/anyio/releases">anyio's
releases</a>.</em></p>
<blockquote>
<h2>4.14.2</h2>
<ul>
<li>Changed <code>ByteReceiveStream.receive()</code> implementations to
raise a <code>ValueError</code> when <code>max_bytes</code> is not a
positive integer (<a
href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting
<code>float(&quot;inf&quot;)</code> when the limiter was instantiated
outside of an event loop. The adapter setter checked for infinity by
identity (<code>value is math.inf</code>), so only the exact
<code>math.inf</code> singleton was accepted, while every backend setter
(using <code>math.isinf()</code>) accepts any positive infinity (<a
href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>;
PR by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a>).</li>
<li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker
function writes enough data to <code>sys.stderr</code> to fill the
(undrained) pipe buffer. The worker process now redirects
<code>sys.stderr</code> to <code>os.devnull</code> as well, matching the
documented behavior</li>
<li>Fixed <code>TLSStream.wrap()</code> matching an internationalized
(unicode) host name against the peer certificate using IDNA 2003 (via
the standard library) instead of IDNA 2008, which could cause the host
name to be matched against the wrong certificate (<a
href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li>
<li>Fixed <code>anyio.open_process()</code> (and
<code>run_process()</code>) ignoring the <code>extra_groups</code>
argument, as it mistakenly passed the value of the <code>group</code>
argument instead (<a
href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li>
<li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and
<code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising
<code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on
the <code>trio</code> backend when there are no tokens available (<a
href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li>
<li>Fixed <code>CapacityLimiter</code> on the asyncio backend
over-granting tokens (<code>borrowed_tokens</code> exceeding
<code>total_tokens</code> and <code>available_tokens</code> going
negative) when a non-blocking acquire was made in the window between a
token being released and the notified waiter resuming. The freed token
is now reserved for the woken waiter right away, so the non-blocking
acquire correctly raises <code>WouldBlock</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>;
PR by <a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a>)</li>
<li>Fixed unnecessary CPU spin when delivering cancellation from
<code>CancelScope</code> on asyncio under certain conditions, including
improper cancel scope nesting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li>
</ul>
<h2>4.14.1</h2>
<ul>
<li>Fixed teardown of higher-scoped async fixtures failing on asyncio
with <code>RuntimeError: Attempted to exit cancel scope in a different
task than it was entered in</code> when an async test raise an outcome
exception (e.g., <code>pytest.skip()</code>,
<code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a
href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</li>
<li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of
<code>0</code> when the limiter was instantiated outside of an event
loop, contradicting the documented behavior of allowing 0 total tokens
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>;
PR by <a
href="https://github.com/nyxst4ck"><code>@​nyxst4ck</code></a>)</li>
</ul>
<h2>4.14.0</h2>
<ul>
<li>
<p>Added support for Python 3.15</p>
</li>
<li>
<p>Added an asynchronous implementation of the <code>itertools</code>
module (<a
href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>;
PR by <a href="https://github.com/11kkw"><code>@​11kkw</code></a>)</p>
</li>
<li>
<p>Added the <code>local_port</code> parameter to
<code>connect_tcp()</code> to allow binding to a specific local port
before connecting (<a
href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>;
PR by <a
href="https://github.com/nullwiz"><code>@​nullwiz</code></a>)</p>
</li>
<li>
<p>Added support for custom capacity limiters in async path and file I/O
functions and classes</p>
</li>
<li>
<p>Added the <code>create_task()</code> task group method for easier
asyncio migration (returns a <code>TaskHandle</code>) (<a
href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p>
</li>
<li>
<p>Changed <code>TaskGroup.start_soon()</code> to return a
<code>TaskHandle</code></p>
</li>
<li>
<p>Added an option for <code>TaskGroup.start()</code> to return a
<code>TaskHandle</code> (which then contains the start value in the
<code>start_value</code> property)</p>
</li>
<li>
<p>Added the <code>cancel()</code> convenience method to
<code>TaskGroup</code> as a shortcut for cancelling the task group's
cancel scope</p>
</li>
<li>
<p>Improved the error message when a known backend is not installed to
suggest the install command (<a
href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Improved <code>anyio.Path</code> to preserve subclass types by
returning <code>Self</code> in methods that return path objects (<a
href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>;
PR by <a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>)</p>
</li>
<li>
<p>Changed the parameter type annotation in
<code>anyio.Path.write_bytes()</code> to accept any
<code>ReadableBuffer</code>, thus allowing it to accept
<code>bytearray</code> and <code>memoryview</code> to match
<code>pathlib.Path.write_bytes()</code> (<a
href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>;
PR by <a href="https://github.com/SAY-5"><code>@​SAY-5</code></a>)</p>
</li>
<li>
<p>Changed several type annotations to only accept callables returning
coroutine-like objects instead of arbitrary awaitables:</p>
<ul>
<li><code>TaskGroup.start_soon()</code></li>
<li><code>TaskGroup.start()</code></li>
<li><code>anyio.from_thread.run()</code></li>
</ul>
<p>This reverts an earlier change from v3.7.0 which was made in error.
