mirror of
https://github.com/langchain-ai/langgraph.git
synced 2026-10-01 22:15:11 +02:00
main
3754
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
157a06dda9 |
chore(deps-dev): bump the minor-and-patch group across 1 directory with 5 updates (#9155)
Bumps the minor-and-patch group with 5 updates in the /libs/langgraph directory: | Package | From | To | | --- | --- | --- | | [langchain-core](https://github.com/langchain-ai/langchain) | `1.6.1` | `1.6.5` | | [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` | `3.16.0` | | [syrupy](https://github.com/syrupy-project/syrupy) | `6.0.0` | `6.1.1` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.9` | | [ty](https://github.com/astral-sh/ty) | `0.0.75` | `0.0.84` | Updates `langchain-core` from 1.6.1 to 1.6.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langchain/releases">langchain-core's releases</a>.</em></p> <blockquote> <h2>langchain-core==1.6.5</h2> <p>Changes since langchain-core==1.6.4</p> <p>release(core): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>) fix(core): abbreviate long tool IDs in XML buffer strings (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</p> <h2>langchain-core==1.6.4</h2> <p>Changes since langchain-core==1.6.3</p> <p>release(core): 1.6.4 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40718">#40718</a>) chore(core): deprecate chat message history (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40711">#40711</a>) chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40634">#40634</a>) chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40574">#40574</a>)</p> <h2>langchain-core==1.6.3</h2> <p>Changes since langchain-core==1.6.2</p> <p>release(core): 1.6.3 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40407">#40407</a>) feat(core): Allow model name and provider tracing metadata override based on gateway response (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40406">#40406</a>) test(core): cover the deprecated <code>.text()</code> access path (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40243">#40243</a>) docs(core): remove stale Args/Raises entries from FileCallbackHandler._write and ChatGeneration.set_text (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40211">#40211</a>)</p> <h2>langchain-core==1.6.2</h2> <p>Changes since langchain-core==1.6.1</p> <p>release(core): 1.6.2 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40209">#40209</a>) feat(openai): support async tools (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40208">#40208</a>) chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40150">#40150</a>) chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40113">#40113</a>) fix(core): avoid mutation in google-genai standard content (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40023">#40023</a>) fix(core): avoid mutation in bedrock converse standard content (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40022">#40022</a>)</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langchain/commit/c5ab14d42a3e22865c9def909de0b11d70b0bbf0"><code>c5ab14d</code></a> release(core): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/5704d9d4813f8c0527f04e2662cf313e1350f96f"><code>5704d9d</code></a> chore(model-profiles): refresh model profile data (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40804">#40804</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/7622d3dce760ac4be6d9aef4c653277e06064aea"><code>7622d3d</code></a> release(openai): 1.6.6 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40800">#40800</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/2dd956b8add667dac4f97605ae441d75b8ae228e"><code>2dd956b</code></a> docs(infra): fix AGENTS.md root setup guidance and package doc accuracy (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40794">#40794</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/49f4b4016b82513c3dc1623bf3daa10453861621"><code>49f4b40</code></a> fix(openai): raise on error events in stream path (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40791">#40791</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/19cadaa1a1e0cac71f3148e2f18b414dcab17426"><code>19cadaa</code></a> fix(core): abbreviate long tool IDs in XML buffer strings (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/798441e8b07e88e79db355db452cd9492f9628f2"><code>798441e</code></a> chore(anthropic): fix integration test cassette (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40790">#40790</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/a476942bac3fe5e521676d0f53fabafcb7ba71b1"><code>a476942</code></a> release(openai): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40787">#40787</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/46c6bdf1b4e23028a5acc060d8b2797dbf200291"><code>46c6bdf</code></a> release(anthropic): 1.7.4 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40786">#40786</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/290dabaff27ee379920d55d155d5055d2fe29cc8"><code>290daba</code></a> fix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40785">#40785</a>)</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langchain/compare/langchain-core==1.6.1...langchain-core==1.6.5">compare view</a></li> </ul> </details> <br /> Updates `pytest-mock` from 3.15.1 to 3.16.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's releases</a>.</em></p> <blockquote> <h2>v3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's changelog</a>.</em></p> <blockquote> <h2>3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604></code>_: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611></code>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606></code>_: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547></code>_: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147></code>_: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a> Release 3.16.0</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a> Fix duplicate_iterators for async spies (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a> Fix async assertion argument introspection (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a> docs: import os in the opening usage example (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a> Honour resetall() arguments for non-callable mocks (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare view</a></li> </ul> </details> <br /> Updates `syrupy` from 6.0.0 to 6.1.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/syrupy-project/syrupy/releases">syrupy's releases</a>.</em></p> <blockquote> <h2>v6.1.1</h2> <blockquote> <p><strong>Note:</strong> 6.1.0 was skipped due to a CI issue. Use <strong>6.1.1</strong>.</p> </blockquote> <h3>Experimental <code>--snapshot-file-lock</code> for pytest-xdist</h3> <p><code>--snapshot-update</code> under pytest-xdist can race when multiple workers rewrite the same multi-entry amber (<code>.ambr</code>) file, silently dropping snapshots (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1237">#1237</a>).</p> <p>This release adds an <strong>experimental</strong> opt-in:</p> <ul> <li><code>--snapshot-file-lock</code> — exclusive file lock + atomic replace around amber writes</li> <li><code>--snapshot-file-lock-timeout</code> — max wait for the lock (default <strong>60s</strong>)</li> </ul> <p>Same-machine workers only; not reliable across remote workers / NFS. See <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1239">#1239</a>.</p> <blockquote> <p><strong>Callout for pytest-xdist users:</strong> please try <code>--snapshot-file-lock</code> with <code>--snapshot-update</code> and <a href="https://github.com/syrupy-project/syrupy/issues">open an issue</a> if you hit problems. Locking is expected to become the default in a future minor release.</p> </blockquote> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/shipbyaeron"><code>@shipbyaeron</code></a> made their first contribution in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1236">syrupy-project/syrupy#1236</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.1">https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.1</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/syrupy-project/syrupy/blob/main/CHANGELOG.md">syrupy's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/syrupy-project/syrupy/releases/tag/v6.1.1">v6.1.1</a> (2026-09-13)</h2> <h2>What's Changed</h2> <ul> <li>chore(deps): update dependency ruff to v0.16.4 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1225">syrupy-project/syrupy#1225</a></li> <li>chore(deps): update dependency pytest-benchmark to v5.3.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1226">syrupy-project/syrupy#1226</a></li> <li>chore(deps): update dependency ruff to v0.16.5 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1227">syrupy-project/syrupy#1227</a></li> <li>chore(deps): update dependency pydantic to v2.13.5 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1228">syrupy-project/syrupy#1228</a></li> <li>chore(deps): update dependency coverage to v7.16.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1229">syrupy-project/syrupy#1229</a></li> <li>chore(deps): update dependency hypothesis to v6.166.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1230">syrupy-project/syrupy#1230</a></li> <li>chore(deps): update dependency hypothesis to v6.167.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1231">syrupy-project/syrupy#1231</a></li> <li>chore(deps): update dependency hypothesis to v6.167.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1232">syrupy-project/syrupy#1232</a></li> <li>chore(deps): update actions/deploy-pages action to v5.0.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1234">syrupy-project/syrupy#1234</a></li> <li>chore(deps): update dependency ruff to v0.16.6 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1235">syrupy-project/syrupy#1235</a></li> <li>test: add coverage for read_snapshot_data_from_location returning None by <a href="https://github.com/shipbyaeron"><code>@shipbyaeron</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1236">syrupy-project/syrupy#1236</a></li> <li>chore(deps): update dependency hypothesis to v6.168.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1238">syrupy-project/syrupy#1238</a></li> <li>fix: opt-in file lock for concurrent amber writes under xdist by <a href="https://github.com/noahnu"><code>@noahnu</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1239">syrupy-project/syrupy#1239</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/shipbyaeron"><code>@shipbyaeron</code></a> made their first contribution in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1236">syrupy-project/syrupy#1236</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.1">https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.1</a></p> <h2><a href="https://github.com/syrupy-project/syrupy/releases/tag/v6.1.0">v6.1.0</a> (2026-09-13)</h2> <h2>What's Changed</h2> <ul> <li>chore(deps): update dependency ruff to v0.16.4 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1225">syrupy-project/syrupy#1225</a></li> <li>chore(deps): update dependency pytest-benchmark to v5.3.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1226">syrupy-project/syrupy#1226</a></li> <li>chore(deps): update dependency ruff to v0.16.5 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1227">syrupy-project/syrupy#1227</a></li> <li>chore(deps): update dependency pydantic to v2.13.5 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1228">syrupy-project/syrupy#1228</a></li> <li>chore(deps): update dependency coverage to v7.16.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1229">syrupy-project/syrupy#1229</a></li> <li>chore(deps): update dependency hypothesis to v6.166.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1230">syrupy-project/syrupy#1230</a></li> <li>chore(deps): update dependency hypothesis to v6.167.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1231">syrupy-project/syrupy#1231</a></li> <li>chore(deps): update dependency hypothesis to v6.167.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1232">syrupy-project/syrupy#1232</a></li> <li>chore(deps): update actions/deploy-pages action to v5.0.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1234">syrupy-project/syrupy#1234</a></li> <li>chore(deps): update dependency ruff to v0.16.6 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1235">syrupy-project/syrupy#1235</a></li> <li>test: add coverage for read_snapshot_data_from_location returning None by <a href="https://github.com/shipbyaeron"><code>@shipbyaeron</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1236">syrupy-project/syrupy#1236</a></li> <li>chore(deps): update dependency hypothesis to v6.168.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1238">syrupy-project/syrupy#1238</a></li> <li>fix: opt-in file lock for concurrent amber writes under xdist by <a href="https://github.com/noahnu"><code>@noahnu</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1239">syrupy-project/syrupy#1239</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/shipbyaeron"><code>@shipbyaeron</code></a> made their first contribution in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1236">syrupy-project/syrupy#1236</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.0">https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/syrupy-project/syrupy/commit/2d251e73f1ebe47fe83ed71d835d3ae8580e8313"><code>2d251e7</code></a> chore(release): 6.1.1 [skip ci]</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/9b64ec05752586c45d1097e9d25f9ee1d4e93219"><code>9b64ec0</code></a> chore(release): 6.1.0 [skip ci]</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/5b4256eac8720075f25b0fa8491f75948001b983"><code>5b4256e</code></a> fix: opt-in file lock for concurrent amber writes under xdist (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1239">#1239</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/d4cb1513b5d2b1b18c3b407150db22d2d8604ddd"><code>d4cb151</code></a> chore(deps): update dependency hypothesis to v6.168.0 (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1238">#1238</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/16c4cb5b8785d89e49b8076a99f58d810e02fcce"><code>16c4cb5</code></a> test: add coverage for read_snapshot_data_from_location returning None (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1236">#1236</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/2e1d3ba0d39a1d87735213a32de9dd9cdb929690"><code>2e1d3ba</code></a> chore(deps): update dependency ruff to v0.16.6 (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1235">#1235</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/fcc929d4deb2302f2d37e6511015ef43a0841bc2"><code>fcc929d</code></a> chore(deps): update actions/deploy-pages action to v5.0.1 (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1234">#1234</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/4f1bad75777ecc9d916a648dd3669b2844d08f7d"><code>4f1bad7</code></a> chore(deps): update dependency hypothesis to v6.167.1 (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1232">#1232</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/24eda28579f5761cbc64713ffcee41cc73602010"><code>24eda28</code></a> chore(deps): update dependency hypothesis to v6.167.0 (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1231">#1231</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/0d7e46f9431e07810da4ef90dbe861b85fbc8469"><code>0d7e46f</code></a> chore(deps): update dependency hypothesis to v6.166.0 (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1230">#1230</a>)</li> <li>Additional commits viewable in <a href="https://github.com/syrupy-project/syrupy/compare/v6.0.0...v6.1.1">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.5 to 0.16.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.9</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>Install ruff 0.16.9</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh </code></pre> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.9</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>0.16.8</h2> <p>Released on 2026-09-16.</p> <h3>Bug fixes</h3> <ul> <li>Visit functional <code>TypedDict</code> keyword arguments correctly (<a href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li> <li>[<code>flake8-simplify</code>] Detect nested <code>async with</code> under sync parent (<code>SIM117</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li> <li>[<code>flake8-simplify</code>] Preserve operand order in <code>SIM109</code> fix (<a href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a> Bump version to 0.16.9 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a> Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a> Update dependency astral-sh/uv to v0.12.18 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a> [<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>...</li> <li><a href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a> Use <code>target</code> form in <code>rooster.version_files</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a> [ty] Prefer existing @ paths over response files in Ruff and ty (<a href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a> ci(github): update version number in placeholder of issue template (<a href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a> [ty] Propagate outer type context through cast calls (<a href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a> [ty] Contain rendered code within Markdown fences (<a href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a> authorize ruff-pre-commit dispatch via OIDC (<a href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare view</a></li> </ul> </details> <br /> Updates `ty` from 0.0.75 to 0.0.84 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/releases">ty's releases</a>.</em></p> <blockquote> <h2>0.0.84</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's changelog</a>.</em></p> <blockquote> <h2>0.0.84</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a> Bump version to 0.0.84 (<a href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a> publish to astral-sh/versions via OIDC (<a href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a> use oidc issued token for docs publication (<a href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a> Update prek dependencies (<a href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a> Update docker/setup-buildx-action action to v4.3.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a> Update astral-sh/setup-uv action to v10.2.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a> Bump version to 0.0.83 (<a href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a> Sync the ty security mirror (<a href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a> Grant the versions workflow repository read access (<a href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a> use scoped token for release workflow (<a href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare view</a></li> </ul> </details> <br /> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: John Kennedy <jkennedyvz@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
5204e60579 |
chore(deps-dev): bump the minor-and-patch group in /libs/checkpoint-sqlite with 3 updates (#9146)
Bumps the minor-and-patch group in /libs/checkpoint-sqlite with 3 updates: [pytest-mock](https://github.com/pytest-dev/pytest-mock), [ruff](https://github.com/astral-sh/ruff) and [ty](https://github.com/astral-sh/ty). Updates `pytest-mock` from 3.15.1 to 3.16.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's releases</a>.</em></p> <blockquote> <h2>v3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's changelog</a>.</em></p> <blockquote> <h2>3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604></code>_: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611></code>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606></code>_: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547></code>_: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147></code>_: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a> Release 3.16.0</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a> Fix duplicate_iterators for async spies (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a> Fix async assertion argument introspection (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a> docs: import os in the opening usage example (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a> Honour resetall() arguments for non-callable mocks (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.5 to 0.16.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.9</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>Install ruff 0.16.9</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh </code></pre> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.9</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>0.16.8</h2> <p>Released on 2026-09-16.</p> <h3>Bug fixes</h3> <ul> <li>Visit functional <code>TypedDict</code> keyword arguments correctly (<a href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li> <li>[<code>flake8-simplify</code>] Detect nested <code>async with</code> under sync parent (<code>SIM117</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li> <li>[<code>flake8-simplify</code>] Preserve operand order in <code>SIM109</code> fix (<a href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a> Bump version to 0.16.9 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a> Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a> Update dependency astral-sh/uv to v0.12.18 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a> [<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>...</li> <li><a href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a> Use <code>target</code> form in <code>rooster.version_files</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a> [ty] Prefer existing @ paths over response files in Ruff and ty (<a href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a> ci(github): update version number in placeholder of issue template (<a href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a> [ty] Propagate outer type context through cast calls (<a href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a> [ty] Contain rendered code within Markdown fences (<a href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a> authorize ruff-pre-commit dispatch via OIDC (<a href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare view</a></li> </ul> </details> <br /> Updates `ty` from 0.0.75 to 0.0.84 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/releases">ty's releases</a>.</em></p> <blockquote> <h2>0.0.84</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's changelog</a>.</em></p> <blockquote> <h2>0.0.84</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a> Bump version to 0.0.84 (<a href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a> publish to astral-sh/versions via OIDC (<a href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a> use oidc issued token for docs publication (<a href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a> Update prek dependencies (<a href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a> Update docker/setup-buildx-action action to v4.3.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a> Update astral-sh/setup-uv action to v10.2.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a> Bump version to 0.0.83 (<a href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a> Sync the ty security mirror (<a href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a> Grant the versions workflow repository read access (<a href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a> use scoped token for release workflow (<a href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: John Kennedy <jkennedyvz@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
2053f0b176 |
chore(deps-dev): bump the minor-and-patch group in /libs/checkpoint-conformance with 2 updates (#9145)