(<a
href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p>
</li>
<li>
<p>Changed <code>anyio.run</code> to support callables returning
arbitrary awaitables at runtime on all backends. Previously, this only
worked on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>;
PR by <a
href="https://github.com/gschaffner"><code>@​gschaffner</code></a>)</p>
</li>
<li>
<p>Changed several classes (and their subclasses) to have
<code>__slots__</code> (with <code>__weakref__</code>):</p>
<ul>
<li><code>anyio.CancelScope</code></li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a>
Bumped up the version</li>
<li><a
href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a>
Fixed 100% CPU spin on cancel scope misuse (<a
href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a>
Fix CapacityLimiter over-granting tokens on asyncio (<a
href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a>
Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less
flaky</li>
<li><a
href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a>
Relaxed timeouts to fix test flakiness</li>
<li><a
href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a>
Fix test flakiness caused by slow callback duration logging</li>
<li><a
href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a>
Fixed CapacityLimiter raising trio.WouldBlock instead of
anyio.WouldBlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li>
<li><a
href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a>
Pin setup-uv to a commit sha across downstream jobs (<a
href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a>
Fixed stderr writes in a worker subprocess causing a deadlock (<a
href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li>
<li><a
href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a>
Fix flaky test_tcp_listener_same_port using a hardcoded port (<a
href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/agronholm/anyio/compare/4.12.1...4.14.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=anyio&package-manager=uv&previous-version=4.12.1&new-version=4.14.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-18 15:24:12 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
c81c13533e chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/langgraph (#8958)
Bumps [soupsieve](https://github.com/facelessuser/soupsieve) from 2.8.4
to 2.9.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/facelessuser/soupsieve/releases">soupsieve's
releases</a>.</em></p>
<blockquote>
<h2>2.9</h2>
<ul>
<li><strong>NEW</strong>: Drop Python 3.9 support.</li>
<li><strong>NEW</strong>: Lazy compile selector patterns to improve
initial import speed.</li>
<li><strong>FIX</strong>: Correct
<code>:nth-child</code>/<code>:nth-of-type</code> (and
<code>-last-</code> variants) for <code>An+B</code> values whose
sequence steps onto
index 0 or onto the last child (e.g. <code>:nth-child(2n-2)</code>,
<code>:nth-child(n-1)</code>, <code>:nth-child(n+5)</code>), which
previously
matched the wrong elements or nothing at all (<a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a>).</li>
<li><strong>FIX</strong>: More efficient CSS ID matching (<a
href="https://github.com/kaimandalic"><code>@​kaimandalic</code></a>).</li>
<li><strong>FIX</strong>: Fix inefficient trimming of comments and white
space (<a
href="https://github.com/kaimandalic"><code>@​kaimandalic</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004"><code>8763f91</code></a>
Format changelog message</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda"><code>cf198fc</code></a>
Fix inefficient trimming of comments and white space</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef"><code>ce44e49</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19"><code>751c57b</code></a>
Fix :nth-child/:nth-of-type matching for An+B index boundaries (<a
href="https://redirect.github.com/facelessuser/soupsieve/issues/297">#297</a>)</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b"><code>08e9ede</code></a>
Drop Python 3.9</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81"><code>d6e6830</code></a>
Rework selector mapping</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3"><code>d2d1581</code></a>
Utilize property for accessing lazy regular expression pattern</li>
<li><a
href="https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d"><code>b8701de</code></a>
Build patterns and regexes lazily in css_parser (<a
href="https://redirect.github.com/facelessuser/soupsieve/issues/296">#296</a>)</li>
<li>See full diff in <a
href="https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=soupsieve&package-manager=uv&previous-version=2.8.4&new-version=2.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-17 20:18:46 -07:00
Elior Nataf LackritzandGitHub 448a763779 feat(langgraph): add response_schema to interrupt() (#8886)
Adds an optional keyword-only `response_schema` to `interrupt()`,
carried on `Interrupt.response_schema` as JSON Schema so clients
(LangGraph Studio first) can render a typed form for the resume value
instead of a free-form JSON box. Default `None`, so nothing changes for
existing graphs.

- Accepts a JSON Schema dict (passed through, not validated) or a
Pydantic model / `TypedDict` / dataclass, converted with
`TypeAdapter.json_schema()`. For those, the resume value is validated
and the validated object is what `interrupt()` returns; an invalid value
raises from the node before it is committed, so the next resume works.
- Additive on the `stream_mode="debug"` payload: interrupt dicts gain
`response_schema` (it is a dataclass field, serialized with `asdict`).
- `libs/sdk-py`: mirrors the field on the `Interrupt` TypedDict as
`NotRequired`; the server omits the key when no schema was given.

JS counterpart: langchain-ai/langgraphjs#2824.

Verified: new tests parametrized across every checkpointer backend
(schema kinds, coercion, invalid resume) plus the full `libs/langgraph`
suite and downstream `prebuilt`, `cli`, `sdk-py`; round-tripped end to
end through the agent server with this branch installed.
2026-09-17 11:33:37 -04:00
John KennedyGitHublangsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
e539ac122f chore(deps): fix vulnerable dev dependencies (#8449)
## Summary
Patch both `js-yaml` release lines in `libs/cli/js-examples` for
GHSA-2883-xcg3-v3hh: Jest's transitive copy to 3.15.2 and ESLint's to
4.3.2. Updates the existing fix rather than opening a duplicate; no
runtime dependencies added and no major-version overrides.

Addresses Dependabot alerts
[#398](https://github.com/langchain-ai/langgraph/security/dependabot/398)
and
[#397](https://github.com/langchain-ai/langgraph/security/dependabot/397).
These are real vulnerable versions in example development tooling; patch
rather than dismiss. Alerts remain open until this reaches `main` and
GitHub rescans.

## Verification
- [x] Yarn 1.22.22 regenerated the lockfile with lifecycle scripts
disabled; diff limited to the two js-yaml entries and scoped
resolutions.
- [x] `yarn install --frozen-lockfile --ignore-scripts --force
--non-interactive` in `libs/cli/js-examples`.
- [x] `yarn why js-yaml`: ESLint 4.3.2 and Jest/Istanbul 3.15.2.
- [x] Resolved versions checked against freshly retrieved GitHub
advisory patched versions for both alerts.
- [x] `yarn format:check` and `git diff --check`.
- [ ] Build fails in unchanged `tests/graph.int.test.ts:7`: `input` is
not a valid update property (also recorded in the earlier PR
verification).
- [ ] Unit-test script fails because it uses Jest's removed
`--testPathPattern` option; Jest requires `--testPathPatterns`.
- [ ] Lint fails because ESLint 10 requires `eslint.config.*`, which
this example lacks.

The build/test/lint configuration issues are outside this scoped
dependency patch and remain unresolved. No full test-pass claim.

---------

Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
2026-09-09 00:22:43 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>John Kennedy
ff4529380d chore(deps): bump httpx2 from 2.10.0 to 2.12.0 in /libs/cli (#8863)
Bumps [httpx2](https://github.com/pydantic/httpx2) from 2.10.0 to
2.12.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pydantic/httpx2/releases">httpx2's
releases</a>.</em></p>
<blockquote>
<h2>v2.12.0</h2>
<h2>Highlights</h2>
<h3>🛡️ Bounded response decompression</h3>
<p><code>httpx2</code> now decodes <code>gzip</code>,
<code>deflate</code>, Brotli, and Zstandard responses incrementally.