Bumps the minor-and-patch group in /libs/checkpoint-conformance with 2 updates: [ruff](https://github.com/astral-sh/ruff) and [ty](https://github.com/astral-sh/ty). Updates `ruff` from 0.16.5 to 0.16.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.9</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>Install ruff 0.16.9</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh </code></pre> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.9</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>0.16.8</h2> <p>Released on 2026-09-16.</p> <h3>Bug fixes</h3> <ul> <li>Visit functional <code>TypedDict</code> keyword arguments correctly (<a href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li> <li>[<code>flake8-simplify</code>] Detect nested <code>async with</code> under sync parent (<code>SIM117</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li> <li>[<code>flake8-simplify</code>] Preserve operand order in <code>SIM109</code> fix (<a href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a> Bump version to 0.16.9 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a> Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a> Update dependency astral-sh/uv to v0.12.18 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a> [<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>...</li> <li><a href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a> Use <code>target</code> form in <code>rooster.version_files</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a> [ty] Prefer existing @ paths over response files in Ruff and ty (<a href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a> ci(github): update version number in placeholder of issue template (<a href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a> [ty] Propagate outer type context through cast calls (<a href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a> [ty] Contain rendered code within Markdown fences (<a href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a> authorize ruff-pre-commit dispatch via OIDC (<a href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare view</a></li> </ul> </details> <br /> Updates `ty` from 0.0.75 to 0.0.84 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/releases">ty's releases</a>.</em></p> <blockquote> <h2>0.0.84</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's changelog</a>.</em></p> <blockquote> <h2>0.0.84</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a> Bump version to 0.0.84 (<a href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a> publish to astral-sh/versions via OIDC (<a href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a> use oidc issued token for docs publication (<a href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a> Update prek dependencies (<a href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a> Update docker/setup-buildx-action action to v4.3.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a> Update astral-sh/setup-uv action to v10.2.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a> Bump version to 0.0.83 (<a href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a> Sync the ty security mirror (<a href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a> Grant the versions workflow repository read access (<a href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a> use scoped token for release workflow (<a href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: John Kennedy <jkennedyvz@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
c4f55715ec |
chore(deps): bump the minor-and-patch group in /libs/sdk-py with 5 updates (#9149)
Bumps the minor-and-patch group in /libs/sdk-py with 5 updates: | Package | From | To | | --- | --- | --- | | [langchain-core](https://github.com/langchain-ai/langchain) | `1.6.1` | `1.6.5` | | [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` | `3.16.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.9` | | [ty](https://github.com/astral-sh/ty) | `0.0.75` | `0.0.84` | | [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` | Updates `langchain-core` from 1.6.1 to 1.6.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langchain/releases">langchain-core's releases</a>.</em></p> <blockquote> <h2>langchain-core==1.6.5</h2> <p>Changes since langchain-core==1.6.4</p> <p>release(core): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>) fix(core): abbreviate long tool IDs in XML buffer strings (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</p> <h2>langchain-core==1.6.4</h2> <p>Changes since langchain-core==1.6.3</p> <p>release(core): 1.6.4 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40718">#40718</a>) chore(core): deprecate chat message history (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40711">#40711</a>) chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40634">#40634</a>) chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40574">#40574</a>)</p> <h2>langchain-core==1.6.3</h2> <p>Changes since langchain-core==1.6.2</p> <p>release(core): 1.6.3 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40407">#40407</a>) feat(core): Allow model name and provider tracing metadata override based on gateway response (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40406">#40406</a>) test(core): cover the deprecated <code>.text()</code> access path (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40243">#40243</a>) docs(core): remove stale Args/Raises entries from FileCallbackHandler._write and ChatGeneration.set_text (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40211">#40211</a>)</p> <h2>langchain-core==1.6.2</h2> <p>Changes since langchain-core==1.6.1</p> <p>release(core): 1.6.2 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40209">#40209</a>) feat(openai): support async tools (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40208">#40208</a>) chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40150">#40150</a>) chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40113">#40113</a>) fix(core): avoid mutation in google-genai standard content (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40023">#40023</a>) fix(core): avoid mutation in bedrock converse standard content (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40022">#40022</a>)</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langchain/commit/c5ab14d42a3e22865c9def909de0b11d70b0bbf0"><code>c5ab14d</code></a> release(core): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/5704d9d4813f8c0527f04e2662cf313e1350f96f"><code>5704d9d</code></a> chore(model-profiles): refresh model profile data (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40804">#40804</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/7622d3dce760ac4be6d9aef4c653277e06064aea"><code>7622d3d</code></a> release(openai): 1.6.6 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40800">#40800</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/2dd956b8add667dac4f97605ae441d75b8ae228e"><code>2dd956b</code></a> docs(infra): fix AGENTS.md root setup guidance and package doc accuracy (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40794">#40794</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/49f4b4016b82513c3dc1623bf3daa10453861621"><code>49f4b40</code></a> fix(openai): raise on error events in stream path (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40791">#40791</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/19cadaa1a1e0cac71f3148e2f18b414dcab17426"><code>19cadaa</code></a> fix(core): abbreviate long tool IDs in XML buffer strings (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/798441e8b07e88e79db355db452cd9492f9628f2"><code>798441e</code></a> chore(anthropic): fix integration test cassette (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40790">#40790</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/a476942bac3fe5e521676d0f53fabafcb7ba71b1"><code>a476942</code></a> release(openai): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40787">#40787</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/46c6bdf1b4e23028a5acc060d8b2797dbf200291"><code>46c6bdf</code></a> release(anthropic): 1.7.4 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40786">#40786</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/290dabaff27ee379920d55d155d5055d2fe29cc8"><code>290daba</code></a> fix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40785">#40785</a>)</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langchain/compare/langchain-core==1.6.1...langchain-core==1.6.5">compare view</a></li> </ul> </details> <br /> Updates `pytest-mock` from 3.15.1 to 3.16.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's releases</a>.</em></p> <blockquote> <h2>v3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's changelog</a>.</em></p> <blockquote> <h2>3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604></code>_: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611></code>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606></code>_: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547></code>_: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147></code>_: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a> Release 3.16.0</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a> Fix duplicate_iterators for async spies (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a> Fix async assertion argument introspection (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a> docs: import os in the opening usage example (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a> Honour resetall() arguments for non-callable mocks (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.5 to 0.16.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.9</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>Install ruff 0.16.9</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh </code></pre> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.9</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>0.16.8</h2> <p>Released on 2026-09-16.</p> <h3>Bug fixes</h3> <ul> <li>Visit functional <code>TypedDict</code> keyword arguments correctly (<a href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li> <li>[<code>flake8-simplify</code>] Detect nested <code>async with</code> under sync parent (<code>SIM117</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li> <li>[<code>flake8-simplify</code>] Preserve operand order in <code>SIM109</code> fix (<a href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a> Bump version to 0.16.9 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a> Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a> Update dependency astral-sh/uv to v0.12.18 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a> [<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>...</li> <li><a href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a> Use <code>target</code> form in <code>rooster.version_files</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a> [ty] Prefer existing @ paths over response files in Ruff and ty (<a href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a> ci(github): update version number in placeholder of issue template (<a href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a> [ty] Propagate outer type context through cast calls (<a href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a> [ty] Contain rendered code within Markdown fences (<a href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a> authorize ruff-pre-commit dispatch via OIDC (<a href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare view</a></li> </ul> </details> <br /> Updates `ty` from 0.0.75 to 0.0.84 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/releases">ty's releases</a>.</em></p> <blockquote> <h2>0.0.84</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's changelog</a>.</em></p> <blockquote> <h2>0.0.84</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a> Bump version to 0.0.84 (<a href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a> publish to astral-sh/versions via OIDC (<a href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a> use oidc issued token for docs publication (<a href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a> Update prek dependencies (<a href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a> Update docker/setup-buildx-action action to v4.3.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a> Update astral-sh/setup-uv action to v10.2.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a> Bump version to 0.0.83 (<a href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a> Sync the ty security mirror (<a href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a> Grant the versions workflow repository read access (<a href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a> use scoped token for release workflow (<a href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare view</a></li> </ul> </details> <br /> Updates `starlette` from 1.6.0 to 1.7.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kludex/starlette/releases">starlette's releases</a>.</em></p> <blockquote> <h2>Version 1.7.0</h2> <p>This release adds experimental OpenTelemetry tracing, HTTP <code>QUERY</code> support, and response trailers in <code>TestClient</code>. Starlette now requires AnyIO 4.</p> <blockquote> <p>[!WARNING] <code>OpenTelemetryMiddleware</code> is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.</p> </blockquote> <h2>Added</h2> <ul> <li>Add experimental <code>OpenTelemetryMiddleware</code> for HTTP server spans, with URL exclusions and custom tracer providers <a href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>, <a href="https://redirect.github.com/Kludex/starlette/pull/3463">#3463</a>, and <a href="https://redirect.github.com/Kludex/starlette/pull/3520">#3520</a>.</li> <li>Expose the matched route through <code>scope["route"]</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>.</li> <li>Support the <code>QUERY</code> HTTP method in <code>HTTPEndpoint</code>, CORS, and OpenAPI 3.2 schema generation <a href="https://redirect.github.com/Kludex/starlette/pull/3489">#3489</a>.</li> <li>Capture HTTP response trailers in <code>TestClient</code> and expose them through <code>response.extensions["http.response.trailers"]</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3563">#3563</a>.</li> <li>Support partitioned cookies in <code>SessionMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3510">#3510</a>.</li> <li>Add <code>partitioned</code> to <code>Response.delete_cookie()</code> on Python 3.14 and later <a href="https://redirect.github.com/Kludex/starlette/pull/3376">#3376</a>.</li> <li>Support IPv6 hosts in <code>TrustedHostMiddleware</code> and <code>TestClient</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3471">#3471</a>.</li> <li>Support Python 3.15 <a href="https://redirect.github.com/Kludex/starlette/pull/3508">#3508</a>.</li> </ul> <h2>Changed</h2> <ul> <li>Require <code>anyio>=4.0.0,<5</code>, dropping support for AnyIO 3 <a href="https://redirect.github.com/Kludex/starlette/pull/3512">#3512</a>.</li> <li>Raise <code>WebSocketDisconnected</code>, a <code>RuntimeError</code> subclass, for disconnected WebSocket operations <a href="https://redirect.github.com/Kludex/starlette/pull/2767">#2767</a>.</li> <li>Accept <code>Collection[str]</code> in <code>CORSMiddleware</code> configuration annotations, including sets and frozensets <a href="https://redirect.github.com/Kludex/starlette/pull/3518">#3518</a>.</li> </ul> <h2>Fixed</h2> <ul> <li>Run background tasks only after the response is sent when using <code>BaseHTTPMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3476">#3476</a>.</li> <li>Return <code>400</code> for invalid multipart parser input <a href="https://redirect.github.com/Kludex/starlette/pull/3492">#3492</a>.</li> <li>Include <code>Vary: Origin</code> on all normal CORS responses and vary preflight responses by all request headers that affect them <a href="https://redirect.github.com/Kludex/starlette/pull/3516">#3516</a> and <a href="https://redirect.github.com/Kludex/starlette/pull/3517">#3517</a>.</li> <li>Handle malformed <code>Host</code> headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware <a href="https://redirect.github.com/Kludex/starlette/pull/3472">#3472</a>.</li> <li>Ignore <code>Range</code> headers when <code>FileResponse</code> has a status other than <code>200</code>, preserving its status and full body <a href="https://redirect.github.com/Kludex/starlette/pull/3568">#3568</a>.</li> <li>Handle standalone <code>If-None-Match: *</code> in <code>StaticFiles</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3201">#3201</a>.</li> <li>Reject WebSocket requests to <code>StaticFiles</code> without raising an assertion error <a href="https://redirect.github.com/Kludex/starlette/pull/3532">#3532</a>.</li> <li>Persist session mutations made with <code>popitem()</code> and <code>|=</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3436">#3436</a>.</li> <li>Handle empty and absent payloads in <code>WebSocketEndpoint.decode()</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3372">#3372</a>.</li> <li>Implement <code>identity</code> on <code>SimpleUser</code> and <code>UnauthenticatedUser</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3271">#3271</a>.</li> <li>Allow <code>HTTPException</code> to use non-standard status codes without an explicit <code>detail</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3545">#3545</a>.</li> <li>Avoid deprecated AnyIO imports in <code>TestClient</code> and add explicit imports in <code>WSGIMiddleware</code> for AnyIO 4.15 compatibility <a href="https://redirect.github.com/Kludex/starlette/pull/3498">#3498</a> and <a href="https://redirect.github.com/Kludex/starlette/pull/3501">#3501</a>.</li> <li>Offload debug traceback rendering to a worker thread in <code>ServerErrorMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/2858">#2858</a>.</li> </ul> <p><strong>Full changelog:</strong> <a href="https://github.com/Kludex/starlette/compare/1.6.0...1.7.0">1.6.0...1.7.0</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kludex/starlette/blob/main/docs/release-notes.md">starlette's changelog</a>.</em></p> <blockquote> <h2>1.7.0 (September 23, 2026)</h2> <p>This release adds experimental OpenTelemetry tracing and requires AnyIO 4.</p> <p>!!! warning "OpenTelemetryMiddleware is experimental" Its API and emitted telemetry may change in minor releases without a deprecation period <a href="https://redirect.github.com/Kludex/starlette/pull/3574">#3574</a>.</p> <h4>Added</h4> <ul> <li>Add experimental <code>OpenTelemetryMiddleware</code> for HTTP server spans, with URL exclusions and custom tracer providers <a href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>, <a href="https://redirect.github.com/Kludex/starlette/pull/3463">#3463</a>, and <a href="https://redirect.github.com/Kludex/starlette/pull/3520">#3520</a>.</li> <li>Expose the matched route through <code>scope["route"]</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3438">#3438</a>.</li> <li>Support the <code>QUERY</code> HTTP method in <code>HTTPEndpoint</code>, CORS, and OpenAPI 3.2 schema generation <a href="https://redirect.github.com/Kludex/starlette/pull/3489">#3489</a>.</li> <li>Capture HTTP response trailers in <code>TestClient</code> and expose them through <code>response.extensions["http.response.trailers"]</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3563">#3563</a>.</li> <li>Support partitioned cookies in <code>SessionMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3510">#3510</a>.</li> <li>Add <code>partitioned</code> to <code>Response.delete_cookie()</code> on Python 3.14 and later <a href="https://redirect.github.com/Kludex/starlette/pull/3376">#3376</a>.</li> <li>Support IPv6 hosts in <code>TrustedHostMiddleware</code> and <code>TestClient</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3471">#3471</a>.</li> <li>Support Python 3.15 <a href="https://redirect.github.com/Kludex/starlette/pull/3508">#3508</a>.</li> </ul> <h4>Changed</h4> <ul> <li>Require <code>anyio>=4.0.0,<5</code>, dropping support for AnyIO 3 <a href="https://redirect.github.com/Kludex/starlette/pull/3512">#3512</a>.</li> <li>Raise <code>WebSocketDisconnected</code>, a <code>RuntimeError</code> subclass, for disconnected WebSocket operations <a href="https://redirect.github.com/Kludex/starlette/pull/2767">#2767</a>.</li> <li>Accept <code>Collection[str]</code> in <code>CORSMiddleware</code> configuration annotations, including sets and frozensets <a href="https://redirect.github.com/Kludex/starlette/pull/3518">#3518</a>.</li> </ul> <h4>Fixed</h4> <ul> <li>Run background tasks only after the response is sent when using <code>BaseHTTPMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3476">#3476</a>.</li> <li>Return <code>400</code> for invalid multipart parser input <a href="https://redirect.github.com/Kludex/starlette/pull/3492">#3492</a>.</li> <li>Include <code>Vary: Origin</code> on all normal CORS responses and vary preflight responses by all request headers that affect them <a href="https://redirect.github.com/Kludex/starlette/pull/3516">#3516</a> and <a href="https://redirect.github.com/Kludex/starlette/pull/3517">#3517</a>.</li> <li>Handle malformed <code>Host</code> headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware <a href="https://redirect.github.com/Kludex/starlette/pull/3472">#3472</a>.</li> <li>Ignore <code>Range</code> headers when <code>FileResponse</code> has a status other than <code>200</code>, preserving its status and full body <a href="https://redirect.github.com/Kludex/starlette/pull/3568">#3568</a>.</li> <li>Handle standalone <code>If-None-Match: *</code> in <code>StaticFiles</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3201">#3201</a>.</li> <li>Reject WebSocket requests to <code>StaticFiles</code> without raising an assertion error <a href="https://redirect.github.com/Kludex/starlette/pull/3532">#3532</a>.</li> <li>Persist session mutations made with <code>popitem()</code> and <code>|=</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3436">#3436</a>.</li> <li>Handle empty and absent payloads in <code>WebSocketEndpoint.decode()</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3372">#3372</a>.</li> <li>Implement <code>identity</code> on <code>SimpleUser</code> and <code>UnauthenticatedUser</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3271">#3271</a>.</li> <li>Allow <code>HTTPException</code> to use non-standard status codes without an explicit <code>detail</code> <a href="https://redirect.github.com/Kludex/starlette/pull/3545">#3545</a>.</li> <li>Avoid deprecated AnyIO imports in <code>TestClient</code> and add explicit imports in <code>WSGIMiddleware</code> for AnyIO 4.15 compatibility <a href="https://redirect.github.com/Kludex/starlette/pull/3498">#3498</a> and <a href="https://redirect.github.com/Kludex/starlette/pull/3501">#3501</a>.</li> <li>Offload debug traceback rendering to a worker thread in <code>ServerErrorMiddleware</code> <a href="https://redirect.github.com/Kludex/starlette/pull/2858">#2858</a>.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kludex/starlette/commit/2269e9a08c1edd3dfdea865710f40f84c857b623"><code>2269e9a</code></a> Version 1.7.0 (<a href="https://redirect.github.com/Kludex/starlette/issues/3575">#3575</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/4fe55eb2649e74fb01472bad9a1bc54fc3495904"><code>4fe55eb</code></a> Preserve <code>FileResponse</code> status for range requests (<a href="https://redirect.github.com/Kludex/starlette/issues/3568">#3568</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/1f08daf1627c866a4244418ea6da673d272fc8bb"><code>1f08daf</code></a> Mark OpenTelemetryMiddleware as experimental (<a href="https://redirect.github.com/Kludex/starlette/issues/3574">#3574</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/57de5fa9c2a98089a78d32d560e9b23e62560d5f"><code>57de5fa</code></a> Support HTTP response trailers in TestClient (<a href="https://redirect.github.com/Kludex/starlette/issues/3563">#3563</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/03f12b7fcf0a3e21a8da648ca0900c79472e9efe"><code>03f12b7</code></a> Allow HTTPException to use non-standard status codes (<a href="https://redirect.github.com/Kludex/starlette/issues/3545">#3545</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/76fd00f1e293990ea41555946a6b0f58901eaca1"><code>76fd00f</code></a> Reject <code>WebSocket</code> requests to <code>StaticFiles</code> (<a href="https://redirect.github.com/Kludex/starlette/issues/3532">#3532</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/f03f65c2f98c592773d691b4d309c68b83e568ef"><code>f03f65c</code></a> docs: fix 'its not available' and 'This ensure' wording (<a href="https://redirect.github.com/Kludex/starlette/issues/3526">#3526</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/485aca4e797d41849743cf73d5adcfd699695467"><code>485aca4</code></a> docs: the test client is built on httpx2, not httpx (<a href="https://redirect.github.com/Kludex/starlette/issues/3525">#3525</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/fd662b17b9cc41dca32a03509305619643f2dd61"><code>fd662b1</code></a> Implement <code>identity</code> on <code>SimpleUser</code> and <code>UnauthenticatedUser</code> (<a href="https://redirect.github.com/Kludex/starlette/issues/3271">#3271</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/41db6a707f2636526847dbda0e5610e732e6b4fc"><code>41db6a7</code></a> Stabilize CodSpeed upload buffer allocations (<a href="https://redirect.github.com/Kludex/starlette/issues/3524">#3524</a>)</li> <li>Additional commits viewable in <a href="https://github.com/Kludex/starlette/compare/1.6.0...1.7.0">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: John Kennedy <jkennedyvz@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