Each decode step emits at most 1 MiB, so streaming a highly compressed
response no longer requires materializing an entire inflated network
chunk in memory (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1126">pydantic/httpx2#1126</a>).</p>
<h3>📦 Shared Zstandard API</h3>
<p>Python 3.13 and earlier now use <code>backports.zstd</code>, which
provides the same bounded incremental decompression API as
<code>compression.zstd</code> on Python 3.14 and later (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1146">pydantic/httpx2#1146</a>).</p>
<h2>httpx2</h2>
<h3>Changed</h3>
<ul>
<li>Use <code>backports.zstd</code> for Zstandard decoding on Python
3.13 and earlier by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1146">pydantic/httpx2#1146</a></li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Bound peak memory while streaming compressed responses and close
response streams when decoding fails by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1126">pydantic/httpx2#1126</a></li>
</ul>
<h2>httpcore2</h2>
<p>No changes since <code>2.11.0</code>. Version bumped to stay in
lockstep with <code>httpx2</code>.</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/pydantic/httpx2/compare/v2.11.0...v2.12.0">https://github.com/pydantic/httpx2/compare/v2.11.0...v2.12.0</a></p>
<h2>v2.11.0</h2>
<h2>Highlights</h2>
<h3>🌐 Public origin API</h3>
<p><code>httpx2</code> now includes an immutable and hashable
<code>Origin</code> value object, available through
<code>URL.origin</code>. It provides normalized scheme, host, and
effective port comparisons without including URL paths, queries,
fragments, or credentials (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1134">pydantic/httpx2#1134</a>).</p>
<h3>🛠️ Request compatibility and validation</h3>
<ul>
<li>Explicit <code>Transfer-Encoding</code> headers now take precedence
over body-derived <code>Content-Length</code> headers (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1137">pydantic/httpx2#1137</a>).</li>
<li>Deprecated status code aliases are available again (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1135">pydantic/httpx2#1135</a>).</li>
<li>Multipart part headers are validated before serialization (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1142">pydantic/httpx2#1142</a>).</li>
</ul>
<h2>httpx2</h2>
<h3>Added</h3>
<ul>
<li>Add the public <code>Origin</code> value object and
<code>URL.origin</code> property by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1134">pydantic/httpx2#1134</a></li>
</ul>
<h3>Changed</h3>
<ul>
<li>Require Brotli 1.2.0 or later for the <code>brotli</code> extra by
<a href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1141">pydantic/httpx2#1141</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md">httpx2's
changelog</a>.</em></p>
<blockquote>
<h2>2.12.0 (August 18th, 2026)</h2>
<h3>Changed</h3>
<ul>
<li>Use <code>backports.zstd</code> for Zstandard decoding on Python
3.13 and earlier.
(<a
href="https://redirect.github.com/pydantic/httpx2/pull/1146">#1146</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Bound peak memory while streaming compressed responses and close
response streams when decoding fails.
(<a
href="https://redirect.github.com/pydantic/httpx2/pull/1126">#1126</a>)</li>
</ul>
<h2>2.11.0 (August 18th, 2026)</h2>
<h3>Added</h3>
<ul>
<li>Add the public <code>Origin</code> value object and
<code>URL.origin</code> property for normalized,
hashable origin comparisons. (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1134">#1134</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Require Brotli 1.2.0 or later for the <code>brotli</code> extra. (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1141">#1141</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Restore deprecated status code aliases. (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1135">#1135</a>)</li>
<li>Extract HTTP/2 release notes from changelog headings correctly. (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1136">#1136</a>)</li>
<li>Respect explicit <code>Transfer-Encoding</code> headers and expose
buffered request body lengths to WSGI applications.
(<a
href="https://redirect.github.com/pydantic/httpx2/pull/1137">#1137</a>)</li>
<li>Validate multipart part header names and values before
serialization.
(<a
href="https://redirect.github.com/pydantic/httpx2/pull/1142">#1142</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pydantic/httpx2/commit/71ae23be5448f859c2b4e21d9972ddfa7b8d759d"><code>71ae23b</code></a>
Version 2.12.0 (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1147">#1147</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8"><code>4fd0c70</code></a>
Decode compressed response bodies incrementally (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1126">#1126</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/d588e528a11eb20323031ee571fadc668bb81b3f"><code>d588e52</code></a>
Use <code>backports.zstd</code> on Python 3.13 and earlier (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1146">#1146</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/344589da2a992f7e5a0c25c68cc78c25ec6d70bd"><code>344589d</code></a>
Version 2.11.0 (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1143">#1143</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d"><code>de96d81</code></a>
Validate multipart part headers (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1142">#1142</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/51c32698ce029140cb69a26921d017e3edda80fa"><code>51c3269</code></a>
Require brotli 1.2.0 in the brotli extra (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1141">#1141</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab"><code>829b93a</code></a>
Respect explicit Transfer-Encoding headers (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1137">#1137</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/4fa6c8ee96fb79035c6820e4f44a10b6262d9c9f"><code>4fa6c8e</code></a>
Fix changelog extraction regex for H2 release headings (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1136">#1136</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/8a6f37063514ee2a2601607c20be72667fdfa3be"><code>8a6f370</code></a>
Restore deprecated status code aliases (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1135">#1135</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/d03f1ec6a1a323f951a8c21cd14f9c02f2d1e855"><code>d03f1ec</code></a>
Add public Origin API (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1134">#1134</a>)</li>
<li>See full diff in <a
href="https://github.com/pydantic/httpx2/compare/v2.10.0...v2.12.0">compare
view</a></li>
</ul>
</details>
<br />

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com>
2026-09-09 06:32:13 +00:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>John Kennedyopen-swe[bot] <open-swe@users.noreply.github.com>
c0b884e6d8 chore(deps): bump js-yaml from 4.3.1 to 4.3.2 in /libs/cli/js-monorepo-example (#8867)
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.1 to 4.3.2.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md">js-yaml's
changelog</a>.</em></p>
<blockquote>
<h2>4.3.2 - 2026-08-26</h2>
<h3>Changed</h3>
<ul>
<li>[backport] Hard-limit merge sequence size to 100.</li>
</ul>
<h3>Security</h3>
<ul>
<li>[backport] Count empty mappings in merge sequences toward
<code>maxTotalMergeKeys</code>
to limit CPU usage, <a
href="https://redirect.github.com/nodeca/js-yaml/issues/797">#797</a>.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191"><code>79ca68d</code></a>
4.3.2 released</li>
<li><a
href="https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b"><code>d90b661</code></a>
Backport merge limits from v5.4.1</li>
<li>See full diff in <a
href="https://github.com/nodeca/js-yaml/compare/4.3.1...4.3.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=js-yaml&package-manager=npm_and_yarn&previous-version=4.3.1&new-version=4.3.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-09 06:19:17 +00:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
3299a1f563 chore(deps): bump httpcore2 from 2.5.0 to 2.10.0 in /libs/cli (#8864)
Bumps [httpcore2](https://github.com/pydantic/httpx2) from 2.5.0 to
2.10.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pydantic/httpx2/releases">httpcore2's
releases</a>.</em></p>
<blockquote>
<h2>v2.10.0</h2>
<h2>Highlights</h2>
<h3>🚀 Performance and memory improvements</h3>
<ul>
<li>Sending large HTTP/2 request bodies no longer copies the body
quadratically - sending a 256 MiB body went from ~36s to under 0.1s (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1127">pydantic/httpx2#1127</a>).</li>
<li>SSE parsing is up to 35x faster on highly fragmented streams (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1117">pydantic/httpx2#1117</a>).</li>
<li>Cookie extraction is now skipped for responses without a
<code>Set-Cookie</code> header, making typical requests roughly 8%
faster (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1107">pydantic/httpx2#1107</a>).</li>
</ul>
<h3>🕸️ WebAssembly / Emscripten support</h3>
<p><code>httpx2</code> now runs on Pyodide / Emscripten, using a
JavaScript <code>fetch</code>-based transport defined in
<code>httpx2-jsfetch</code> (<a
href="https://redirect.github.com/pydantic/httpx2/pull/1119">pydantic/httpx2#1119</a>,
<a
href="https://redirect.github.com/pydantic/httpx2/pull/1114">pydantic/httpx2#1114</a>).