b36b1d58a8 |
chore(deps): bump tornado from 6.5.8 to 6.5.9 in /libs/langgraph (#9160)
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.8 to 6.5.9. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's changelog</a>.</em></p> <blockquote> <h1>Release notes</h1> <p>.. toctree:: :maxdepth: 2</p> <p>releases/v6.6.0 releases/v6.5.10 releases/v6.5.9 releases/v6.5.8 releases/v6.5.7 releases/v6.5.6 releases/v6.5.5 releases/v6.5.4 releases/v6.5.3 releases/v6.5.2 releases/v6.5.1 releases/v6.5.0 releases/v6.4.2 releases/v6.4.1 releases/v6.4.0 releases/v6.3.3 releases/v6.3.2 releases/v6.3.1 releases/v6.3.0 releases/v6.2.0 releases/v6.1.0 releases/v6.0.4 releases/v6.0.3 releases/v6.0.2 releases/v6.0.1 releases/v6.0.0 releases/v5.1.1 releases/v5.1.0 releases/v5.0.2 releases/v5.0.1 releases/v5.0.0 releases/v4.5.3 releases/v4.5.2 releases/v4.5.1 releases/v4.5.0 releases/v4.4.3 releases/v4.4.2 releases/v4.4.1 releases/v4.4.0 releases/v4.3.0 releases/v4.2.1 releases/v4.2.0 releases/v4.1.0 releases/v4.0.2</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tornadoweb/tornado/commit/75ef8b1cfa0e658aceb17c5a810ad1c74dc69bc7"><code>75ef8b1</code></a> Merge pull request <a href="https://redirect.github.com/tornadoweb/tornado/issues/3719">#3719</a> from bdarnell/fixes-659</li> <li><a href="https://github.com/tornadoweb/tornado/commit/3590cb4566d363331c294cfa63c5035ae2c32c87"><code>3590cb4</code></a> test: Hardcode SimpleAsyncHTTPClient in HTTP1xxLimitTestCase</li> <li><a href="https://github.com/tornadoweb/tornado/commit/9fc5d6d9fff435066836d165d0f1f6ebb067fb9e"><code>9fc5d6d</code></a> test: Make tracemalloc optional in httpclient_test</li> <li><a href="https://github.com/tornadoweb/tornado/commit/555a2ee9a20275d6dfde879977fce58d02e7898a"><code>555a2ee</code></a> iostream: Treat connection resets as a clean close in read_until_close</li> <li><a href="https://github.com/tornadoweb/tornado/commit/3ba622f2ecb75226a8e64d4ee96b7045fc4c8a64"><code>3ba622f</code></a> Release notes and version bump for 6.5.9</li> <li><a href="https://github.com/tornadoweb/tornado/commit/41eea68aba54e8ecaafc1b777dc5c104d289a290"><code>41eea68</code></a> test: Fix some test issues only found by our custom tox config</li> <li><a href="https://github.com/tornadoweb/tornado/commit/ab1a778defaccd0dde9c1c419578e3a1777a9eeb"><code>ab1a778</code></a> Merge remote-tracking branch 'bdarnell/claude/asynchttpclient-streaming-memor...</li> <li><a href="https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32"><code>437ab5f</code></a> web: Do not follow symlinks out of the static directory</li> <li><a href="https://github.com/tornadoweb/tornado/commit/03945136ea9746eccf61caf88edae39642e59c93"><code>0394513</code></a> httputil: Apply the argument count limit to query strings</li> <li><a href="https://github.com/tornadoweb/tornado/commit/b798f8322a15ba8b6ef725d698d1037024139714"><code>b798f83</code></a> http1connection: Return after reading the response that follows a 1xx</li> <li>Additional commits viewable in <a href="https://github.com/tornadoweb/tornado/compare/v6.5.8...v6.5.9">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
9829ef9e64 |
chore(deps): bump virtualenv from 21.2.4 to 21.7.12 in /libs/cli (#9159)
Bumps [virtualenv](https://github.com/pypa/virtualenv) from 21.2.4 to 21.7.12. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pypa/virtualenv/releases">virtualenv's releases</a>.</em></p> <blockquote> <h2>21.7.12</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🔧 chore(changelog): drop dead CVE-2026-24049 fragment by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3249">pypa/virtualenv#3249</a></li> <li>🐛 fix(activation): escape batch quote() against injection by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3250">pypa/virtualenv#3250</a></li> <li>🐛 fix(seed): verify downloaded wheel digests by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3251">pypa/virtualenv#3251</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pypa/virtualenv/compare/21.7.11...21.7.12">https://github.com/pypa/virtualenv/compare/21.7.11...21.7.12</a></p> <h2>21.7.11</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>Add OpenSSF Scorecard workflow by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3238">pypa/virtualenv#3238</a></li> <li>Document AI-assisted contributions and licensing policy by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3239">pypa/virtualenv#3239</a></li> <li>👷 ci(release): attest and sign release provenance by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3242">pypa/virtualenv#3242</a></li> <li>👷 ci: harden Scorecard-scored checks in CI by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3241">pypa/virtualenv#3241</a></li> <li>🐛 fix(ci): parallelize graalpy tests, recover crashed workers by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3240">pypa/virtualenv#3240</a></li> <li>🐛 fix(ci): mark real-shell activation tests as slow by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3243">pypa/virtualenv#3243</a></li> <li>👷 ci: run macOS jobs on macos-26 by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3244">pypa/virtualenv#3244</a></li> <li>🐛 fix(activation): undo a live activation before activate.bat saves values by <a href="https://github.com/darrenhuai"><code>@darrenhuai</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3245">pypa/virtualenv#3245</a></li> <li>🐛 fix(create): keep pyvenv.cfg values on a single line by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3247">pypa/virtualenv#3247</a></li> <li>🔧 chore(test): add opt-in Atheris fuzz harness by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3246">pypa/virtualenv#3246</a></li> <li>📝 docs(readme): add OpenSSF Best Practices badge by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3248">pypa/virtualenv#3248</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pypa/virtualenv/compare/21.7.10...21.7.11">https://github.com/pypa/virtualenv/compare/21.7.10...21.7.11</a></p> <h2>21.7.10</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🔧 chore: check spelling with typos in pre-commit by <a href="https://github.com/even-even"><code>@even-even</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3235">pypa/virtualenv#3235</a></li> <li>🐛 fix(activation): keep and restore the user's TCL_LIBRARY and TK_LIBRARY by <a href="https://github.com/darrenhuai"><code>@darrenhuai</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3234">pypa/virtualenv#3234</a></li> <li>🐛 fix(create): skip blank and comment lines in pyvenv.cfg by <a href="https://github.com/r3wretrhy"><code>@r3wretrhy</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3232">pypa/virtualenv#3232</a></li> <li>🐛 fix(activation): restore PKG_CONFIG_PATH that was not set before by <a href="https://github.com/darrenhuai"><code>@darrenhuai</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3233">pypa/virtualenv#3233</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/r3wretrhy"><code>@r3wretrhy</code></a> made their first contribution in <a href="https://redirect.github.com/pypa/virtualenv/pull/3232">pypa/virtualenv#3232</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pypa/virtualenv/compare/21.7.9...21.7.10">https://github.com/pypa/virtualenv/compare/21.7.9...21.7.10</a></p> <h2>21.7.9</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>fix(test): EncodingWarning: 'encoding' argument not specified by <a href="https://github.com/even-even"><code>@even-even</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3228">pypa/virtualenv#3228</a></li> <li>🐛 fix(config): ignore a config file that fails to parse instead of crashing by <a href="https://github.com/darrenhuai"><code>@darrenhuai</code></a> in <a href="https://redirect.github.com/pypa/virtualenv/pull/3230">pypa/virtualenv#3230</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst">virtualenv's changelog</a>.</em></p> <blockquote> <h1>Bugfixes - 21.7.12</h1> <ul> <li>Fix <code>activate.bat</code> running arbitrary commands from a crafted <code>--prompt</code>, <code>VIRTUALENV_PROMPT</code>, or config file value. (:issue:<code>3250</code>)</li> <li>Verify a downloaded seed wheel's sha256 against PyPI before seeding it into a virtual environment, skipped when a custom pip index is configured. (:issue:<code>3251</code>)</li> </ul> <hr /> <p>v21.7.11 (2026-09-17)</p> <hr /> <h1>Bugfixes - 21.7.11</h1> <ul> <li>Running <code>activate.bat</code> again before <code>deactivate</code> no longer makes <code>deactivate</code> leave the environment's <code>PKG_CONFIG_PATH</code>, <code>TCL_LIBRARY</code> and <code>TK_LIBRARY</code> behind, or lose values the user had set before the first activation - by :user:<code>darrenhuai</code>. (:issue:<code>3245</code>)</li> <li>Write <code>pyvenv.cfg</code> values on a single line, so a prompt carrying a line boundary can no longer inject configuration. <code>--prompt</code>, the <code>VIRTUALENV_PROMPT</code> environment variable and the config file all set the prompt, and <code>pyvenv.cfg</code> has no escape syntax, so a newline, a carriage return, or any other boundary <code>str.splitlines</code> recognizes, such as <code>U+2028</code>, started a new configuration line. Reading the file back picked up those lines as keys, and since the last value for a key wins, they replaced anything written earlier, including <code>home</code>. (:issue:<code>3247</code>)</li> </ul> <h1>Improved Documentation - 21.7.11</h1> <ul> <li>Document the policy for AI-assisted contributions and the licensing rules for dependencies. (:issue:<code>3239</code>)</li> </ul> <h1>Misc - 21.7.11</h1> <ul> <li>:issue:<code>3238</code>, :issue:<code>3240</code>, :issue:<code>3241</code>, :issue:<code>3242</code>, :issue:<code>3243</code>, :issue:<code>3244</code>, :issue:<code>3246</code></li> </ul> <hr /> <p>v21.7.10 (2026-09-15)</p> <hr /> <h1>Bugfixes - 21.7.10</h1> <ul> <li>Skip blank lines, <code>#</code> comments and lines without <code>=</code> in <code>pyvenv.cfg</code> instead of raising <code>ValueError</code> - by :user:<code>r3wretrhy</code>. (:issue:<code>3232</code>)</li> <li><code>deactivate</code> in bash, fish and PowerShell unsets <code>PKG_CONFIG_PATH</code> when activation found it unset, instead of keeping the environment's <code>lib/pkgconfig</code>. csh activation no longer drops a <code>PKG_CONFIG_PATH</code> the user had set. Activation in batch, fish, nushell and PowerShell no longer adds a trailing separator when <code>PKG_CONFIG_PATH</code> is unset, and PowerShell and nushell build the value with the host's path separators - by :user:<code>darrenhuai</code>. (:issue:<code>3233</code>)</li> <li>Activation in bash, csh, fish and PowerShell keeps the user's <code>TCL_LIBRARY</code> and <code>TK_LIBRARY</code>, and <code>deactivate</code> restores them. csh and PowerShell removed both variables on every activation, fish did so when the interpreter has</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pypa/virtualenv/commit/9666b42afc8d6103e765d77958d7bae782f5406e"><code>9666b42</code></a> release 21.7.12</li> <li><a href="https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d"><code>a01ed3e</code></a> 🐛 fix(seed): verify downloaded wheel digests (<a href="https://redirect.github.com/pypa/virtualenv/issues/3251">#3251</a>)</li> <li><a href="https://github.com/pypa/virtualenv/commit/d721ff140ce4afdc2a9b76751e4584e25d9fbea6"><code>d721ff1</code></a> 🐛 fix(activation): escape batch quote() against injection (<a href="https://redirect.github.com/pypa/virtualenv/issues/3250">#3250</a>)</li> <li><a href="https://github.com/pypa/virtualenv/commit/087a2ef8bd3aa15b562a3558b1068f603e50f77a"><code>087a2ef</code></a> 🔧 chore(changelog): drop dead CVE-2026-24049 fragment (<a href="https://redirect.github.com/pypa/virtualenv/issues/3249">#3249</a>)</li> <li><a href="https://github.com/pypa/virtualenv/commit/73e352ae02bfa52ffc0e307b04f1b6a7168c4eb0"><code>73e352a</code></a> release 21.7.11</li> <li><a href="https://github.com/pypa/virtualenv/commit/68ee5a3f27ca44912af9bd73c4c87e41978a8c08"><code>68ee5a3</code></a> 📝 docs(readme): add OpenSSF Best Practices badge (<a href="https://redirect.github.com/pypa/virtualenv/issues/3248">#3248</a>)</li> <li><a href="https://github.com/pypa/virtualenv/commit/787d1c9a0843310200f37861e6b2744a7d1e5364"><code>787d1c9</code></a> 🔧 chore(test): add opt-in Atheris fuzz harness (<a href="https://redirect.github.com/pypa/virtualenv/issues/3246">#3246</a>)</li> <li><a href="https://github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140"><code>a30f995</code></a> 🐛 fix(create): keep pyvenv.cfg values on a single line (<a href="https://redirect.github.com/pypa/virtualenv/issues/3247">#3247</a>)</li> <li><a href="https://github.com/pypa/virtualenv/commit/469dd28e659f7cd3e7d8cdb3f1245c125d32e817"><code>469dd28</code></a> 🐛 fix(activation): undo a live activation before activate.bat saves values (#...</li> <li><a href="https://github.com/pypa/virtualenv/commit/a045a14c76dcb71d1811fe57aa6c5f4fad2357cd"><code>a045a14</code></a> 👷 ci: run macOS jobs on macos-26 (<a href="https://redirect.github.com/pypa/virtualenv/issues/3244">#3244</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pypa/virtualenv/compare/21.2.4...21.7.12">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b1765f3d0f |
chore(deps): bump the minor-and-patch group in /libs/checkpoint-postgres with 6 updates (#9147)
Bumps the minor-and-patch group in /libs/checkpoint-postgres with 6 updates: | Package | From | To | | --- | --- | --- | | [psycopg](https://github.com/psycopg/psycopg) | `3.3.4` | `3.3.6` | | [psycopg-pool](https://github.com/psycopg/psycopg) | `3.3.1` | `3.3.3` | | [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.1` | | [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` | `3.16.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.9` | | [ty](https://github.com/astral-sh/ty) | `0.0.75` | `0.0.84` | Updates `psycopg` from 3.3.4 to 3.3.6 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/psycopg/psycopg/blob/master/docs/news.rst">psycopg's changelog</a>.</em></p> <blockquote> <p>.. currentmodule:: psycopg</p> <p>.. index:: single: Release notes single: News</p> <h1><code>psycopg</code> release notes</h1> <h2>Future releases</h2> <p>Psycopg 3.3.7 (unreleased) ^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Fix segfault fetching arrays of strings or timestamps after closing the connection (🎫<code>[#1428](https://github.com/psycopg/psycopg/issues/1428)</code>).</li> </ul> <h2>Current release</h2> <p>Psycopg 3.3.6 ^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.15 (🎫<code>[#1245](https://github.com/psycopg/psycopg/issues/1245)</code>).</li> <li>Improve performance of async queries by reducing the overhead of the <code>!wait_async()</code> function (🎫<code>[#1331](https://github.com/psycopg/psycopg/issues/1331)</code>).</li> <li>Don't wait forever for a query to terminate after interrupting it, for instance if the server is unresponsive. The fix requires libpq 17 or newer (🎫<code>[#1371](https://github.com/psycopg/psycopg/issues/1371)</code>).</li> <li>Cancel a running query upon receiving <code>!SystemExit</code> (🎫<code>[#1384](https://github.com/psycopg/psycopg/issues/1384)</code>).</li> <li>Report <code>!None</code> instead of <code>65535</code> as the <code>Column.precision</code> of an :sql:<code>interval</code> column declared with a fields restriction and no explicit precision, such as e.g. :sql:<code>interval day to second</code> (🎫<code>[#1397](https://github.com/psycopg/psycopg/issues/1397)</code>).</li> <li>Fix dumping of nested subclasses of lists as arrays (🎫<code>[#1398](https://github.com/psycopg/psycopg/issues/1398)</code>).</li> <li>Discard prepared statements upon :sql:<code>DEALLOCATE ALL</code> (🎫<code>[#1408](https://github.com/psycopg/psycopg/issues/1408)</code>).</li> <li>Better guards dumping large Python <code>!int</code> to binary numeric (🎫<code>[#1414](https://github.com/psycopg/psycopg/issues/1414)</code>).</li> </ul> <p>Psycopg 3.3.5 ^^^^^^^^^^^^^</p> <ul> <li>Discard prepared statements upon :sql:<code>ALTER *</code> or <code>DISCARD *</code> (🎫<code>[#1307](https://github.com/psycopg/psycopg/issues/1307)</code>).</li> <li>Fix <code>!ProgrammingError</code> when dumping non-<code>!None</code> values with no <code>!NoneType</code> dumper registered in python implementation (🎫<code>[#1325](https://github.com/psycopg/psycopg/issues/1325)</code>).</li> <li>Fix <code>!wait_selector</code> wait function to not raise <code>!KeyError</code> (🎫<code>[#1327](https://github.com/psycopg/psycopg/issues/1327)</code>).</li> <li>Fix <code>!DataError</code> messages leaking the literal <code>{...}</code> placeholder instead</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/psycopg/psycopg/commit/a67654d1e7afbf9b3a619557838f62de1c790e7c"><code>a67654d</code></a> chore: bump psycopg package version to 3.3.6</li> <li><a href="https://github.com/psycopg/psycopg/commit/443814b3b111ac678a39fd523c1a826266fb69b5"><code>443814b</code></a> Merge pull request <a href="https://redirect.github.com/psycopg/psycopg/issues/1416">#1416</a> from dvarrazzo/wait-async-perf</li> <li><a href="https://github.com/psycopg/psycopg/commit/42966e9ebbda3b9c69b15c5588543c15f2aae5dd"><code>42966e9</code></a> test: add helpful comments to some tests</li> <li><a href="https://github.com/psycopg/psycopg/commit/5e8797f0c8003d8cd12a1e5c13f05fbb94c1c1d2"><code>5e8797f</code></a> test: add reasonable connect_timeout to most tests</li> <li><a href="https://github.com/psycopg/psycopg/commit/c81ba62442dfbd69e207d6914e6ae2aa27e56886"><code>c81ba62</code></a> perf: reduce the overhead of wait_async()</li> <li><a href="https://github.com/psycopg/psycopg/commit/d2bbfe4e2b1e36a20e72a18097f35a3db27296e3"><code>d2bbfe4</code></a> refactor: use get_running_loop() in the async wait functions</li> <li><a href="https://github.com/psycopg/psycopg/commit/2b1484a550e01c88fda077099678f0abb9217ecb"><code>2b1484a</code></a> test: add a script to measure the async wait functions</li> <li><a href="https://github.com/psycopg/psycopg/commit/573cf4aa70d8fdefc9d5f3eb69d5419cd6d3cd51"><code>573cf4a</code></a> test: fix incorrect wait timing test</li> <li><a href="https://github.com/psycopg/psycopg/commit/2b68990874175b8d97269218d4963b2d5c8656f3"><code>2b68990</code></a> refactor: drop leftovers of waiting with inf interval in wait_conn_async</li> <li><a href="https://github.com/psycopg/psycopg/commit/60765dd8fc7d8df03cd75efcff485bfb3c83a0ed"><code>60765dd</code></a> Merge pull request <a href="https://redirect.github.com/psycopg/psycopg/issues/1414">#1414</a> from dvarrazzo/fix-decimal-overflow</li> <li>Additional commits viewable in <a href="https://github.com/psycopg/psycopg/compare/3.3.4...3.3.6">compare view</a></li> </ul> </details> <br /> Updates `psycopg-pool` from 3.3.1 to 3.3.3 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/psycopg/psycopg/blob/master/docs/news.rst">psycopg-pool's changelog</a>.</em></p> <blockquote> <p>.. currentmodule:: psycopg</p> <p>.. index:: single: Release notes single: News</p> <h1><code>psycopg</code> release notes</h1> <h2>Future releases</h2> <p>Psycopg 3.3.7 (unreleased) ^^^^^^^^^^^^^^^^^^^^^^^^^^</p> <ul> <li>Fix segfault fetching arrays of strings or timestamps after closing the connection (🎫<code>[#1428](https://github.com/psycopg/psycopg/issues/1428)</code>).</li> </ul> <h2>Current release</h2> <p>Psycopg 3.3.6 ^^^^^^^^^^^^^</p> <ul> <li>Add support for Python 3.15 (🎫<code>[#1245](https://github.com/psycopg/psycopg/issues/1245)</code>).</li> <li>Improve performance of async queries by reducing the overhead of the <code>!wait_async()</code> function (🎫<code>[#1331](https://github.com/psycopg/psycopg/issues/1331)</code>).</li> <li>Don't wait forever for a query to terminate after interrupting it, for instance if the server is unresponsive. The fix requires libpq 17 or newer (🎫<code>[#1371](https://github.com/psycopg/psycopg/issues/1371)</code>).</li> <li>Cancel a running query upon receiving <code>!SystemExit</code> (🎫<code>[#1384](https://github.com/psycopg/psycopg/issues/1384)</code>).</li> <li>Report <code>!None</code> instead of <code>65535</code> as the <code>Column.precision</code> of an :sql:<code>interval</code> column declared with a fields restriction and no explicit precision, such as e.g. :sql:<code>interval day to second</code> (🎫<code>[#1397](https://github.com/psycopg/psycopg/issues/1397)</code>).</li> <li>Fix dumping of nested subclasses of lists as arrays (🎫<code>[#1398](https://github.com/psycopg/psycopg/issues/1398)</code>).</li> <li>Discard prepared statements upon :sql:<code>DEALLOCATE ALL</code> (🎫<code>[#1408](https://github.com/psycopg/psycopg/issues/1408)</code>).</li> <li>Better guards dumping large Python <code>!int</code> to binary numeric (🎫<code>[#1414](https://github.com/psycopg/psycopg/issues/1414)</code>).</li> </ul> <p>Psycopg 3.3.5 ^^^^^^^^^^^^^</p> <ul> <li>Discard prepared statements upon :sql:<code>ALTER *</code> or <code>DISCARD *</code> (🎫<code>[#1307](https://github.com/psycopg/psycopg/issues/1307)</code>).</li> <li>Fix <code>!ProgrammingError</code> when dumping non-<code>!None</code> values with no <code>!NoneType</code> dumper registered in python implementation (🎫<code>[#1325](https://github.com/psycopg/psycopg/issues/1325)</code>).</li> <li>Fix <code>!wait_selector</code> wait function to not raise <code>!KeyError</code> (🎫<code>[#1327](https://github.com/psycopg/psycopg/issues/1327)</code>).</li> <li>Fix <code>!DataError</code> messages leaking the literal <code>{...}</code> placeholder instead</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/psycopg/psycopg/commit/1a8f65a371da3c691111cd4a81141f2cb698eafa"><code>1a8f65a</code></a> chore: bump psycopg package version to 3.3.3</li> <li><a href="https://github.com/psycopg/psycopg/commit/db3c43584320ab5d97e49378e5c9dc09a560b031"><code>db3c435</code></a> Merge pull request <a href="https://redirect.github.com/psycopg/psycopg/issues/1260">#1260</a> from ggevay/sync-error-fix</li> <li><a href="https://github.com/psycopg/psycopg/commit/0237586c415ece15102742f5941874c29fb1221c"><code>0237586</code></a> Fix ValueError when server sends ErrorResponse during Sync after Parse</li> <li><a href="https://github.com/psycopg/psycopg/commit/cb97ef7063520cb8a0cb5236bb9791f8dc4cc454"><code>cb97ef7</code></a> docs: fix typos</li> <li><a href="https://github.com/psycopg/psycopg/commit/09c89180f94606dc70475ed863e135f021a11038"><code>09c8918</code></a> Merge pull request <a href="https://redirect.github.com/psycopg/psycopg/issues/1256">#1256</a> from veeceey/fix/tstrings-error-msg-and-docs-improve...</li> <li><a href="https://github.com/psycopg/psycopg/commit/9e74d9646cc3fcbb9d8940182dcdb41119c3fda7"><code>9e74d96</code></a> fix: fix error message incorrectly generated by Claude AI</li> <li><a href="https://github.com/psycopg/psycopg/commit/0db9d8bb76c48e70dffd48776406fd3ffdc89b5a"><code>0db9d8b</code></a> fix: correct typo in tstrings error message and fix sql.rst docs</li> <li><a href="https://github.com/psycopg/psycopg/commit/86a0e1b2bbf30c564c59bf3497d499e2f220ce0f"><code>86a0e1b</code></a> chore(deps): bump pypa/cibuildwheel in the actions group</li> <li><a href="https://github.com/psycopg/psycopg/commit/f5d90fa2a7836c1268c1d43d0d77c431434ad191"><code>f5d90fa</code></a> Merge pull request <a href="https://redirect.github.com/psycopg/psycopg/issues/1233">#1233</a> from lysnikolaou/pgconn-critical-section</li> <li><a href="https://github.com/psycopg/psycopg/commit/d7dc6c7cacc2832fffa0d7e607b5fc171424571d"><code>d7dc6c7</code></a> Merge critical section and nogil blocks into one context manager</li> <li>Additional commits viewable in <a href="https://github.com/psycopg/psycopg/compare/3.3.1...3.3.3">compare view</a></li> </ul> </details> <br /> Updates `anyio` from 4.14.2 to 4.15.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agronholm/anyio/releases">anyio's releases</a>.</em></p> <blockquote> <h2>4.15.1</h2> <ul> <li>Implemented a compatibility fix for supporting direct access of <code>anyio.*</code> submodules from the main package even when those submodules were not directly imported first (<!-- raw HTML omitted --><a href="https://redirect.github.com/agronholm/anyio/issues/1311">#1311</a> <<a href="https://redirect.github.com/agronholm/anyio/issues/1311%5C%3E">agronholm/anyio#1311</a><!-- raw HTML omitted -->)</li> </ul> <h2>4.15.0</h2> <ul> <li> <p>Added support for the newer keyword-only arguments on <code>anyio.Path</code> methods to match the standard library <code>pathlib.Path</code>:</p> <ul> <li><code>follow_symlinks</code> on <code>exists()</code> (Python 3.12+)</li> <li><code>follow_symlinks</code> on <code>is_dir()</code> (Python 3.13+)</li> <li><code>follow_symlinks</code> on <code>is_file()</code> (Python 3.13+)</li> <li><code>follow_symlinks</code> on <code>owner()</code> (Python 3.13+)</li> <li><code>follow_symlinks</code> on <code>group()</code> (Python 3.13+)</li> <li><code>newline</code> on <code>read_text()</code> (Python 3.13+)</li> </ul> <p>(<a href="https://redirect.github.com/agronholm/anyio/pull/1286">#1286</a>, <a href="https://redirect.github.com/agronholm/anyio/pull/1293">#1293</a>; PR by <a href="https://github.com/jaideeppyne"><code>@jaideeppyne</code></a>)</p> </li> <li> <p>Added <code>amap</code>, <code>gather</code>, and <code>as_completed</code> utility functions to simplify common patterns (<a href="https://redirect.github.com/agronholm/anyio/pull/1173">#1173</a>; PR by <a href="https://github.com/Graeme22"><code>@Graeme22</code></a>)</p> </li> <li> <p>Added <code>--anyio-mode</code> command-line option as an alternative to the <code>anyio_mode</code> ini setting, and fix the pytest plugin's auto mode detection to recognize the mode when set via either mechanism(e.g: <code>pytest_asyncio</code>). (<a href="https://redirect.github.com/agronholm/anyio/pull/1242">#1242</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Added the <code>anyio.Future</code> synchronization primitive which behaves similar to <code>asyncio.Future</code>, allowing tasks to wait for a value (or exception) from another task (<a href="https://redirect.github.com/agronholm/anyio/pull/1146">#1146</a>; PR by <a href="https://github.com/Vizonex"><code>@Vizonex</code></a>)</p> </li> <li> <p>Added guidance for managing multiple memory object stream producers and consumers with cloned streams (<a href="https://redirect.github.com/agronholm/anyio/issues/330">#330</a>; PR by <a href="https://github.com/nightcityblade"><code>@nightcityblade</code></a>)</p> </li> <li> <p>Added <code>StapledObjectStream.send_nowait()</code> that delegates to the underlying <code>ObjectSendStream</code>, if it implements it (<a href="https://redirect.github.com/agronholm/anyio/pull/1241">#1241</a>; PR by <a href="https://github.com/davidbrochart"><code>@davidbrochart</code></a>)</p> </li> <li> <p>Added the <code>move_on_at()</code> and <code>fail_at()</code> functions to complement <code>move_on_after()</code> and <code>fail_after()</code></p> </li> <li> <p>Changed the default name for a task spawned with <code>TaskGroup.create_task(func())</code> to match the default task name for the analogous task spawned with <code>TaskGroup.start_soon(func)</code> or <code>TaskGroup.start(func)</code> in more situations. Previously, the default name of a <code>TaskGroup.create_task</code> task never included the module name. (The default name for a task spawned with <code>TaskGroup.start_soon</code> or <code>TaskGroup.start</code> typically includes the module name.) (<a href="https://redirect.github.com/agronholm/anyio/pull/1234">#1234</a>; PR by <a href="https://github.com/gschaffner"><code>@gschaffner</code></a>)</p> </li> <li> <p>Changed the <code>anyio</code> and <code>anyio.abc</code> modules to lazily (much like <code>810</code>) import the necessary submodules. This is done by parsing the AST of the module and building a lookup table from the <code>if TYPE_CHECKING:</code> block. A fallback mode has been provided for installations where the source code is unavailable (e.g. PyInstaller). (<a href="https://redirect.github.com/agronholm/anyio/pull/1169">#1169</a>)</p> </li> <li> <p>Fixed free-threading compatibility issues arising from the fact that on Python 3.14 free-threading builds, newly created threads inherit the current context by default, causing AnyIO to behave erroneously in relation to <code>start_blocking_portal()</code> and <code>anyio.to_thread.run_sync()</code> (<a href="https://redirect.github.com/agronholm/anyio/pull/1224">#1224</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Fixed <code>SpooledTemporaryFile.readinto()</code> and <code>readinto1()</code> reading twice before rollover, so the destination buffer was overwritten by the second read and the file position advanced twice, silently losing data (<a href="https://redirect.github.com/agronholm/anyio/pull/1215">#1215</a>; PR by <a href="https://github.com/c-tonneslan"><code>@c-tonneslan</code></a>)</p> </li> <li> <p>Added a <code>reason</code> parameter to <code>fail_after</code> (and the new <code>fail_at</code>) allowing for added exception context when raising <code>TimeoutError</code> (<a href="https://redirect.github.com/agronholm/anyio/pull/1227">#1227</a>; PR by <a href="https://github.com/Graeme22"><code>@Graeme22</code></a>)</p> </li> <li> <p>Fixed the default <code>TaskHandle.name</code> missing part of the task name for tasks started with <code>TaskGroup.start</code> on Trio (<a href="https://redirect.github.com/agronholm/anyio/issues/1231">#1231</a>; PR by <a href="https://github.com/gschaffner"><code>@gschaffner</code></a>)</p> </li> <li> <p>Fixed <code>anyio.run</code> leaking, or at least, delaying collection of loop and root_task due to the root task being cached in a <code>RunVar</code>. (<a href="https://redirect.github.com/agronholm/anyio/issues/1203">#1203</a>; PR by <a href="https://github.com/tapetersen"><code>@tapetersen</code></a>)</p> </li> <li> <p>Fixed <code>anyio.Path.with_stem()</code> silently producing a wrong path (e.g. <code>Path(".txt")</code>) instead of raising <code>ValueError</code> when given an empty stem on a path with a non-empty suffix, unlike <code>pathlib.PurePath.with_stem</code> (<a href="https://redirect.github.com/agronholm/anyio/pull/1200">#1200</a>; PR by <a href="https://github.com/Sanjays2402"><code>@Sanjays2402</code></a>)</p> </li> <li> <p>Fixed <code>UNIXSocketStream.aclose()</code> raising <code>asyncio.InvalidStateError</code> when a concurrent receive or send operation had just been cancelled on the asyncio backend (<a href="https://redirect.github.com/agronholm/anyio/issues/1267">#1267</a>; PR by <a href="https://github.com/alloutflo"><code>@alloutflo</code></a>)</p> </li> <li> <p>Fixed the pytest plugin importing the deprecated <code>_pytest.python.CallSpec2</code> alias, which triggers <code>PytestRemovedIn10Warning</code> on <code>pytest>=9.2</code> and crashes pytest at startup when <code>filterwarnings = error</code> is configured (<a href="https://redirect.github.com/agronholm/anyio/issues/1271">#1271</a>; PR by <a href="https://github.com/matthewfeickert"><code>@matthewfeickert</code></a>)</p> </li> <li> <p>Fixed an asyncio worker thread race that could raise <code>RuntimeError</code> when the event loop closed between checking its state and scheduling the worker result (<a href="https://redirect.github.com/agronholm/anyio/issues/1265">#1265</a>; PR by <a href="https://github.com/hansu650"><code>@hansu650</code></a>)</p> </li> <li> <p>Fixed <code>CapacityLimiter</code> on the asyncio backend over-granting tokens when <code>total_tokens</code> was raised while the limiter was over-subscribed (<a href="https://redirect.github.com/agronholm/anyio/pull/1223">#1223</a>; PR by <a href="https://github.com/zelinewang"><code>@zelinewang</code></a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agronholm/anyio/commit/ffcd1542cd6d127980205f90a0100078849dd703"><code>ffcd154</code></a> Bumped up the version</li> <li><a href="https://github.com/agronholm/anyio/commit/0ecf5ed98d294242509b043ebd1a0843e52d892f"><code>0ecf5ed</code></a> Added a workaround for third party code accessing unimported submodules (<a href="https://redirect.github.com/agronholm/anyio/issues/1309">#1309</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/928366259543412a2deb1e2ba09ea45ffa92ef4f"><code>9283662</code></a> Bumped up the version</li> <li><a href="https://github.com/agronholm/anyio/commit/d137692a90f76e4f71605e32ea5ca94cab3a539d"><code>d137692</code></a> Improved the instructions for AI agents</li> <li><a href="https://github.com/agronholm/anyio/commit/033fc52b8fa8e90c5d0ef24b10b3860e974a6265"><code>033fc52</code></a> Shield TemporaryDirectory cleanup from cancellation (<a href="https://redirect.github.com/agronholm/anyio/issues/1304">#1304</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/942e9a6552cc10b5aaa779d84bfc8e2c3d5fcffc"><code>942e9a6</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/agronholm/anyio/issues/1305">#1305</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/b825c3be7cb4ca1a8000b8065d4e147843deb704"><code>b825c3b</code></a> Fixed pyproject.toml changes not triggering the test suite</li> <li><a href="https://github.com/agronholm/anyio/commit/9727dc504681e2986b5bc285de9571fb467539af"><code>9727dc5</code></a> Fixed start inconsistencies between trio and asyncio (<a href="https://redirect.github.com/agronholm/anyio/issues/1198">#1198</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/b05fe6d160a640355c201363cab286a7d2581da8"><code>b05fe6d</code></a> Fixed wrong type in move_on_after (<a href="https://redirect.github.com/agronholm/anyio/issues/1297">#1297</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/44d0c93cc20079acbf38ba4dbed5ab9df323f153"><code>44d0c93</code></a> Fixed asyncio task group coroutine cleanup (<a href="https://redirect.github.com/agronholm/anyio/issues/1275">#1275</a>)</li> <li>Additional commits viewable in <a href="https://github.com/agronholm/anyio/compare/4.14.2...4.15.1">compare view</a></li> </ul> </details> <br /> Updates `pytest-mock` from 3.15.1 to 3.16.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's releases</a>.</em></p> <blockquote> <h2>v3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's changelog</a>.</em></p> <blockquote> <h2>3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604></code>_: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611></code>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606></code>_: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547></code>_: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147></code>_: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a> Release 3.16.0</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a> Fix duplicate_iterators for async spies (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a> Fix async assertion argument introspection (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a> docs: import os in the opening usage example (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a> Honour resetall() arguments for non-callable mocks (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.5 to 0.16.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.9</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>Install ruff 0.16.9</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh </code></pre> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.9</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>0.16.8</h2> <p>Released on 2026-09-16.</p> <h3>Bug fixes</h3> <ul> <li>Visit functional <code>TypedDict</code> keyword arguments correctly (<a href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li> <li>[<code>flake8-simplify</code>] Detect nested <code>async with</code> under sync parent (<code>SIM117</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li> <li>[<code>flake8-simplify</code>] Preserve operand order in <code>SIM109</code> fix (<a href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a> Bump version to 0.16.9 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a> Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a> Update dependency astral-sh/uv to v0.12.18 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a> [<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>...</li> <li><a href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a> Use <code>target</code> form in <code>rooster.version_files</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a> [ty] Prefer existing @ paths over response files in Ruff and ty (<a href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a> ci(github): update version number in placeholder of issue template (<a href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a> [ty] Propagate outer type context through cast calls (<a href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a> [ty] Contain rendered code within Markdown fences (<a href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a> authorize ruff-pre-commit dispatch via OIDC (<a href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare view</a></li> </ul> </details> <br /> Updates `ty` from 0.0.75 to 0.0.84 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/releases">ty's releases</a>.</em></p> <blockquote> <h2>0.0.84</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's changelog</a>.</em></p> <blockquote> <h2>0.0.84</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a> Bump version to 0.0.84 (<a href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a> publish to astral-sh/versions via OIDC (<a href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a> use oidc issued token for docs publication (<a href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a> Update prek dependencies (<a href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a> Update docker/setup-buildx-action action to v4.3.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a> Update astral-sh/setup-uv action to v10.2.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a> Bump version to 0.0.83 (<a href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a> Sync the ty security mirror (<a href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a> Grant the versions workflow repository read access (<a href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a> use scoped token for release workflow (<a href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
3a2501e8c5 |
chore(deps): bump the minor-and-patch group in /libs/checkpoint with 4 updates (#9148)
Bumps the minor-and-patch group in /libs/checkpoint with 4 updates: [langchain-core](https://github.com/langchain-ai/langchain), [pytest-mock](https://github.com/pytest-dev/pytest-mock), [ruff](https://github.com/astral-sh/ruff) and [ty](https://github.com/astral-sh/ty). Updates `langchain-core` from 1.6.1 to 1.6.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langchain/releases">langchain-core's releases</a>.</em></p> <blockquote> <h2>langchain-core==1.6.5</h2> <p>Changes since langchain-core==1.6.4</p> <p>release(core): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>) fix(core): abbreviate long tool IDs in XML buffer strings (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</p> <h2>langchain-core==1.6.4</h2> <p>Changes since langchain-core==1.6.3</p> <p>release(core): 1.6.4 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40718">#40718</a>) chore(core): deprecate chat message history (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40711">#40711</a>) chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40634">#40634</a>) chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40574">#40574</a>)</p> <h2>langchain-core==1.6.3</h2> <p>Changes since langchain-core==1.6.2</p> <p>release(core): 1.6.3 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40407">#40407</a>) feat(core): Allow model name and provider tracing metadata override based on gateway response (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40406">#40406</a>) test(core): cover the deprecated <code>.text()</code> access path (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40243">#40243</a>) docs(core): remove stale Args/Raises entries from FileCallbackHandler._write and ChatGeneration.set_text (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40211">#40211</a>)</p> <h2>langchain-core==1.6.2</h2> <p>Changes since langchain-core==1.6.1</p> <p>release(core): 1.6.2 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40209">#40209</a>) feat(openai): support async tools (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40208">#40208</a>) chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40150">#40150</a>) chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40113">#40113</a>) fix(core): avoid mutation in google-genai standard content (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40023">#40023</a>) fix(core): avoid mutation in bedrock converse standard content (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40022">#40022</a>)</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langchain/commit/c5ab14d42a3e22865c9def909de0b11d70b0bbf0"><code>c5ab14d</code></a> release(core): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40816">#40816</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/5704d9d4813f8c0527f04e2662cf313e1350f96f"><code>5704d9d</code></a> chore(model-profiles): refresh model profile data (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40804">#40804</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/7622d3dce760ac4be6d9aef4c653277e06064aea"><code>7622d3d</code></a> release(openai): 1.6.6 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40800">#40800</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/2dd956b8add667dac4f97605ae441d75b8ae228e"><code>2dd956b</code></a> docs(infra): fix AGENTS.md root setup guidance and package doc accuracy (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40794">#40794</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/49f4b4016b82513c3dc1623bf3daa10453861621"><code>49f4b40</code></a> fix(openai): raise on error events in stream path (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40791">#40791</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/19cadaa1a1e0cac71f3148e2f18b414dcab17426"><code>19cadaa</code></a> fix(core): abbreviate long tool IDs in XML buffer strings (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40792">#40792</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/798441e8b07e88e79db355db452cd9492f9628f2"><code>798441e</code></a> chore(anthropic): fix integration test cassette (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40790">#40790</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/a476942bac3fe5e521676d0f53fabafcb7ba71b1"><code>a476942</code></a> release(openai): 1.6.5 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40787">#40787</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/46c6bdf1b4e23028a5acc060d8b2797dbf200291"><code>46c6bdf</code></a> release(anthropic): 1.7.4 (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40786">#40786</a>)</li> <li><a href="https://github.com/langchain-ai/langchain/commit/290dabaff27ee379920d55d155d5055d2fe29cc8"><code>290daba</code></a> fix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (<a href="https://redirect.github.com/langchain-ai/langchain/issues/40785">#40785</a>)</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langchain/compare/langchain-core==1.6.1...langchain-core==1.6.5">compare view</a></li> </ul> </details> <br /> Updates `pytest-mock` from 3.15.1 to 3.16.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's releases</a>.</em></p> <blockquote> <h2>v3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's changelog</a>.</em></p> <blockquote> <h2>3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604></code>_: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611></code>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606></code>_: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547></code>_: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147></code>_: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a> Release 3.16.0</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a> Fix duplicate_iterators for async spies (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a> Fix async assertion argument introspection (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a> docs: import os in the opening usage example (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a> Honour resetall() arguments for non-callable mocks (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.5 to 0.16.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.9</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>Install ruff 0.16.9</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh </code></pre> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.9</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>0.16.8</h2> <p>Released on 2026-09-16.</p> <h3>Bug fixes</h3> <ul> <li>Visit functional <code>TypedDict</code> keyword arguments correctly (<a href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li> <li>[<code>flake8-simplify</code>] Detect nested <code>async with</code> under sync parent (<code>SIM117</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li> <li>[<code>flake8-simplify</code>] Preserve operand order in <code>SIM109</code> fix (<a href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a> Bump version to 0.16.9 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a> Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a> Update dependency astral-sh/uv to v0.12.18 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a> [<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>...</li> <li><a href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a> Use <code>target</code> form in <code>rooster.version_files</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a> [ty] Prefer existing @ paths over response files in Ruff and ty (<a href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a> ci(github): update version number in placeholder of issue template (<a href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a> [ty] Propagate outer type context through cast calls (<a href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a> [ty] Contain rendered code within Markdown fences (<a href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a> authorize ruff-pre-commit dispatch via OIDC (<a href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare view</a></li> </ul> </details> <br /> Updates `ty` from 0.0.75 to 0.0.84 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/releases">ty's releases</a>.</em></p> <blockquote> <h2>0.0.84</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's changelog</a>.</em></p> <blockquote> <h2>0.0.84</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a> Bump version to 0.0.84 (<a href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a> publish to astral-sh/versions via OIDC (<a href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a> use oidc issued token for docs publication (<a href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a> Update prek dependencies (<a href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a> Update docker/setup-buildx-action action to v4.3.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a> Update astral-sh/setup-uv action to v10.2.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a> Bump version to 0.0.83 (<a href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a> Sync the ty security mirror (<a href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a> Grant the versions workflow repository read access (<a href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a> use scoped token for release workflow (<a href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
3474bbff29 |
chore(deps): bump the minor-and-patch group in /libs/cli/js-monorepo-example with 8 updates (#9151)