Thanks <a
href="https://github.com/hoodmane"><code>@​hoodmane</code></a>!</p>
<h2>httpx2</h2>
<h3>Added</h3>
<ul>
<li>Add support for running on WebAssembly / Emscripten via Pyodide by
<a href="https://github.com/hoodmane"><code>@​hoodmane</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1119">pydantic/httpx2#1119</a></li>
<li>Add <code>max_event_size</code> to cap SSE event buffering by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1071">pydantic/httpx2#1071</a></li>
<li>Add RFC 9110 status code constants by <a
href="https://github.com/mbeijen"><code>@​mbeijen</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1069">pydantic/httpx2#1069</a></li>
<li>Add support for Python 3.15 by <a
href="https://github.com/hugovk"><code>@​hugovk</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1090">pydantic/httpx2#1090</a></li>
</ul>
<h3>Changed</h3>
<ul>
<li>Improve SSE chunk buffering performance by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1117">pydantic/httpx2#1117</a></li>
<li>Skip cookie extraction without <code>Set-Cookie</code> by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1107">pydantic/httpx2#1107</a></li>
<li>Return <code>str | None</code> instead of <code>Any</code> from
<code>Headers.get</code> by <a
href="https://github.com/ItsDrike"><code>@​ItsDrike</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1121">pydantic/httpx2#1121</a></li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Enforce WebSocket max message size across fragments by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1085">pydantic/httpx2#1085</a></li>
<li>Ignore unsolicited and duplicate Pong frames by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1122">pydantic/httpx2#1122</a></li>
</ul>
<h2>httpcore2</h2>
<h3>Added</h3>
<ul>
<li>Add support for Python 3.15 by <a
href="https://github.com/hugovk"><code>@​hugovk</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1090">pydantic/httpx2#1090</a></li>
</ul>
<h3>Changed</h3>
<ul>
<li>Avoid quadratic copying when sending large HTTP/2 request bodies by
<a href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1127">pydantic/httpx2#1127</a></li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Propagate the original exception instead of raising
<code>KeyError</code> when an HTTP/2 stream fails by <a
href="https://github.com/yhay81"><code>@​yhay81</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1093">pydantic/httpx2#1093</a></li>
<li>Start TLS for the <code>wss</code> scheme in SOCKS5 proxy
connections by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/pydantic/httpx2/pull/1104">pydantic/httpx2#1104</a></li>
</ul>
<h2>🙏 New Contributors</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pydantic/httpx2/commit/a966320e75477b8c55ee78fdb8f57ead6a574cb0"><code>a966320</code></a>
Version 2.10.0 (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1129">#1129</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/586f968f5510aa4d3b7edd1f1b039684c42945ee"><code>586f968</code></a>
Avoid quadratic copying when sending large HTTP/2 request bodies (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1127">#1127</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/dee1d1ace3021404d0aa255957821eda97c94c43"><code>dee1d1a</code></a>
Return <code>str | None</code> instead of <code>Any</code> from
<code>Headers.get</code> (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1121">#1121</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/dec24ad57d1d337de7de23c011eb566a145e7b40"><code>dec24ad</code></a>
Use <code>httpx2-jsfetch</code> on Emscripten (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1119">#1119</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/454b8b2197f62d699ff3ad762917643926b4da77"><code>454b8b2</code></a>
Ignore unsolicited and duplicate Pong frames (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1122">#1122</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414"><code>cbfc0e0</code></a>
Improve SSE chunk buffering performance (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1117">#1117</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/ad141d876c7d3c3f58555cbb0a178ec2c1f15b51"><code>ad141d8</code></a>
Refactor SSE parser coordination (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1118">#1118</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/e0b01245e42d2091034ee9455cbb068bc0d6c0c6"><code>e0b0124</code></a>
Make <code>_client</code> depend on the <code>_transports</code> package
instead of its submodules ...</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/e52f963c62f397f225c8d29573aedbe5ae613906"><code>e52f963</code></a>
Skip dependencies not needed on Emscripten (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1114">#1114</a>)</li>
<li><a
href="https://github.com/pydantic/httpx2/commit/5d9eedc98186c612d0e426df417f78f6ec21e9ca"><code>5d9eedc</code></a>
Add <code>max_event_size</code> to cap SSE event buffering (<a
href="https://redirect.github.com/pydantic/httpx2/issues/1071">#1071</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pydantic/httpx2/compare/v2.5.0...v2.10.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=httpcore2&package-manager=uv&previous-version=2.5.0&new-version=2.10.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-08 21:26:36 -07:00
Parker J. RuleandGitHub 0199b519e1 fix(cli): clarify missing deploy config (#8854)
Shows an actionable, docs-linked error when `langgraph deploy` is run
without a `langgraph.json` instead of exposing a traceback.
2026-09-08 17:03:14 +00:00
Nick HollonandGitHub 81bf17b231 fix(langgraph): type undeclared v3 stream projections (#8596) 2026-09-03 11:23:25 -04:00
John KennedyGitHublangsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
11738d83db chore(langgraph): bump mistune to 3.3.4 (#8804)
Updates the `libs/langgraph/uv.lock` development dependency from Mistune
3.3.0 to 3.3.4, resolving GHSA-6m44-fpc8-c3rq (Dependabot #389). The
change is scoped to the affected lockfile.

Validation: `uv lock --project libs/langgraph --locked`.

Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
2026-09-02 17:38:30 -07:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1983e60971 chore(deps): bump browserslist from 4.28.1 to 4.28.8 in /libs/cli/js-examples (#8797)
Bumps [browserslist](https://github.com/browserslist/browserslist) from
4.28.1 to 4.28.8.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/browserslist/browserslist/releases">browserslist's
releases</a>.</em></p>
<blockquote>
<h2>4.28.8</h2>
<ul>
<li>Fixed <code>including kaios</code> in baseline queries (by <a
href="https://github.com/Jaybhade"><code>@​Jaybhade</code></a>).</li>
</ul>
<h2>4.28.7</h2>
<ul>
<li>Improved parsing performance.</li>
<li>Fixed unbounded memory growth (by <a
href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
<li>Fixed prototype write issue (by <a
href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
</ul>
<h2>4.28.6</h2>
<ul>
<li>Fixed Electron version queries (by <a
href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
</ul>
<h2>4.28.5</h2>
<ul>
<li>Fixed <code>&gt;</code> and <code>&gt;=</code> queries (by <a
href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
</ul>
<h2>4.28.4</h2>
<ul>
<li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li>
</ul>
<h2>4.28.3</h2>
<ul>
<li>Fixed baseline query case-insensitivity (by <a
href="https://github.com/swwind"><code>@​swwind</code></a>).</li>
</ul>
<h2>4.28.2</h2>
<ul>
<li>Fix prototype pollution (by <a
href="https://github.com/chluo1997"><code>@​chluo1997</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md">browserslist's
changelog</a>.</em></p>
<blockquote>
<h2>4.28.8</h2>
<ul>
<li>Fixed <code>including kaios</code> in baseline queries (by <a
href="https://github.com/Jaybhade"><code>@​Jaybhade</code></a>).</li>
</ul>
<h2>4.28.7</h2>
<ul>
<li>Improved parsing performance.</li>
<li>Fixed unbounded memory growth (by <a
href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
<li>Fixed prototype write issue (by <a
href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
</ul>
<h2>4.28.6</h2>
<ul>
<li>Fixed Electron version queries (by <a
href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
</ul>
<h2>4.28.5</h2>
<ul>
<li>Fixed <code>&gt;</code> and <code>&gt;=</code> queries (by <a
href="https://github.com/spokodev"><code>@​spokodev</code></a>).</li>
</ul>
<h2>4.28.4</h2>
<ul>
<li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li>
</ul>
<h2>4.28.3</h2>
<ul>
<li>Fixed baseline query case-insensitivity (by <a
href="https://github.com/swwind"><code>@​swwind</code></a>).</li>
</ul>
<h2>4.28.2</h2>
<ul>
<li>Fix prototype pollution (by <a
href="https://github.com/chluo1997"><code>@​chluo1997</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad"><code>f2f2e6c</code></a>
Release 4.28.8 version</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377"><code>d0787c8</code></a>
Update dependencies</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f"><code>fcf8fa9</code></a>
Merge pull request <a
href="https://redirect.github.com/browserslist/browserslist/issues/939">#939</a>
from Jaybhade/fix/baseline-kaios-without-downstream</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c"><code>57ecd64</code></a>
fix: support &quot;including kaios&quot; without downstream</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1"><code>093a0f6</code></a>
Update EM banner</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276"><code>b637868</code></a>
Release 4.28.7 version</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46"><code>313f465</code></a>
Update dependencies</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/c935c5a206f8b13db8846818bc03643e147dcbdf"><code>c935c5a</code></a>
Fix regexp performance</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/d7e9e653cb53399065943f59f0b3063987b0a008"><code>d7e9e65</code></a>
Rewrite structure parsing to make it always fast</li>
<li><a
href="https://github.com/browserslist/browserslist/commit/ec4a55efd76bdfa506ec7ce4fea1691559e9ca8f"><code>ec4a55e</code></a>
Fix import order</li>
<li>Additional commits viewable in <a
href="https://github.com/browserslist/browserslist/compare/4.28.1...4.28.8">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for browserslist since your current version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=browserslist&package-manager=npm_and_yarn&previous-version=4.28.1&new-version=4.28.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraph/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 13:27:41 -07:00