Bumps the minor-and-patch group in /libs/cli/js-monorepo-example with 8 updates: | Package | From | To | | --- | --- | --- | | [turbo](https://github.com/vercel/turborepo) | `2.10.12` | `2.11.5` | | [@eslint/eslintrc](https://github.com/eslint/eslintrc) | `3.3.6` | `3.3.7` | | [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.11.0` | | [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.68.0` | `8.70.1` | | [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.68.0` | `8.70.1` | | [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` | | [@langchain/core](https://github.com/langchain-ai/langchainjs) | `1.2.9` | `1.2.13` | | [@langchain/langgraph](https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core) | `1.4.13` | `1.4.18` | Updates `turbo` from 2.10.12 to 2.11.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vercel/turborepo/releases">turbo's releases</a>.</em></p> <blockquote> <h2>Turborepo v2.11.5</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <h3>Changelog</h3> <ul> <li>chore: Release Turborepo 2.11.4 by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/vercel/turborepo/pull/14231">vercel/turborepo#14231</a></li> <li>test: Move Python opt-in hint into filter contracts by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14228">vercel/turborepo#14228</a></li> <li>test: Move dependency-output summary assertion into contract by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14230">vercel/turborepo#14230</a></li> <li>test: Move dependency-output selection and validation cases to engine contracts by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14232">vercel/turborepo#14232</a></li> <li>test: Move Cargo exclude-only scope coverage by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14238">vercel/turborepo#14238</a></li> <li>test: Move Cargo cache-authority cases to contracts by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14240">vercel/turborepo#14240</a></li> <li>test: Move JIT dependency graph scenario into engine contract by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14235">vercel/turborepo#14235</a></li> <li>test: Move dependency-output hash cases into task-hash contracts by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14233">vercel/turborepo#14233</a></li> <li>test: Move Cargo task-filter cases into crate contracts by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14239">vercel/turborepo#14239</a></li> <li>test: Move JIT input hash timing cases into task-hash contracts by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14234">vercel/turborepo#14234</a></li> <li>test: Move package input normalization cases into engine contracts by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14236">vercel/turborepo#14236</a></li> <li>test: Move structured startup and JIT input cases into contracts by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14237">vercel/turborepo#14237</a></li> <li>fix: Back off remote artifact requests during outages by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14222">vercel/turborepo#14222</a></li> <li>chore: Release Turborepo 2.11.5-canary.1 by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/vercel/turborepo/pull/14245">vercel/turborepo#14245</a></li> <li>test: Make new-package lockfile filter deterministic by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14241">vercel/turborepo#14241</a></li> <li>test: Trim redundant Go cache builds by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14242">vercel/turborepo#14242</a></li> <li>test: Reduce Go versioned-name test matrix by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14243">vercel/turborepo#14243</a></li> <li>test: Move Go binary checks into contracts by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14246">vercel/turborepo#14246</a></li> <li>test: Consolidate Go format smokes by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14244">vercel/turborepo#14244</a></li> <li>test: Reuse Cargo build artifacts safely by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14247">vercel/turborepo#14247</a></li> <li>test: Separate prune planning matrix from buildability smoke by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14248">vercel/turborepo#14248</a></li> <li>feat: Bundle docs in <code>turbo</code> npm package by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14108">vercel/turborepo#14108</a></li> <li>chore: Release Turborepo 2.11.5-canary.2 by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/vercel/turborepo/pull/14249">vercel/turborepo#14249</a></li> <li>fix: Stabilize pnpm per-workspace lockfile hashes by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14253">vercel/turborepo#14253</a></li> <li>chore: Upgrade factory Next.js to 16.3.3 by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14254">vercel/turborepo#14254</a></li> <li>fix: Update js-yaml to address CVE-2026-84375 by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14255">vercel/turborepo#14255</a></li> <li>chore: Upgrade Next.js in docs and factory for CVE-2026-94545 by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14256">vercel/turborepo#14256</a></li> <li>fix: Remove unmaintained proc-macro-error2 by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14257">vercel/turborepo#14257</a></li> <li>refactor: Replace clap in production CLIs with usage-rs by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14259">vercel/turborepo#14259</a></li> <li>chore: Remove tiny-gradient dependency by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14260">vercel/turborepo#14260</a></li> <li>refactor: Replace human-panic with local crash reporting by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14261">vercel/turborepo#14261</a></li> <li>chore: Remove unused struct_iterable dependency by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14258">vercel/turborepo#14258</a></li> <li>fix: Sign complete on-disk artifacts after local cache writes by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14265">vercel/turborepo#14265</a></li> <li>chore: Remove <code>derive_setters</code> dependency by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14266">vercel/turborepo#14266</a></li> <li>chore: Remove port_scanner dependency by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14267">vercel/turborepo#14267</a></li> <li>chore: Remove unused Rust dependency declarations by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14268">vercel/turborepo#14268</a></li> <li>refactor: Remove unused public Rust APIs by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14269">vercel/turborepo#14269</a></li> <li>refactor: Use workspace Rust edition across crates by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14270">vercel/turborepo#14270</a></li> <li>chore: Clean up Rust Clippy exceptions by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14271">vercel/turborepo#14271</a></li> <li>refactor: Group task-hash and uv generation context by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14279">vercel/turborepo#14279</a></li> <li>refactor: Remove unused global hash wrapper by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14281">vercel/turborepo#14281</a></li> <li>refactor: Remove unused file-hash telemetry argument by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14282">vercel/turborepo#14282</a></li> <li>refactor: Remove dead CLI code and crate-wide allowance by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14283">vercel/turborepo#14283</a></li> <li>refactor: Remove dead Microfrontends config code by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14284">vercel/turborepo#14284</a></li> <li>refactor: Remove unused UI task types and dead-code allowance by <a href="https://github.com/anthonyshew"><code>@anthonyshew</code></a> in <a href="https://redirect.github.com/vercel/turborepo/pull/14286">vercel/turborepo#14286</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vercel/turborepo/commit/8492b42667210270f4169f0df8c0edf725ff2f41"><code>8492b42</code></a> publish 2.11.5 to registry</li> <li><a href="https://github.com/vercel/turborepo/commit/a50ee6536eac2f7f3168cc38087ee7d8397fc0e9"><code>a50ee65</code></a> chore: Release Turborepo 2.11.5-canary.5 (<a href="https://redirect.github.com/vercel/turborepo/issues/14328">#14328</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/c9602f339008964f8dfaf6329491c374cf2f0a60"><code>c9602f3</code></a> fix: Pass repository to release asset commands (<a href="https://redirect.github.com/vercel/turborepo/issues/14327">#14327</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/8cb67669e73cf73bde0a8a9e0a9a829ddd34993f"><code>8cb6766</code></a> fix: Isolate installer test environment (<a href="https://redirect.github.com/vercel/turborepo/issues/14326">#14326</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/5108f6c9fda7a7aeb2d2f31c46a44bbe966970c7"><code>5108f6c</code></a> feat: Add standalone installers URLs for <code>curl | bash</code> (<a href="https://redirect.github.com/vercel/turborepo/issues/14325">#14325</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/a46f82a2742ef0f8e1b5f9acebfbe2544c34c528"><code>a46f82a</code></a> chore: Release Turborepo 2.11.5-canary.4 (<a href="https://redirect.github.com/vercel/turborepo/issues/14324">#14324</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/8427e6e5dd7efc7afdf5a332502551fc8f2eabc8"><code>8427e6e</code></a> fix: Run standalone archive job on manual releases (<a href="https://redirect.github.com/vercel/turborepo/issues/14323">#14323</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/7f57aa38406027a30a77d46489ebbdf9dd3ef0e5"><code>7f57aa3</code></a> feat: Publish versioned standalone turbo archives (<a href="https://redirect.github.com/vercel/turborepo/issues/14322">#14322</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/d6b852c53c8473ec88081e826b357feb35938e5e"><code>d6b852c</code></a> docs: Update Turborepo schema URL example (<a href="https://redirect.github.com/vercel/turborepo/issues/14321">#14321</a>)</li> <li><a href="https://github.com/vercel/turborepo/commit/c76ac66c4447bfe35301bee0a002d3c60e163342"><code>c76ac66</code></a> chore: Release Turborepo 2.11.5-canary.3 (<a href="https://redirect.github.com/vercel/turborepo/issues/14320">#14320</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vercel/turborepo/compare/v2.10.12...v2.11.5">compare view</a></li> </ul> </details> <br /> Updates `@eslint/eslintrc` from 3.3.6 to 3.3.7 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/eslint/eslintrc/releases">@eslint/eslintrc's releases</a>.</em></p> <blockquote> <h2>eslintrc: v3.3.7</h2> <h2><a href="https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7">3.3.7</a> (2026-09-01)</h2> <h3>Bug Fixes</h3> <ul> <li>Bump js-yaml to 4.3.1 (<a href="https://redirect.github.com/eslint/eslintrc/issues/239">#239</a>) (<a href="https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9">f27e7c9</a>)</li> <li>update js-yaml to 4.3.2 to address security vulnerability (<a href="https://redirect.github.com/eslint/eslintrc/issues/243">#243</a>) (<a href="https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f">bb0d97a</a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/eslint/eslintrc/blob/main/CHANGELOG.md">@eslint/eslintrc's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7">3.3.7</a> (2026-09-01)</h2> <h3>Bug Fixes</h3> <ul> <li>Bump js-yaml to 4.3.1 (<a href="https://redirect.github.com/eslint/eslintrc/issues/239">#239</a>) (<a href="https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9">f27e7c9</a>)</li> <li>update js-yaml to 4.3.2 to address security vulnerability (<a href="https://redirect.github.com/eslint/eslintrc/issues/243">#243</a>) (<a href="https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f">bb0d97a</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/eslint/eslintrc/commit/7943fa6dd55b236a539f658b88c763a4f9fbb38d"><code>7943fa6</code></a> chore: release 3.3.7 🚀 (<a href="https://redirect.github.com/eslint/eslintrc/issues/240">#240</a>)</li> <li><a href="https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f"><code>bb0d97a</code></a> fix: update js-yaml to 4.3.2 to address security vulnerability (<a href="https://redirect.github.com/eslint/eslintrc/issues/243">#243</a>)</li> <li><a href="https://github.com/eslint/eslintrc/commit/5b4abc9c74dd92b9eb782ca81d559a88906509e9"><code>5b4abc9</code></a> docs: Update README sponsors</li> <li><a href="https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9"><code>f27e7c9</code></a> fix: Bump js-yaml to 4.3.1 (<a href="https://redirect.github.com/eslint/eslintrc/issues/239">#239</a>)</li> <li><a href="https://github.com/eslint/eslintrc/commit/b75e1d2425deebfd1ec7f952dda7d0c4f4d65d5c"><code>b75e1d2</code></a> docs: Update README sponsors</li> <li><a href="https://github.com/eslint/eslintrc/commit/302c13310e148268f990df3edbfd10dab44f2678"><code>302c133</code></a> docs: Update README sponsors</li> <li><a href="https://github.com/eslint/eslintrc/commit/e62e7661b0d9063e42a37af5551bbcb1897e188d"><code>e62e766</code></a> docs: Update README sponsors</li> <li><a href="https://github.com/eslint/eslintrc/commit/cf27f9fd8f775d94500f2569a5bfb6a7de9cdb33"><code>cf27f9f</code></a> docs: Update README sponsors</li> <li><a href="https://github.com/eslint/eslintrc/commit/c7f4cdf1ffa86e28b5b8bf09f9e8bc7fadbf87ff"><code>c7f4cdf</code></a> docs: Update README sponsors</li> <li><a href="https://github.com/eslint/eslintrc/commit/3319822ac925e018c47fcafa351b20ea0bf6eeff"><code>3319822</code></a> docs: Update README sponsors</li> <li>Additional commits viewable in <a href="https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7">compare view</a></li> </ul> </details> <br /> Updates `eslint` from 10.9.1 to 10.11.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/eslint/eslint/releases">eslint's releases</a>.</em></p> <blockquote> <h2>v10.11.0</h2> <h2>Features</h2> <ul> <li><a href="https://github.com/eslint/eslint/commit/d136fa4b0d2dd4a9e738ca1c012cc674d1441127"><code>d136fa4</code></a> feat: object-shorthand handle quoted properties for <code>ignoreConstructors</code> (<a href="https://redirect.github.com/eslint/eslint/issues/21271">#21271</a>) (Pavel)</li> <li><a href="https://github.com/eslint/eslint/commit/397b3b8134b8ce1a61cbf414d4c29c945ba25690"><code>397b3b8</code></a> feat: report unsafe labeled <code>continue</code> in <code>no-unsafe-finally</code> rule (<a href="https://redirect.github.com/eslint/eslint/issues/21316">#21316</a>) (electrohyun)</li> <li><a href="https://github.com/eslint/eslint/commit/d3dd47f42e4cb5f9da27e3a2e741aa21e02ea1a4"><code>d3dd47f</code></a> feat: only exempt <code>new-cap</code> built-ins that reference the global (<a href="https://redirect.github.com/eslint/eslint/issues/21290">#21290</a>) (sethamus)</li> </ul> <h2>Bug Fixes</h2> <ul> <li><a href="https://github.com/eslint/eslint/commit/22b09f54f67a9512d4cea39ddbab9b6973d5c476"><code>22b09f5</code></a> fix: ignore <code>__proto__</code> properties in <code>prefer-object-spread</code> (<a href="https://redirect.github.com/eslint/eslint/issues/21311">#21311</a>) (xbinaryx)</li> <li><a href="https://github.com/eslint/eslint/commit/b684bb1cd7e6be03ad1b7a951baead936d9c2166"><code>b684bb1</code></a> fix: make TimePass.parse optional in types and docs (<a href="https://redirect.github.com/eslint/eslint/issues/21313">#21313</a>) (ntnyq)</li> <li><a href="https://github.com/eslint/eslint/commit/26d11bce3e0e21f223613d4bb4be3423839b229e"><code>26d11bc</code></a> fix: don't report <code>__proto__</code> properties in <code>object-shorthand</code> (<a href="https://redirect.github.com/eslint/eslint/issues/21310">#21310</a>) (xbinaryx)</li> </ul> <h2>Documentation</h2> <ul> <li><a href="https://github.com/eslint/eslint/commit/9ecfdc5319f83580cf3b81beab7e936015fef2fa"><code>9ecfdc5</code></a> docs: note that --cache can serve stale results for cross-file rules (<a href="https://redirect.github.com/eslint/eslint/issues/21312">#21312</a>) (bytedoe)</li> <li><a href="https://github.com/eslint/eslint/commit/6c789ff39bc5420e94e8dafeb328bf2b7e3d35ab"><code>6c789ff</code></a> docs: Update README (GitHub Actions Bot)</li> <li><a href="https://github.com/eslint/eslint/commit/5997825635dc9c4e81434894607ef2e3887e0ea3"><code>5997825</code></a> docs: clarify preserve-caught-error known limitation (<a href="https://redirect.github.com/eslint/eslint/issues/21294">#21294</a>) (Akinyemi Toluwalase)</li> </ul> <h2>Chores</h2> <ul> <li><a href="https://github.com/eslint/eslint/commit/520dd77a35922fb537e2dbfb3c839d047acbdd68"><code>520dd77</code></a> perf: Implement fast paths in critical areas (<a href="https://redirect.github.com/eslint/eslint/issues/21210">#21210</a>) (Nicholas C. Zakas)</li> <li><a href="https://github.com/eslint/eslint/commit/92086c87e042413a3d0363d8fc3fbb11db98d06a"><code>92086c8</code></a> test: update <code>EMFILE</code> error generation for Node.js 26.9.0 compatibility (<a href="https://redirect.github.com/eslint/eslint/issues/21330">#21330</a>) (Francesco Trotta)</li> <li><a href="https://github.com/eslint/eslint/commit/9ac7eb60525ec768c2fdc6699e5a292aa913ce9e"><code>9ac7eb6</code></a> chore: update github/codeql-action action to v4.38.0 (<a href="https://redirect.github.com/eslint/eslint/issues/21331">#21331</a>) (renovate[bot])</li> <li><a href="https://github.com/eslint/eslint/commit/24310e3a0e22b3c086ca402f88448676f2e1cfcd"><code>24310e3</code></a> chore: update ecosystem plugins (<a href="https://redirect.github.com/eslint/eslint/issues/21324">#21324</a>) (ESLint Bot)</li> <li><a href="https://github.com/eslint/eslint/commit/45ad79e54a39b54b4ce8eb47e612bd2f72a7a651"><code>45ad79e</code></a> ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (<a href="https://redirect.github.com/eslint/eslint/issues/21318">#21318</a>) (dependabot[bot])</li> <li><a href="https://github.com/eslint/eslint/commit/ac74e37322ebf122ada676f153dc55c81f3caab0"><code>ac74e37</code></a> chore: Add AGENTS.md with AI disclosure requirements (<a href="https://redirect.github.com/eslint/eslint/issues/21221">#21221</a>) (Nicholas C. Zakas)</li> <li><a href="https://github.com/eslint/eslint/commit/c8326608e710e670beaf982501aed80ea104919a"><code>c832660</code></a> chore: Upgrade Stylelint to the latest version in docs (<a href="https://redirect.github.com/eslint/eslint/issues/21245">#21245</a>) (Jung Hyeon Jun)</li> <li><a href="https://github.com/eslint/eslint/commit/f9f88fcccd965fdc162b89c4615dd4018e3cabdf"><code>f9f88fc</code></a> chore: update ecosystem plugins (<a href="https://redirect.github.com/eslint/eslint/issues/21308">#21308</a>) (ESLint Bot)</li> <li><a href="https://github.com/eslint/eslint/commit/fc81076a5b8145360654d81cbc130cf7d25dca77"><code>fc81076</code></a> ci: add more types integration tests (<a href="https://redirect.github.com/eslint/eslint/issues/20395">#20395</a>) (Nitin Kumar)</li> </ul> <h2>v10.10.0</h2> <h2>Features</h2> <ul> <li><a href="https://github.com/eslint/eslint/commit/264b4346d1963701df0c398b4aeb2f6e8b2af93e"><code>264b434</code></a> feat: add <code>d</code> and <code>v</code> flags to <code>no-unexpected-multiline</code> (<a href="https://redirect.github.com/eslint/eslint/issues/21305">#21305</a>) (Gihyeon Jeong / 정기현)</li> <li><a href="https://github.com/eslint/eslint/commit/c6cc6c592f30901345d94ef75e0d42c1894fae6c"><code>c6cc6c5</code></a> feat: check <code>Object.prototype</code> property names in <code>new-cap</code> (<a href="https://redirect.github.com/eslint/eslint/issues/21269">#21269</a>) (crimsonjay0)</li> <li><a href="https://github.com/eslint/eslint/commit/5661fa65fde9fd4c14f0b730e3cee6a42fc657c1"><code>5661fa6</code></a> feat: no-extra-bind false negatives with class fields and static blocks (<a href="https://redirect.github.com/eslint/eslint/issues/21260">#21260</a>) (synthex-byte)</li> </ul> <h2>Bug Fixes</h2> <ul> <li><a href="https://github.com/eslint/eslint/commit/bb47dc6da2399a8f76c0c0c3273e6bc314c480e5"><code>bb47dc6</code></a> fix: update dependency file-entry-cache to v11 (<a href="https://redirect.github.com/eslint/eslint/issues/20801">#20801</a>) (Milos Djermanovic)</li> <li><a href="https://github.com/eslint/eslint/commit/427ac0a014066c36aa57fa8fa9af20fd9fb591e1"><code>427ac0a</code></a> fix: use format strings in debug calls (<a href="https://redirect.github.com/eslint/eslint/issues/21247">#21247</a>) (Francesco Trotta)</li> <li><a href="https://github.com/eslint/eslint/commit/9d8153223dbf47b9aecdc1474202aaee4845f146"><code>9d81532</code></a> fix: support <code>__proto__</code> in <code>/* exported */</code> comments (<a href="https://redirect.github.com/eslint/eslint/issues/21261">#21261</a>) (sethamus)</li> <li><a href="https://github.com/eslint/eslint/commit/87e0a082438264ad90b87fd74165ab4fd90f63ef"><code>87e0a08</code></a> fix: prefer-object-has-own autofix breaks when Object is shadowed (<a href="https://redirect.github.com/eslint/eslint/issues/21282">#21282</a>) (김채영)</li> <li><a href="https://github.com/eslint/eslint/commit/8e2cb142217f2efee1d10dcc02bfb75145ae775d"><code>8e2cb14</code></a> fix: <code>new-cap</code> false positive for <code>UTC</code> calls with <code>properties: false</code> (<a href="https://redirect.github.com/eslint/eslint/issues/21275">#21275</a>) (Pixel)</li> <li><a href="https://github.com/eslint/eslint/commit/9f4a364ab0ade048dfce1f37792b1d461d866e55"><code>9f4a364</code></a> fix: Ignore static imports in no-unreachable (<a href="https://redirect.github.com/eslint/eslint/issues/21276">#21276</a>) (Taha Kotil)</li> </ul> <h2>Documentation</h2> <ul> <li><a href="https://github.com/eslint/eslint/commit/2417cad57d7d1bc4cf3ecf0f0575cfb10ff2011c"><code>2417cad</code></a> docs: Update README (GitHub Actions Bot)</li> <li><a href="https://github.com/eslint/eslint/commit/9cecb8a0a2348070abf72321965d41919c7cc626"><code>9cecb8a</code></a> docs: document <code>\c</code> control letter escapes in no-control-regex (<a href="https://redirect.github.com/eslint/eslint/issues/21286">#21286</a>) (한국)</li> <li><a href="https://github.com/eslint/eslint/commit/8724829f69f8ed80c876e3a5a017da199ce78739"><code>8724829</code></a> docs: update compat table links (<a href="https://redirect.github.com/eslint/eslint/issues/21263">#21263</a>) (fnx)</li> <li><a href="https://github.com/eslint/eslint/commit/5634542be580750ffb1a5766470f9e9c72719696"><code>5634542</code></a> docs: Clarify eqeqeq suggestion behavior (<a href="https://redirect.github.com/eslint/eslint/issues/21256">#21256</a>) (Müslüm Yılmaz)</li> </ul> <h2>Chores</h2> <ul> <li><a href="https://github.com/eslint/eslint/commit/b3d876b46083d67899eb1d9613118c1c583632a2"><code>b3d876b</code></a> chore: disable npm audit in ecosystem tests (<a href="https://redirect.github.com/eslint/eslint/issues/21306">#21306</a>) (Francesco Trotta)</li> <li><a href="https://github.com/eslint/eslint/commit/1696682791661c13167eb905da2f38d1b8f4a3bf"><code>1696682</code></a> ci: restore EMFILE test on Node.js 26 (<a href="https://redirect.github.com/eslint/eslint/issues/21297">#21297</a>) (Marry (Subin Yang))</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/eslint/eslint/commit/3c0b7c6e1fe2dec778b97a996018126f22d437ae"><code>3c0b7c6</code></a> 10.11.0</li> <li><a href="https://github.com/eslint/eslint/commit/321f0a70dd908ed461b11142e17fbdc0c0f1f198"><code>321f0a7</code></a> Build: changelog update for 10.11.0</li> <li><a href="https://github.com/eslint/eslint/commit/520dd77a35922fb537e2dbfb3c839d047acbdd68"><code>520dd77</code></a> perf: Implement fast paths in critical areas (<a href="https://redirect.github.com/eslint/eslint/issues/21210">#21210</a>)</li> <li><a href="https://github.com/eslint/eslint/commit/9ecfdc5319f83580cf3b81beab7e936015fef2fa"><code>9ecfdc5</code></a> docs: note that --cache can serve stale results for cross-file rules (<a href="https://redirect.github.com/eslint/eslint/issues/21312">#21312</a>)</li> <li><a href="https://github.com/eslint/eslint/commit/92086c87e042413a3d0363d8fc3fbb11db98d06a"><code>92086c8</code></a> test: update <code>EMFILE</code> error generation for Node.js 26.9.0 compatibility (<a href="https://redirect.github.com/eslint/eslint/issues/21330">#21330</a>)</li> <li><a href="https://github.com/eslint/eslint/commit/9ac7eb60525ec768c2fdc6699e5a292aa913ce9e"><code>9ac7eb6</code></a> chore: update github/codeql-action action to v4.38.0 (<a href="https://redirect.github.com/eslint/eslint/issues/21331">#21331</a>)</li> <li><a href="https://github.com/eslint/eslint/commit/22b09f54f67a9512d4cea39ddbab9b6973d5c476"><code>22b09f5</code></a> fix: ignore <code>__proto__</code> properties in <code>prefer-object-spread</code> (<a href="https://redirect.github.com/eslint/eslint/issues/21311">#21311</a>)</li> <li><a href="https://github.com/eslint/eslint/commit/24310e3a0e22b3c086ca402f88448676f2e1cfcd"><code>24310e3</code></a> chore: update ecosystem plugins (<a href="https://redirect.github.com/eslint/eslint/issues/21324">#21324</a>)</li> <li><a href="https://github.com/eslint/eslint/commit/d136fa4b0d2dd4a9e738ca1c012cc674d1441127"><code>d136fa4</code></a> feat: object-shorthand handle quoted properties for <code>ignoreConstructors</code> (<a href="https://redirect.github.com/eslint/eslint/issues/21">#21</a>...</li> <li><a href="https://github.com/eslint/eslint/commit/45ad79e54a39b54b4ce8eb47e612bd2f72a7a651"><code>45ad79e</code></a> ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (<a href="https://redirect.github.com/eslint/eslint/issues/21318">#21318</a>)</li> <li>Additional commits viewable in <a href="https://github.com/eslint/eslint/compare/v10.9.1...v10.11.0">compare view</a></li> </ul> </details> <br /> Updates `@typescript-eslint/eslint-plugin` from 8.68.0 to 8.70.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/typescript-eslint/typescript-eslint/releases">@typescript-eslint/eslint-plugin's releases</a>.</em></p> <blockquote> <h2>v8.70.1</h2> <h2>8.70.1 (2026-09-21)</h2> <h3>🩹 Fixes</h3> <ul> <li><strong>ast-spec:</strong> narrow import attribute keys to identifiers and strings (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12879">#12879</a>)</li> <li><strong>eslint-plugin:</strong> [no-useless-default-assignment] avoid false positives on tuples with a rest element (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12768">#12768</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12637">#12637</a>)</li> <li><strong>eslint-plugin:</strong> [no-explicit-any] use unknown[] for bare any rest parameters (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12818">#12818</a>)</li> <li><strong>eslint-plugin:</strong> [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12854">#12854</a>)</li> <li><strong>eslint-plugin:</strong> [no-misused-spread] omit WeakMap spread suggestions (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12850">#12850</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12869">#12869</a>)</li> <li><strong>eslint-plugin:</strong> [no-meaningless-void-operator] allow void on assignment expressions (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12873">#12873</a>)</li> <li><strong>eslint-plugin:</strong> [await-thenable] prevent autofix from breaking code when removing <code>await</code> (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12716">#12716</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-parameter-property-assignment] account for parameter reassignment (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12880">#12880</a>)</li> <li><strong>eslint-plugin:</strong> [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12845">#12845</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12747">#12747</a>)</li> <li><strong>eslint-plugin:</strong> [no-useless-default-assignment] convert the fixer to a suggestion fixer (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12826">#12826</a>)</li> <li><strong>eslint-plugin:</strong> [no-misused-promises] handle multiple Promise constituents (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12904">#12904</a>)</li> <li><strong>rule-tester:</strong> test the final autofix output instead of the first pass (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12867">#12867</a>)</li> <li><strong>scope-manager:</strong> merge implicit global definitions (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12809">#12809</a>)</li> <li><strong>type-utils:</strong> match package specifiers on whole path components (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12838">#12838</a>)</li> <li><strong>typescript-estree:</strong> resolve symlinked paths when matching files to projects (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12725">#12725</a>)</li> <li><strong>typescript-estree:</strong> add missing <code><</code> token opening type arguments (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12821">#12821</a>)</li> <li><strong>typescript-estree:</strong> require string literal import attribute values (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12894">#12894</a>)</li> <li><strong>website:</strong> prevent playground from breaking down after opening link with the .js file type (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12777">#12777</a>)</li> </ul> <h3>❤️ Thank You</h3> <ul> <li>Amin <a href="https://github.com/amiin-dev"><code>@amiin-dev</code></a></li> <li>Brad Zacher <a href="https://github.com/bradzacher"><code>@bradzacher</code></a></li> <li>Cameron</li> <li>Diptajoy Mistry <a href="https://github.com/diptomistry"><code>@diptomistry</code></a></li> <li>Evyatar Daud <a href="https://github.com/StyleShit"><code>@StyleShit</code></a></li> <li>Grit <a href="https://github.com/Grit03"><code>@Grit03</code></a></li> <li>Hugo <a href="https://github.com/hugop95"><code>@hugop95</code></a></li> <li>Josh Goldberg ✨</li> <li>Michael Naumov <a href="https://github.com/mnaoumov"><code>@mnaoumov</code></a></li> <li>Mikhail Baev <a href="https://github.com/baevm"><code>@baevm</code></a></li> <li>Om Rawat</li> <li>overlookmotel</li> <li>Sanath <a href="https://github.com/sansynx"><code>@sansynx</code></a></li> <li>Shinji</li> <li>stoicism <a href="https://github.com/stoicism02"><code>@stoicism02</code></a></li> <li>Vinccool96</li> <li>Younsang Na <a href="https://github.com/nayounsang"><code>@nayounsang</code></a></li> <li>김채영 <a href="https://github.com/cchaeyoung"><code>@cchaeyoung</code></a></li> <li>송재욱</li> </ul> <p>See <a href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.1">GitHub Releases</a> for more information.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md">@typescript-eslint/eslint-plugin's changelog</a>.</em></p> <blockquote> <h2>8.70.1 (2026-09-21)</h2> <h3>🩹 Fixes</h3> <ul> <li><strong>eslint-plugin:</strong> [no-misused-promises] handle multiple Promise constituents (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12904">#12904</a>)</li> <li><strong>eslint-plugin:</strong> [no-useless-default-assignment] convert the fixer to a suggestion fixer (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12826">#12826</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12747">#12747</a>)</li> <li><strong>eslint-plugin:</strong> [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12845">#12845</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-parameter-property-assignment] account for parameter reassignment (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12880">#12880</a>)</li> <li><strong>eslint-plugin:</strong> [await-thenable] prevent autofix from breaking code when removing <code>await</code> (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12716">#12716</a>)</li> <li><strong>eslint-plugin:</strong> [no-meaningless-void-operator] allow void on assignment expressions (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12873">#12873</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12869">#12869</a>)</li> <li><strong>eslint-plugin:</strong> [no-misused-spread] omit WeakMap spread suggestions (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12850">#12850</a>)</li> <li><strong>eslint-plugin:</strong> [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12854">#12854</a>)</li> <li><strong>eslint-plugin:</strong> [no-explicit-any] use unknown[] for bare any rest parameters (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12818">#12818</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12637">#12637</a>)</li> <li><strong>eslint-plugin:</strong> [no-useless-default-assignment] avoid false positives on tuples with a rest element (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12768">#12768</a>)</li> </ul> <h3>❤️ Thank You</h3> <ul> <li>Brad Zacher <a href="https://github.com/bradzacher"><code>@bradzacher</code></a></li> <li>Diptajoy Mistry <a href="https://github.com/diptomistry"><code>@diptomistry</code></a></li> <li>Grit <a href="https://github.com/Grit03"><code>@Grit03</code></a></li> <li>Hugo <a href="https://github.com/hugop95"><code>@hugop95</code></a></li> <li>Michael Naumov <a href="https://github.com/mnaoumov"><code>@mnaoumov</code></a></li> <li>Mikhail Baev <a href="https://github.com/baevm"><code>@baevm</code></a></li> <li>Om Rawat</li> <li>Sanath <a href="https://github.com/sansynx"><code>@sansynx</code></a></li> <li>Shinji</li> <li>Vinccool96</li> <li>김채영 <a href="https://github.com/cchaeyoung"><code>@cchaeyoung</code></a></li> <li>송재욱</li> </ul> <p>See <a href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.1">GitHub Releases</a> for more information.</p> <p>You can read about our <a href="https://typescript-eslint.io/users/versioning">versioning strategy</a> and <a href="https://typescript-eslint.io/users/releases">releases</a> on our website.</p> <h2>8.70.0 (2026-09-07)</h2> <h3>🚀 Features</h3> <ul> <li><strong>eslint-plugin:</strong> [no-generated-empty-object-type] add rule (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12730">#12730</a>)</li> </ul> <h3>🩹 Fixes</h3> <ul> <li><strong>eslint-plugin:</strong> [no-deprecated] report deprecated imported values used in object shorthand properties (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780">#12780</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-condition] no false positive on RHS of a nested logical expression (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12728">#12728</a>)</li> <li><strong>eslint-plugin:</strong> [member-ordering] don't report fields that read fields declared before them (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12729">#12729</a>)</li> </ul> <h3>❤️ Thank You</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/23d38ceeb8fb1237f55cb62fc2b54419e1fa1ed7"><code>23d38ce</code></a> chore(release): publish 8.70.1</li> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/9d82e4b1d9011da31d62d14387bb5a539853fafa"><code>9d82e4b</code></a> chore: expand eslint-plugin rules test files glob (<a href="https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin/issues/12878">#12878</a>)</li> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/f7482f636b89b8eab966b4191ce4a53a3f4b4d9c"><code>f7482f6</code></a> fix(eslint-plugin): [no-misused-promises] handle multiple Promise constituent...</li> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/267304477e04538614fe72ad71e7e13082eb7a90"><code>2673044</code></a> docs(eslint-plugin): [prefer-promise-reject-errors] add option sections and e...</li> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/8f141a2ba63d539465eb4e4604f7d79f6f50ce14"><code>8f141a2</code></a> fix(eslint-plugin): [no-useless-default-assignment] convert the fixer to a su...</li> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/479cd85ff82b81dbec9989621681257ebc317a69"><code>479cd85</code></a> chore: enable assertion option <code>requireData</code> for all rule tests (<a href="https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin/issues/12816">#12816</a>)</li> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/f3c190c5b5cfa9edaba15fa3f944a76a7364b3ed"><code>f3c190c</code></a> fix(eslint-plugin): [no-unnecessary-condition] handle union-keyed index acces...</li> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/b1993dfd3c45b2c2d83058627499f1dfec5d6d2c"><code>b1993df</code></a> fix(eslint-plugin): [unbound-method] treat Intl.Collator.prototype.compare as...</li> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/da394bc9c21afe97f456040da723d2c558f99658"><code>da394bc</code></a> fix(eslint-plugin): [no-unnecessary-parameter-property-assignment] account fo...</li> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/4a742ff890b7cca8cbf79e78a9a3b345913094c6"><code>4a742ff</code></a> fix(eslint-plugin): [await-thenable] prevent autofix from breaking code when ...</li> <li>Additional commits viewable in <a href="https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/eslint-plugin">compare view</a></li> </ul> </details> <br /> Updates `@typescript-eslint/parser` from 8.68.0 to 8.70.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/typescript-eslint/typescript-eslint/releases">@typescript-eslint/parser's releases</a>.</em></p> <blockquote> <h2>v8.70.1</h2> <h2>8.70.1 (2026-09-21)</h2> <h3>🩹 Fixes</h3> <ul> <li><strong>ast-spec:</strong> narrow import attribute keys to identifiers and strings (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12879">#12879</a>)</li> <li><strong>eslint-plugin:</strong> [no-useless-default-assignment] avoid false positives on tuples with a rest element (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12768">#12768</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-type-parameters] handle type precedence in the suggestion fixer (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12637">#12637</a>)</li> <li><strong>eslint-plugin:</strong> [no-explicit-any] use unknown[] for bare any rest parameters (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12818">#12818</a>)</li> <li><strong>eslint-plugin:</strong> [no-generated-empty-object-type] don't report a mapped type whose keys are not resolved yet (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12854">#12854</a>)</li> <li><strong>eslint-plugin:</strong> [no-misused-spread] omit WeakMap spread suggestions (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12850">#12850</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-type-assertion] false positive for empty object asserted to a type alias of Record (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12869">#12869</a>)</li> <li><strong>eslint-plugin:</strong> [no-meaningless-void-operator] allow void on assignment expressions (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12873">#12873</a>)</li> <li><strong>eslint-plugin:</strong> [await-thenable] prevent autofix from breaking code when removing <code>await</code> (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12716">#12716</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-parameter-property-assignment] account for parameter reassignment (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12880">#12880</a>)</li> <li><strong>eslint-plugin:</strong> [unbound-method] treat Intl.Collator.prototype.compare as spec-bound (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12845">#12845</a>)</li> <li><strong>eslint-plugin:</strong> [no-unnecessary-condition] handle union-keyed index access on the left-hand side of nullish assignment (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12747">#12747</a>)</li> <li><strong>eslint-plugin:</strong> [no-useless-default-assignment] convert the fixer to a suggestion fixer (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12826">#12826</a>)</li> <li><strong>eslint-plugin:</strong> [no-misused-promises] handle multiple Promise constituents (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12904">#12904</a>)</li> <li><strong>rule-tester:</strong> test the final autofix output instead of the first pass (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12867">#12867</a>)</li> <li><strong>scope-manager:</strong> merge implicit global definitions (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12809">#12809</a>)</li> <li><strong>type-utils:</strong> match package specifiers on whole path components (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12838">#12838</a>)</li> <li><strong>typescript-estree:</strong> resolve symlinked paths when matching files to projects (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12725">#12725</a>)</li> <li><strong>typescript-estree:</strong> add missing <code><</code> token opening type arguments (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12821">#12821</a>)</li> <li><strong>typescript-estree:</strong> require string literal import attribute values (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12894">#12894</a>)</li> <li><strong>website:</strong> prevent playground from breaking down after opening link with the .js file type (<a href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12777">#12777</a>)</li> </ul> <h3>❤️ Thank You</h3> <ul> <li>Amin <a href="https://github.com/amiin-dev"><code>@amiin-dev</code></a></li> <li>Brad Zacher <a href="https://github.com/bradzacher"><code>@bradzacher</code></a></li> <li>Cameron</li> <li>Diptajoy Mistry <a href="https://github.com/diptomistry"><code>@diptomistry</code></a></li> <li>Evyatar Daud <a href="https://github.com/StyleShit"><code>@StyleShit</code></a></li> <li>Grit <a href="https://github.com/Grit03"><code>@Grit03</code></a></li> <li>Hugo <a href="https://github.com/hugop95"><code>@hugop95</code></a></li> <li>Josh Goldberg ✨</li> <li>Michael Naumov <a href="https://github.com/mnaoumov"><code>@mnaoumov</code></a></li> <li>Mikhail Baev <a href="https://github.com/baevm"><code>@baevm</code></a></li> <li>Om Rawat</li> <li>overlookmotel</li> <li>Sanath <a href="https://github.com/sansynx"><code>@sansynx</code></a></li> <li>Shinji</li> <li>stoicism <a href="https://github.com/stoicism02"><code>@stoicism02</code></a></li> <li>Vinccool96</li> <li>Younsang Na <a href="https://github.com/nayounsang"><code>@nayounsang</code></a></li> <li>김채영 <a href="https://github.com/cchaeyoung"><code>@cchaeyoung</code></a></li> <li>송재욱</li> </ul> <p>See <a href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.1">GitHub Releases</a> for more information.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md">@typescript-eslint/parser's changelog</a>.</em></p> <blockquote> <h2>8.70.1 (2026-09-21)</h2> <p>This was a version bump only for parser to align it with other projects, there were no code changes.</p> <p>See <a href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.1">GitHub Releases</a> for more information.</p> <p>You can read about our <a href="https://typescript-eslint.io/users/versioning">versioning strategy</a> and <a href="https://typescript-eslint.io/users/releases">releases</a> on our website.</p> <h2>8.70.0 (2026-09-07)</h2> <p>This was a version bump only for parser to align it with other projects, there were no code changes.</p> <p>See <a href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0">GitHub Releases</a> for more information.</p> <p>You can read about our <a href="https://typescript-eslint.io/users/versioning">versioning strategy</a> and <a href="https://typescript-eslint.io/users/releases">releases</a> on our website.</p> <h2>8.69.0 (2026-08-31)</h2> <p>This was a version bump only for parser to align it with other projects, there were no code changes.</p> <p>See <a href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.69.0">GitHub Releases</a> for more information.</p> <p>You can read about our <a href="https://typescript-eslint.io/users/versioning">versioning strategy</a> and <a href="https://typescript-eslint.io/users/releases">releases</a> on our website.</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/23d38ceeb8fb1237f55cb62fc2b54419e1fa1ed7"><code>23d38ce</code></a> chore(release): publish 8.70.1</li> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/7ee76085c22e923c0036b8e0733a3ca7dfd82b60"><code>7ee7608</code></a> chore(release): publish 8.70.0</li> <li><a href="https://github.com/typescript-eslint/typescript-eslint/commit/9a6e546823e5d8f2dc015df2aa66c0230615e209"><code>9a6e546</code></a> chore(release): publish 8.69.0</li> <li>See full diff in <a href="https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/parser">compare view</a></li> </ul> </details> <br /> Updates `prettier` from 3.9.6 to 3.9.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/prettier/prettier/releases">prettier's releases</a>.</em></p> <blockquote> <h2>3.9.9</h2> <ul> <li>Markdown: Fix text with <code>$</code> been incorrectly parsed as math syntax (<a href="https://redirect.github.com/prettier/prettier/pull/20140">#20140</a> by <a href="https://github.com/fisker"><code>@fisker</code></a>)</li> </ul> <p>🔗 <a href="https://github.com/prettier/prettier/blob/3.9.9/CHANGELOG.md#399">Changelog</a></p> <h2>3.9.8</h2> <ul> <li>Markdown: Don't let Liquid objects interrupt paragraphs (<a href="https://redirect.github.com/prettier/prettier/pull/20087">#20087</a> by <a href="https://github.com/seiyab"><code>@seiyab</code></a>)</li> </ul> <p>🔗 <a href="https://github.com/prettier/prettier/blob/3.9.8/CHANGELOG.md#398">Changelog</a></p> <h2>3.9.7</h2> <ul> <li>Support Angular 22.2</li> <li>Fix regressions in v3.9</li> </ul> <p>🔗 <a href="https://github.com/prettier/prettier/blob/3.9.7/CHANGELOG.md#397">Changelog</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md">prettier's changelog</a>.</em></p> <blockquote> <h1>3.9.9</h1> <p><a href="https://github.com/prettier/prettier/compare/3.9.8...3.9.9">diff</a></p> <h4>Markdown: Fix text with <code>$</code> been incorrectly parsed as math syntax (<a href="https://redirect.github.com/prettier/prettier/pull/20140">#20140</a> by <a href="https://github.com/fisker"><code>@fisker</code></a>)</h4> <!-- raw HTML omitted --> <pre lang="md"><code><!-- Input --> **Uses $FOO** from `a.sh` and `b.sh`, plus `$BAR` from `c.sh`, before anything else runs here. <p><!-- Prettier 3.9.8 --> <strong>Uses $FOO</strong> from <code>a.sh</code> and <code>b.sh</code>, plus <code>$BAR</code>from<code>c.sh</code>, before anything else runs here.</p> <p><!-- Prettier 3.9.9 --> <strong>Uses $FOO</strong> from <code>a.sh</code> and <code>b.sh</code>, plus <code>$BAR</code> from <code>c.sh</code>, before anything else runs here. </code></pre></p> <h1>3.9.8</h1> <p><a href="https://github.com/prettier/prettier/compare/3.9.7...3.9.8">diff</a></p> <h4>Markdown: Don't let Liquid objects interrupt paragraphs (<a href="https://redirect.github.com/prettier/prettier/pull/20087">#20087</a> by <a href="https://github.com/seiyab"><code>@seiyab</code></a>)</h4> <!-- raw HTML omitted --> <pre lang="markdown"><code><!-- Input --> If `module` is not a [`WebAssembly.Module`](https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module) object instance, a {{jsxref("TypeError")}} is thrown. <p><!-- Prettier 3.9.7 --> If <code>module</code> is not a <a href="https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module"><code>WebAssembly.Module</code></a> object instance, a</p> <p>{{jsxref("TypeError")}} is thrown.</p> <p><!-- Prettier 3.9.8 --> If <code>module</code> is not a <a href="https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module"><code>WebAssembly.Module</code></a> object instance, a {{jsxref("TypeError")}} is thrown. </code></pre></p> <h1>3.9.7</h1> <p><a href="https://github.com/prettier/prettier/compare/3.9.6...3.9.7">diff</a></p> <h4>Markdown: Prevent indentation drift in list-item code blocks (<a href="https://redirect.github.com/prettier/prettier/pull/19647">#19647</a>, <a href="https://redirect.github.com/prettier/prettier/pull/19990">#19990</a> by <a href="https://github.com/Austin1serb"><code>@Austin1serb</code></a>, <a href="https://github.com/giaBaoJS"><code>@giaBaoJS</code></a>)</h4> <!-- raw HTML omitted --> <pre lang="markdown"><code><!-- Input --> - [x] short first line. </tr></table> </code></pre> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/prettier/prettier/commit/cdd17f2288b28b170a76416c72dac56e3ea5daff"><code>cdd17f2</code></a> Release 3.9.9</li> <li><a href="https://github.com/prettier/prettier/commit/dc7b8968e678f51ea00e2be3fe8c717d114691a3"><code>dc7b896</code></a> Disable <code>singleDollarTextMath</code> in <code>mdast-util-math</code> (<a href="https://redirect.github.com/prettier/prettier/issues/20140">#20140</a>)</li> <li><a href="https://github.com/prettier/prettier/commit/f9be58fb8ec62dd47197ea19a30aac5ad26dfee0"><code>f9be58f</code></a> Git blame ignore 3.9.8</li> <li><a href="https://github.com/prettier/prettier/commit/88470cb79ca3b757dd6b93906d9a992aa1a456c3"><code>88470cb</code></a> Bump Prettier dependency to 3.9.8</li> <li><a href="https://github.com/prettier/prettier/commit/9559cab39eb5082c99a27e8829760c055adba841"><code>9559cab</code></a> Clean changelog_unreleased</li> <li><a href="https://github.com/prettier/prettier/commit/4fc8ee87465de8d54780273a6996d74e8e9da827"><code>4fc8ee8</code></a> Update dependents count</li> <li><a href="https://github.com/prettier/prettier/commit/4f2ab6765d7cb29408a2abdac75d023d64d44107"><code>4f2ab67</code></a> Release 3.9.8</li> <li><a href="https://github.com/prettier/prettier/commit/3d82af8b15b8e89de20dd05cc65f66ab6d4ce8b0"><code>3d82af8</code></a> Update Regex related dependencies (<a href="https://redirect.github.com/prettier/prettier/issues/20082">#20082</a>)</li> <li><a href="https://github.com/prettier/prettier/commit/5ec8db1745c2bdcca3706ab8cfbbe5c11fc457c1"><code>5ec8db1</code></a> [3.9.x] Markdown: Don't let Liquid objects interrupt paragraphs (<a href="https://redirect.github.com/prettier/prettier/issues/20087">#20087</a>)</li> <li><a href="https://github.com/prettier/prettier/commit/5b142ed2bce0095161bf6865af30df2d5ba99466"><code>5b142ed</code></a> Release Release <code>@prettier/plugin-hermes</code><a href="https://github.com/0"><code>@0</code></a>.2.3, <code>@prettier/plugin-oxc</code><a href="https://github.com/0"><code>@0</code></a>.2.3, an...</li> <li>Additional commits viewable in <a href="https://github.com/prettier/prettier/compare/3.9.6...3.9.9">compare view</a></li> </ul> </details> <br /> Updates `@langchain/core` from 1.2.9 to 1.2.13 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langchainjs/releases">@langchain/core's releases</a>.</em></p> <blockquote> <h2><code>@langchain/core</code><a href="https://github.com/1"><code>@1</code></a>.2.13</h2> <h3>Patch Changes</h3> <ul> <li><a href="https://redirect.github.com/langchain-ai/langchainjs/pull/11714">#11714</a> <a href="https://github.com/langchain-ai/langchainjs/commit/a83dfb14f8e17fcb66dc7a915f0cf8ed7b0dffa1"><code>a83dfb1</code></a> Thanks <a href="https://github.com/ccurme"><code>@ccurme</code></a>! - Abbreviate long tool-call IDs when formatting chat messages as strings, keeping original messages unchanged.</li> </ul> <h2><code>@langchain/core</code><a href="https://github.com/1"><code>@1</code></a>.2.12</h2> <h3>Patch Changes</h3> <ul> <li><a href="https://redirect.github.com/langchain-ai/langchainjs/pull/11675">#11675</a> <a href="https://github.com/langchain-ai/langchainjs/commit/030a726639e0147488bc8c23c063a2e72b004c2e"><code>030a726</code></a> Thanks <a href="https://github.com/hntrl"><code>@hntrl</code></a>! - Preserve structured tool arguments in tracer run inputs.</li> </ul> <h2><code>@langchain/core</code><a href="https://github.com/1"><code>@1</code></a>.2.11</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/langchain-ai/langchainjs/pull/11603">#11603</a> <a href="https://github.com/langchain-ai/langchainjs/commit/fec9cd87b01976014dd549bd2cf7849aee89a566"><code>fec9cd8</code></a> Thanks <a href="https://github.com/thushanth-bengre-langchain"><code>@thushanth-bengre-langchain</code></a>! - fix(core): build streaming <code>llmOutput.tokenUsage</code> from the fully-accumulated chunk instead of whichever individual chunk's <code>usage_metadata</code> arrived last</p> <p>Affects both core streaming paths — <code>.stream()</code>/<code>.streamEvents()</code> (<code>_streamIterator</code>) and <code>.invoke()</code>/<code>.generate()</code> when a streaming-preferring callback is attached (<code>_generateWithCache</code>'s <code>hasStreamingHandler</code> branch). Previously, <code>llmOutput.tokenUsage</code> was overwritten by each chunk in turn, so only the last chunk carrying <code>usage_metadata</code> won — correct for providers that emit one cumulative total on a final chunk, but wrong for providers (e.g. <code>@langchain/google</code>, <code>@langchain/anthropic</code>) that emit <code>usage_metadata</code> as a per-chunk delta across multiple chunks, where the values must be summed.</p> <p>Note for provider authors: this assumes each streamed chunk's <code>usage_metadata</code> is either a per-chunk delta or appears only on a single final chunk. A provider that instead repeats a cumulative total on every chunk will now see it summed (and inflated) in <code>llmOutput.tokenUsage</code>, matching the existing behavior of the correctly-working <code>message.usage_metadata</code> field.</p> <p>Also fixes <code>@langchain/google</code>'s <code>invoke({streaming: true})</code> path (no streaming-preferring callback attached), where <code>llmOutput</code> was never populated at all.</p> </li> <li> <p><a href="https://redirect.github.com/langchain-ai/langchainjs/pull/11590">#11590</a> <a href="https://github.com/langchain-ai/langchainjs/commit/ffebdc2f00f3290d19f85e5afd6a297920ae584c"><code>ffebdc2</code></a> Thanks <a href="https://github.com/thushanth-bengre-langchain"><code>@thushanth-bengre-langchain</code></a>! - Fix OpenAI Responses API replay under Zero Data Retention when a response contains more than one reasoning item, for both v0 and v1. In v0, the default replay path now reuses <code>response_metadata.output</code> directly, preserving every reasoning item's <code>id</code>/<code>encrypted_content</code> in original order. In v1, <code>AIMessage.contentBlocks</code> (<code>outputVersion: "v1"</code>) is fixed the same way. <code>additional_kwargs.reasoning</code> is unchanged.</p> </li> </ul> <h2><code>@langchain/core</code><a href="https://github.com/1"><code>@1</code></a>.2.10</h2> <h3>Patch Changes</h3> <ul> <li><a href="https://redirect.github.com/langchain-ai/langchainjs/pull/10047">#10047</a> <a href="https://github.com/langchain-ai/langchainjs/commit/ff1248fd49dacdb35f5da128278cd777068481d7"><code>ff1248f</code></a> Thanks <a href="https://github.com/afirstenberg"><code>@afirstenberg</code></a>! - fix(core): BaseMessage.text use contentBlocks</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langchainjs/commit/c8d12783ecc31a0816f3a47da1040fbd3c08fdbc"><code>c8d1278</code></a> chore: version packages (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11729">#11729</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/5d509ad4b8a5ed9dd4b83020b4c103ac8a69859c"><code>5d509ad</code></a> fix(openai): send in-memory prompt cache retention as in_memory (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11735">#11735</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/663b9a2076c5b274435c77524ad7730450b34f34"><code>663b9a2</code></a> feat(openai): support explicit prompt caching (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11232">#11232</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/7735b219221d6ae63eb5445fb67d26c18fce9c46"><code>7735b21</code></a> chore(infra): drop held mcp-adapters 2.0 changeset to unblock main releases (...</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/34edee1153f0fa40ba6997c8ff7bd45834ca8ce8"><code>34edee1</code></a> fix(langchain): return failed returnDirect tool calls to the model (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11712">#11712</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/0fcb98b4306a771c940e78d6881d0be9f88507c1"><code>0fcb98b</code></a> fix(textsplitters): use char length for loc.lines with custom lengthFunction ...</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/e4a3d1bd0c6753d4e1739a7f10064f48e6bc49ec"><code>e4a3d1b</code></a> chore: version packages (<a href="https://redirect.github.com/langchain-ai/langchainjs/issues/11683">#11683</a>)</li> <li><a href="https://github.com/langchain-ai/langchainjs/commit/a9ada857f22c4b746801e77... _Description has been truncated_ Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
7c8be00fd6 |
chore(deps): bump the minor-and-patch group in /libs/cli with 5 updates (#9153)
Bumps the minor-and-patch group in /libs/cli with 5 updates: | Package | From | To | | --- | --- | --- | | [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.4.4` | `0.4.5` | | [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` | `3.16.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.9` | | [ty](https://github.com/astral-sh/ty) | `0.0.75` | `0.0.84` | | [hatch](https://github.com/pypa/hatch) | `1.18.0` | `1.18.1` | Updates `langgraph-sdk` from 0.4.4 to 0.4.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langgraph/releases">langgraph-sdk's releases</a>.</em></p> <blockquote> <h2>langgraph-sdk==0.4.5</h2> <p>Changes since sdk==0.4.4</p> <ul> <li>release(sdk-py): 0.4.5 (<a href="https://redirect.github.com/langchain-ai/langgraph/issues/8988">#8988</a>)</li> <li>release(langgraph): 1.2.12 (<a href="https://redirect.github.com/langchain-ai/langgraph/issues/8987">#8987</a>)</li> <li>chore(deps): bump anyio from 4.14.2 to 4.15.1 in /libs/sdk-py (<a href="https://redirect.github.com/langchain-ai/langgraph/issues/8997">#8997</a>)</li> <li>chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/cli (<a href="https://redirect.github.com/langchain-ai/langgraph/issues/8998">#8998</a>)</li> <li>chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/sdk-py (<a href="https://redirect.github.com/langchain-ai/langgraph/issues/8994">#8994</a>)</li> <li>feat(langgraph): add response_schema to interrupt() (<a href="https://redirect.github.com/langchain-ai/langgraph/issues/8886">#8886</a>)</li> <li>chore(deps): bump the minor-and-patch group across 1 directory with 7 updates (<a href="https://redirect.github.com/langchain-ai/langgraph/issues/8779">#8779</a>)</li> <li>chore(deps): bump websockets from 16.0 to 16.1.1 in /libs/sdk-py in the major group (<a href="https://redirect.github.com/langchain-ai/langgraph/issues/8781">#8781</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langgraph/commit/6fb2a93212ceeb432c13148849082af0775318a1"><code>6fb2a93</code></a> langgraph: release 0.4.5 (<a href="https://redirect.github.com/langchain-ai/langgraph/issues/4709">#4709</a>)</li> <li><a href="https://github.com/langchain-ai/langgraph/commit/3f8944c1fc560c6b8d700110c7b7764e5c769beb"><code>3f8944c</code></a> checkpoint: release 2.0.26 (<a href="https://redirect.github.com/langchain-ai/langgraph/issues/4708">#4708</a>)</li> <li><a href="https://github.com/langchain-ai/langgraph/commit/e79f3ceedc2508e18b7753d793a90e60ffad0b74"><code>e79f3ce</code></a> Improve how we match cached writes for async imperative tasks (<a href="https://redirect.github.com/langchain-ai/langgraph/issues/4691">#4691</a>)</li> <li><a href="https://github.com/langchain-ai/langgraph/commit/3bdb7d09beae7e1fcfebe86aa91b18e5a93d2cc1"><code>3bdb7d0</code></a> Lint</li> <li><a href="https://github.com/langchain-ai/langgraph/commit/3acf63a918c6f5f59e9a3a4e2c629314e4f6099a"><code>3acf63a</code></a> Lint</li> <li><a href="https://github.com/langchain-ai/langgraph/commit/f51e5e2bd73f1678353bf7e01b09daf1c67cbd0f"><code>f51e5e2</code></a> Improve how we match cached writes for async imperative tasks</li> <li>See full diff in <a href="https://github.com/langchain-ai/langgraph/compare/0.4.4...0.4.5">compare view</a></li> </ul> </details> <br /> Updates `pytest-mock` from 3.15.1 to 3.16.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/releases">pytest-mock's releases</a>.</em></p> <blockquote> <h2>v3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/604">#604</a>: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/611">#611</a>: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/pull/606">#606</a>: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/547">#547</a>: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/147">#147</a>: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst">pytest-mock's changelog</a>.</em></p> <blockquote> <h2>3.16.0</h2> <p><em>2026-09-27</em></p> <ul> <li><code>[#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604></code>_: Fixed <code>duplicate_iterators=True</code> for async functions spied with <code>mocker.spy</code>.</li> <li><code>[#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611></code>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.</li> <li><code>[#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606></code>_: <code>mocker.resetall(return_value=True, side_effect=True)</code> now also applies to non-callable mocks, such as those returned by <code>mocker.create_autospec(SomeClass, instance=True)</code>. Previously both arguments were silently ignored for them.</li> <li><code>[#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547></code>_: Added <code>SpyType</code> for annotating <code>mocker.spy</code> results.</li> <li>Dropped support for EOL Python 3.9.</li> <li><code>[#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147></code>_: Removed handling of <code>RuntimeError: stop called on unstarted patcher</code>, which can no longer occur in the supported Python versions.</li> <li>Added support for Python 3.15.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/f3b531f93c6d9837edc87ea1a6f4324dc9a2cdf3"><code>f3b531f</code></a> Release 3.16.0</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/71ed67309520be160f3e100368705b58758d237a"><code>71ed673</code></a> Fix duplicate_iterators for async spies (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/604">#604</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/0797e3d303cc5bbe0a3514b0625f7aeb3fa350b0"><code>0797e3d</code></a> Fix async assertion argument introspection (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/611">#611</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/e24c334d573cfbf6989a31f4e3346676d9d31598"><code>e24c334</code></a> docs: import os in the opening usage example (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/612">#612</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/9e7eb7b59cde362c1c8ace2d18ca00fe2d7a1cd1"><code>9e7eb7b</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/613">#613</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/445fd4d3daa8ed4c6d5428a77880da2e03d2f721"><code>445fd4d</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/610">#610</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/a8bd0b147afdf6b4bb1a1a3c3c088f32b0240091"><code>a8bd0b1</code></a> Honour resetall() arguments for non-callable mocks (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/606">#606</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/6559fdfd5b67f096423e604a3a5a7045db2486a0"><code>6559fdf</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/608">#608</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/466d026254c949a8fbba8626b894308827be81cf"><code>466d026</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/605">#605</a>)</li> <li><a href="https://github.com/pytest-dev/pytest-mock/commit/164defebde25bc31d53a2a64943c5c9aac43b57e"><code>164defe</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest-mock/issues/603">#603</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pytest-dev/pytest-mock/compare/v3.15.1...v3.16.0">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.5 to 0.16.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.9</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>Install ruff 0.16.9</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh </code></pre> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.9</h2> <p>Released on 2026-09-24.</p> <h3>Preview features</h3> <ul> <li>[<code>ruff</code>] Avoid false positives for overloaded division (<code>RUF069</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28309">#28309</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-bugbear</code>] Avoid false positives for calls with keyword arguments (<code>B009</code>, <code>B010</code>, <code>B043</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28776">#28776</a>)</li> <li>[<code>flake8-tidy-imports</code>] Allow lazy imports to be used in deferred annotations (<code>TID255</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28767">#28767</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>Update LibCST-based fixes for Python 3.15 (<a href="https://redirect.github.com/astral-sh/ruff/pull/28616">#28616</a>)</li> <li>[<code>flake8-pyi</code>] Mention stubs in the diagnostic message (<code>PYI002</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28542">#28542</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Fix horizontal overflow on the rules documentation page (<a href="https://redirect.github.com/astral-sh/ruff/pull/28699">#28699</a>)</li> <li>Update rules table with category information (<a href="https://redirect.github.com/astral-sh/ruff/pull/28651">#28651</a>)</li> <li>[<code>flake8-annotations</code>] Clarify that <code>ANN401</code> checks return types in addition to arguments (<a href="https://redirect.github.com/astral-sh/ruff/pull/28334">#28334</a>)</li> <li>[<code>flake8-bugbear</code>] Document type-checker interaction (<code>B010</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28509">#28509</a>)</li> <li>[<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27794">#27794</a>)</li> <li>[<code>ruff</code>] Mention related isort settings (<code>RUF022</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28719">#28719</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/qinpei-dev"><code>@qinpei-dev</code></a></li> <li><a href="https://github.com/sanjayrohith"><code>@sanjayrohith</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/webdevsamran"><code>@webdevsamran</code></a></li> <li><a href="https://github.com/zaniebot"><code>@zaniebot</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/spaceone"><code>@spaceone</code></a></li> <li><a href="https://github.com/IbrahimKhan12"><code>@IbrahimKhan12</code></a></li> <li><a href="https://github.com/devtechedge"><code>@devtechedge</code></a></li> <li><a href="https://github.com/GruffElixir"><code>@GruffElixir</code></a></li> </ul> <h2>0.16.8</h2> <p>Released on 2026-09-16.</p> <h3>Bug fixes</h3> <ul> <li>Visit functional <code>TypedDict</code> keyword arguments correctly (<a href="https://redirect.github.com/astral-sh/ruff/pull/28584">#28584</a>)</li> <li>[<code>flake8-simplify</code>] Detect nested <code>async with</code> under sync parent (<code>SIM117</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/27821">#27821</a>)</li> <li>[<code>flake8-simplify</code>] Preserve operand order in <code>SIM109</code> fix (<a href="https://redirect.github.com/astral-sh/ruff/pull/27824">#27824</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/0be08a206f9c3180afd3e93bcc792ed5cb1f4db1"><code>0be08a2</code></a> Bump version to 0.16.9 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28882">#28882</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/b4920b72b354e7c715ab861ae23458874683bb02"><code>b4920b7</code></a> Rename <code>ruff_cli</code> to <code>ruff_command_line</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28881">#28881</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/47c751b95908a4d1f95f9ef8723036aae9da0b18"><code>47c751b</code></a> Update dependency astral-sh/uv to v0.12.18 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28880">#28880</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/8c244e56a1aeac31c26d2371ef26588e0632235c"><code>8c244e5</code></a> [<code>flake8-comprehensions</code>] Document <code>map</code>/generator exception behavior (<code>C417</code>...</li> <li><a href="https://github.com/astral-sh/ruff/commit/5edf5a1d0a84663079e46983216059f06acea87d"><code>5edf5a1</code></a> Use <code>target</code> form in <code>rooster.version_files</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28876">#28876</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/915bb2b4bf9ae7eee47cf55646bbfebae254a23b"><code>915bb2b</code></a> [ty] Prefer existing @ paths over response files in Ruff and ty (<a href="https://redirect.github.com/astral-sh/ruff/issues/28877">#28877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/4710e1aa962b13720cf64aa84eb279c5333896d7"><code>4710e1a</code></a> ci(github): update version number in placeholder of issue template (<a href="https://redirect.github.com/astral-sh/ruff/issues/28871">#28871</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/eedfc62a75bf1ba86d48959b00eea75ae87eadca"><code>eedfc62</code></a> [ty] Propagate outer type context through cast calls (<a href="https://redirect.github.com/astral-sh/ruff/issues/28855">#28855</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ceaa6a00830e1e350b8a23977a1a10ac467920a1"><code>ceaa6a0</code></a> [ty] Contain rendered code within Markdown fences (<a href="https://redirect.github.com/astral-sh/ruff/issues/28869">#28869</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/dba0f30615424b94f94a174bba6ce6cce4bf11ff"><code>dba0f30</code></a> authorize ruff-pre-commit dispatch via OIDC (<a href="https://redirect.github.com/astral-sh/ruff/issues/28867">#28867</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.5...0.16.9">compare view</a></li> </ul> </details> <br /> Updates `ty` from 0.0.75 to 0.0.84 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/releases">ty's releases</a>.</em></p> <blockquote> <h2>0.0.84</h2> <h2>Release Notes</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ty/blob/main/CHANGELOG.md">ty's changelog</a>.</em></p> <blockquote> <h2>0.0.84</h2> <p>Released on 2026-09-24.</p> <p>This release addresses <a href="https://github.com/astral-sh/ty/security/advisories/GHSA-vxvm-j4xq-q7m4">GHSA-vxvm-j4xq-q7m4</a>, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.</p> <h3>Bug fixes</h3> <ul> <li>Fix stale diagnostics from the LSP server after toggling <code>showSyntaxErrors</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28759">#28759</a>)</li> </ul> <h3>LSP server</h3> <ul> <li>Complete string keys from dictionary initializers (<a href="https://redirect.github.com/astral-sh/ruff/pull/28820">#28820</a>)</li> <li>Support LSP requests against closed documents (<a href="https://redirect.github.com/astral-sh/ruff/pull/28595">#28595</a>)</li> <li>Select projects for external files using import search paths (<a href="https://redirect.github.com/astral-sh/ruff/pull/28594">#28594</a>)</li> <li>Use workspace editor settings for external files (<a href="https://redirect.github.com/astral-sh/ruff/pull/28639">#28639</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Avoid repeated subtyping checks for materialized recursive protocols (<a href="https://redirect.github.com/astral-sh/ruff/pull/28774">#28774</a>)</li> <li>Skip reading notebooks when discovering scripts (<a href="https://redirect.github.com/astral-sh/ruff/pull/28781">#28781</a>)</li> </ul> <h3>Core type checking</h3> <ul> <li>Avoid incorrect simplification of <code>TypeIs</code> materializations (<a href="https://redirect.github.com/astral-sh/ruff/pull/28817">#28817</a>)</li> <li>Fix disjointness of generic class types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28787">#28787</a>)</li> <li>Fix staticmethod shadowing through generic receivers and unions (<a href="https://redirect.github.com/astral-sh/ruff/pull/28766">#28766</a>)</li> <li>Infer callable signatures from bounded type variables (<a href="https://redirect.github.com/astral-sh/ruff/pull/28599">#28599</a>)</li> <li>Infer constant membership in inline list and set literals (e.g. <code>"foo" in ["foo"]</code> is now inferred as <code>Literal[True]</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28676">#28676</a>)</li> <li>Infer through optional generic containers in the legacy solver (<a href="https://redirect.github.com/astral-sh/ruff/pull/28791">#28791</a>)</li> <li>Preserve call narrowing during cyclic inference (<a href="https://redirect.github.com/astral-sh/ruff/pull/28708">#28708</a>)</li> <li>Preserve intersections of type guard return types (<a href="https://redirect.github.com/astral-sh/ruff/pull/28796">#28796</a>)</li> <li>Use subtyping for constraint-set implication (<a href="https://redirect.github.com/astral-sh/ruff/pull/28657">#28657</a>)</li> </ul> <h3>Configuration</h3> <ul> <li>Disable <code>invalid-legacy-positional-parameter</code> by default (<a href="https://redirect.github.com/astral-sh/ruff/pull/28834">#28834</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Only consider reachable definitions when determining whether a condition should be exempted from <code>redundant-condition(-strict)</code> due to the condition being defined relative to <code>sys.version_info</code>, <code>sys.platform</code>, <code>os.name</code> or <code>typing.TYPE_CHECKING</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/28788">#28788</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/ibraheemdev"><code>@ibraheemdev</code></a></li> <li><a href="https://github.com/zsol"><code>@zsol</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/lerebear"><code>@lerebear</code></a></li> <li><a href="https://github.com/MichaReiser"><code>@MichaReiser</code></a></li> <li><a href="https://github.com/ewdurbin"><code>@ewdurbin</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ty/commit/8dd9a7f7fa35a18275d82117e6593ba45507065f"><code>8dd9a7f</code></a> Bump version to 0.0.84 (<a href="https://redirect.github.com/astral-sh/ty/issues/4585">#4585</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/d4e4bf90906c7677049bc3a29d1735de7d22052d"><code>d4e4bf9</code></a> publish to astral-sh/versions via OIDC (<a href="https://redirect.github.com/astral-sh/ty/issues/4581">#4581</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/94ce7333abb356b2068dc98d37a68c993da6d09b"><code>94ce733</code></a> use oidc issued token for docs publication (<a href="https://redirect.github.com/astral-sh/ty/issues/4579">#4579</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/901eeaa9cd9ac06f34e85e4f721f76a0dc36e217"><code>901eeaa</code></a> Update prek dependencies (<a href="https://redirect.github.com/astral-sh/ty/issues/4576">#4576</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/09bf0b1b2114a628f3e2296d3d9d28245066c98b"><code>09bf0b1</code></a> Update docker/setup-buildx-action action to v4.3.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4575">#4575</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/89d6ffe529dd44f64adc0d28f80744b7c7ab217f"><code>89d6ffe</code></a> Update astral-sh/setup-uv action to v10.2.0 (<a href="https://redirect.github.com/astral-sh/ty/issues/4574">#4574</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/9c214798cfcc59069e986876564638fadf32d774"><code>9c21479</code></a> Bump version to 0.0.83 (<a href="https://redirect.github.com/astral-sh/ty/issues/4569">#4569</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/04c69110b391e96310e6892cbed9936c4f31d7aa"><code>04c6911</code></a> Sync the ty security mirror (<a href="https://redirect.github.com/astral-sh/ty/issues/4549">#4549</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/3fa57a25767c619dbeba697c2acfbb8eb291519a"><code>3fa57a2</code></a> Grant the versions workflow repository read access (<a href="https://redirect.github.com/astral-sh/ty/issues/4550">#4550</a>)</li> <li><a href="https://github.com/astral-sh/ty/commit/a15b35389b44db57f718fd4e19e093481747c53e"><code>a15b353</code></a> use scoped token for release workflow (<a href="https://redirect.github.com/astral-sh/ty/issues/4506">#4506</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ty/compare/0.0.75...0.0.84">compare view</a></li> </ul> </details> <br /> Updates `hatch` from 1.18.0 to 1.18.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pypa/hatch/releases">hatch's releases</a>.</em></p> <blockquote> <h2>Hatch v1.18.1</h2> <p><em><strong>Added:</strong></em></p> <ul> <li>Apply context formatting to the <code>lock-filename</code> environment option so fields such as <code>{env_name}</code> and <code>{matrix:...}</code> are resolved when computing the lock file path.</li> </ul> <p><em><strong>Fixed:</strong></em></p> <ul> <li> <p>Consolidate extras and feature resolution into a single code path, fixing regressions where environment and project extras could be dropped or resolved inconsistently, and always validate undefined features.</p> </li> <li> <p>Normalize hyphens in the plugin name when building environment option environment variable names in <code>get_env_var()</code>, so options for hyphenated plugins resolve to the correct variable.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pypa/hatch/commit/4b17561f822b1b416403a61855374892ecbe11de"><code>4b17561</code></a> release Hatch v1.18.1 (<a href="https://redirect.github.com/pypa/hatch/issues/2426">#2426</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/b6aaa1a3cac6be652ac90c8c79612bddcca733ea"><code>b6aaa1a</code></a> release Hatchling v1.32.1 (<a href="https://redirect.github.com/pypa/hatch/issues/2425">#2425</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/47f333a98228c326786d3919f346bd7b74d9cf8f"><code>47f333a</code></a> Prepare for hatch and hatchling releases (<a href="https://redirect.github.com/pypa/hatch/issues/2424">#2424</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/d5f7bfe813dd4d81520def23b43f5d46aad1899c"><code>d5f7bfe</code></a> Fix version metadata to preserve leading zeros in CalVer (<a href="https://redirect.github.com/pypa/hatch/issues/2398">#2398</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/cbfc465e019ff51460f80ebbc35370e476aed6b9"><code>cbfc465</code></a> Context formatting support for <code>lock-filename</code> (<a href="https://redirect.github.com/pypa/hatch/issues/2412">#2412</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/929362c909899556ae4efd1f61a3b078677ad235"><code>929362c</code></a> Mark a few more tests that require Internet access (<a href="https://redirect.github.com/pypa/hatch/issues/2400">#2400</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/c9d4e8a82a81835e1ed8b29e6885631d7f5aecb3"><code>c9d4e8a</code></a> Fix env var formatting in <code>get_env_var()</code> function (<a href="https://redirect.github.com/pypa/hatch/issues/2397">#2397</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/84023e0b77ddec3aa3015cd9b57f78f00da2cb18"><code>84023e0</code></a> Some type fixes (<a href="https://redirect.github.com/pypa/hatch/issues/1138">#1138</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/ed8e30bebf98f2fe4d70c18a32a50a8160c391cb"><code>ed8e30b</code></a> Refactor extras so that the logic is in one place (<a href="https://redirect.github.com/pypa/hatch/issues/2382">#2382</a>)</li> <li>See full diff in <a href="https://github.com/pypa/hatch/compare/hatch-v1.18.0...hatch-v1.18.1">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
e9bde462f2 |
chore(deps-dev): bump types-requests from 2.33.0.20260712 to 2.33.0.20260906 in /libs/langgraph (#9156)
Bumps [types-requests](https://github.com/python/typeshed) from 2.33.0.20260712 to 2.33.0.20260906. <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/python/typeshed/commits">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4be610c6bc |
chore(deps): bump pyjwt from 2.15.0 to 2.15.1 in /libs/langgraph (#9140)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.15.0 to 2.15.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/releases">pyjwt's releases</a>.</em></p> <blockquote> <h2>2.15.1</h2> <p>See the <a href="https://github.com/jpadilla/pyjwt/blob/2.15.1/CHANGELOG.rst">2.15.1 changelog</a> for complete release details.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's changelog</a>.</em></p> <blockquote> <h2><code>v2.15.1 <https://github.com/jpadilla/pyjwt/compare/2.15.0...2.15.1></code>__</h2> <p>Fixed</p> <pre><code> - Accept trailing Base64URL ``=`` padding when decoding JWS segments, so tokens issued by AWS ALB and similar systems verify instead of raising ``DecodeError: Invalid crypto padding``. Non-alphabet junk such as ``!!!!`` remains rejected (`[#1209](https://github.com/jpadilla/pyjwt/issues/1209) <https://github.com/jpadilla/pyjwt/issues/1209>`__). </code></pre> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/jpadilla/pyjwt/commit/7d5ef55e42ce42221f58dc49943e92ccad1fa66a"><code>7d5ef55</code></a> chore: prepare 2.15.1 release</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/7bf32526738fe837387bdedd4849a4a525c33a79"><code>7bf3252</code></a> Accept canonical Base64URL padding in JWT segments (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1216">#1216</a>)</li> <li>See full diff in <a href="https://github.com/jpadilla/pyjwt/compare/2.15.0...2.15.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
98b10ba0ff |
chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/checkpoint-conformance (#9133)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/releases">urllib3's releases</a>.</em></p> <blockquote> <h2>2.8.0</h2> <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2> <p><a href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3 is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects <a href="https://opencollective.com/urllib3">please consider contributing financially</a> to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.</p> <p>Thank you for your support.</p> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)</li> </ul> <blockquote> <p>[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.</p> <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.</p> </blockquote> <blockquote> <p>[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.</p> </blockquote> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li> </ul> <h2>Bugfixes</h2> <ul> <li> <p>Fixed response header handling to replace obsolete folded header lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p> </li> <li> <p>Fixed usage of <code>proxy_ssl_context</code> with <code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and will raise an error in v3.0. (<a href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p> </li> <li> <p>Changed behavior of the default <code>ConnectionPool.pool</code> initialization. <code>LifoQueue</code> is now resolved from the <code>queue</code> module after the <code>ConnectionPool</code> is instantiated instead of using the default cached <code>QueueCls</code> class property. This is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched late in the program, such as by gevent. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p> </li> <li> <p>Raised <code>UnrewindableBodyError</code> instead of <code>ValueError</code> when retrying a request whose body had <code>tell()</code> but not <code>seek()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p> </li> <li> <p>Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p> </li> <li> <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response data in 64 KiB chunks (same as the default <code>amt</code> when doing <code>HTTPResponse.stream(...)</code>). (<a href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p> </li> <li> <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal integers (<code>2130706433</code>), ensuring SSL certificate verification uses the correct mode for these addresses. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading <code>FullPoolError</code> instead of <code>ValueError</code> when called with an invalid <code>timeout</code> argument on a pool created with <code>block=True</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p> </li> <li> <p>Fixed port-zero handling to preserve explicit <code>:0</code> values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 request authority. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>, <a href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p> </li> <li> <p>Fixed a bug where <code>PoolManager</code> passed the <code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to HTTP connection pools. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p> </li> <li> <p>Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p> </li> <li> <p>Fixed <code>HTTPSConnection.connect()</code> overriding <code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.</p> <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its <code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP target. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p> </li> <li> <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's changelog</a>.</em></p> <blockquote> <h1>2.8.0 (2026-09-15)</h1> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, <code>GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77></code>__)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, <code>GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw></code>__)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, <code>GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g></code>__)</li> </ul> <p>.. caution::</p> <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. </code></pre></p> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<code>[#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044></code>__)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<code>[#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945></code>__)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<code>[#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092></code>__)</li> </ul> <h2>Bugfixes</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a> Release 2.8.0</li> <li><a href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a> Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for brotlicffi (<a href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a> Fix <code>nox -s docs</code> warning (<a href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a> Fix loading unencrypted client keys with a password in pyOpenSSL (<a href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a> Test pickling of <code>InvalidChunkLength</code> (<a href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a> Share security policy between GitHub and Read the Docs (<a href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a> Add policy on duplicate pull requests (<a href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a> Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li> <li>Additional commits viewable in <a href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com> |
||
|
|
ffe4e8cd6d |
chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/langgraph (#9138)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/releases">urllib3's releases</a>.</em></p> <blockquote> <h2>2.8.0</h2> <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2> <p><a href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3 is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects <a href="https://opencollective.com/urllib3">please consider contributing financially</a> to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.</p> <p>Thank you for your support.</p> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)</li> </ul> <blockquote> <p>[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.</p> <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.</p> </blockquote> <blockquote> <p>[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.</p> </blockquote> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li> </ul> <h2>Bugfixes</h2> <ul> <li> <p>Fixed response header handling to replace obsolete folded header lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p> </li> <li> <p>Fixed usage of <code>proxy_ssl_context</code> with <code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and will raise an error in v3.0. (<a href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p> </li> <li> <p>Changed behavior of the default <code>ConnectionPool.pool</code> initialization. <code>LifoQueue</code> is now resolved from the <code>queue</code> module after the <code>ConnectionPool</code> is instantiated instead of using the default cached <code>QueueCls</code> class property. This is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched late in the program, such as by gevent. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p> </li> <li> <p>Raised <code>UnrewindableBodyError</code> instead of <code>ValueError</code> when retrying a request whose body had <code>tell()</code> but not <code>seek()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p> </li> <li> <p>Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p> </li> <li> <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response data in 64 KiB chunks (same as the default <code>amt</code> when doing <code>HTTPResponse.stream(...)</code>). (<a href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p> </li> <li> <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal integers (<code>2130706433</code>), ensuring SSL certificate verification uses the correct mode for these addresses. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading <code>FullPoolError</code> instead of <code>ValueError</code> when called with an invalid <code>timeout</code> argument on a pool created with <code>block=True</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p> </li> <li> <p>Fixed port-zero handling to preserve explicit <code>:0</code> values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 request authority. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>, <a href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p> </li> <li> <p>Fixed a bug where <code>PoolManager</code> passed the <code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to HTTP connection pools. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p> </li> <li> <p>Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p> </li> <li> <p>Fixed <code>HTTPSConnection.connect()</code> overriding <code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.</p> <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its <code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP target. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p> </li> <li> <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's changelog</a>.</em></p> <blockquote> <h1>2.8.0 (2026-09-15)</h1> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, <code>GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77></code>__)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, <code>GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw></code>__)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, <code>GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g></code>__)</li> </ul> <p>.. caution::</p> <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. </code></pre></p> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<code>[#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044></code>__)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<code>[#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945></code>__)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<code>[#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092></code>__)</li> </ul> <h2>Bugfixes</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a> Release 2.8.0</li> <li><a href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a> Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for brotlicffi (<a href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a> Fix <code>nox -s docs</code> warning (<a href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a> Fix loading unencrypted client keys with a password in pyOpenSSL (<a href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a> Test pickling of <code>InvalidChunkLength</code> (<a href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a> Share security policy between GitHub and Read the Docs (<a href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a> Add policy on duplicate pull requests (<a href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a> Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li> <li>Additional commits viewable in <a href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
f75add0ee9 |
chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/cli (#9137)
[//]: # (dependabot-start) ⚠️ **Dependabot is rebasing this PR** ⚠️ Rebasing might not happen immediately, so don't worry if this takes some time. Note: if you make any changes to this PR yourself, they will take precedence over the rebase. --- [//]: # (dependabot-end) Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/releases">urllib3's releases</a>.</em></p> <blockquote> <h2>2.8.0</h2> <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2> <p><a href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3 is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects <a href="https://opencollective.com/urllib3">please consider contributing financially</a> to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.</p> <p>Thank you for your support.</p> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)</li> </ul> <blockquote> <p>[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.</p> <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.</p> </blockquote> <blockquote> <p>[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.</p> </blockquote> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li> </ul> <h2>Bugfixes</h2> <ul> <li> <p>Fixed response header handling to replace obsolete folded header lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p> </li> <li> <p>Fixed usage of <code>proxy_ssl_context</code> with <code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and will raise an error in v3.0. (<a href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p> </li> <li> <p>Changed behavior of the default <code>ConnectionPool.pool</code> initialization. <code>LifoQueue</code> is now resolved from the <code>queue</code> module after the <code>ConnectionPool</code> is instantiated instead of using the default cached <code>QueueCls</code> class property. This is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched late in the program, such as by gevent. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p> </li> <li> <p>Raised <code>UnrewindableBodyError</code> instead of <code>ValueError</code> when retrying a request whose body had <code>tell()</code> but not <code>seek()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p> </li> <li> <p>Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p> </li> <li> <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response data in 64 KiB chunks (same as the default <code>amt</code> when doing <code>HTTPResponse.stream(...)</code>). (<a href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p> </li> <li> <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal integers (<code>2130706433</code>), ensuring SSL certificate verification uses the correct mode for these addresses. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading <code>FullPoolError</code> instead of <code>ValueError</code> when called with an invalid <code>timeout</code> argument on a pool created with <code>block=True</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p> </li> <li> <p>Fixed port-zero handling to preserve explicit <code>:0</code> values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 request authority. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>, <a href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p> </li> <li> <p>Fixed a bug where <code>PoolManager</code> passed the <code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to HTTP connection pools. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p> </li> <li> <p>Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p> </li> <li> <p>Fixed <code>HTTPSConnection.connect()</code> overriding <code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.</p> <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its <code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP target. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p> </li> <li> <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's changelog</a>.</em></p> <blockquote> <h1>2.8.0 (2026-09-15)</h1> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, <code>GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77></code>__)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, <code>GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw></code>__)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, <code>GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g></code>__)</li> </ul> <p>.. caution::</p> <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. </code></pre></p> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<code>[#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044></code>__)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<code>[#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945></code>__)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<code>[#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092></code>__)</li> </ul> <h2>Bugfixes</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a> Release 2.8.0</li> <li><a href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a> Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for brotlicffi (<a href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a> Fix <code>nox -s docs</code> warning (<a href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a> Fix loading unencrypted client keys with a password in pyOpenSSL (<a href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a> Test pickling of <code>InvalidChunkLength</code> (<a href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a> Share security policy between GitHub and Read the Docs (<a href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a> Add policy on duplicate pull requests (<a href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a> Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li> <li>Additional commits viewable in <a href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
902be1eb2b |
chore(deps): bump the uv group across 2 directories with 1 update (#9136)
Bumps the uv group with 1 update in the /libs/cli/uv-examples/monorepo directory: [urllib3](https://github.com/urllib3/urllib3). Bumps the uv group with 1 update in the /libs/cli/uv-examples/simple directory: [urllib3](https://github.com/urllib3/urllib3). Updates `urllib3` from 2.7.0 to 2.8.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/releases">urllib3's releases</a>.</em></p> <blockquote> <h2>2.8.0</h2> <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2> <p><a href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3 is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects <a href="https://opencollective.com/urllib3">please consider contributing financially</a> to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.</p> <p>Thank you for your support.</p> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)</li> </ul> <blockquote> <p>[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.</p> <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.</p> </blockquote> <blockquote> <p>[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.</p> </blockquote> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li> </ul> <h2>Bugfixes</h2> <ul> <li> <p>Fixed response header handling to replace obsolete folded header lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p> </li> <li> <p>Fixed usage of <code>proxy_ssl_context</code> with <code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and will raise an error in v3.0. (<a href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p> </li> <li> <p>Changed behavior of the default <code>ConnectionPool.pool</code> initialization. <code>LifoQueue</code> is now resolved from the <code>queue</code> module after the <code>ConnectionPool</code> is instantiated instead of using the default cached <code>QueueCls</code> class property. This is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched late in the program, such as by gevent. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p> </li> <li> <p>Raised <code>UnrewindableBodyError</code> instead of <code>ValueError</code> when retrying a request whose body had <code>tell()</code> but not <code>seek()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p> </li> <li> <p>Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p> </li> <li> <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response data in 64 KiB chunks (same as the default <code>amt</code> when doing <code>HTTPResponse.stream(...)</code>). (<a href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p> </li> <li> <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal integers (<code>2130706433</code>), ensuring SSL certificate verification uses the correct mode for these addresses. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading <code>FullPoolError</code> instead of <code>ValueError</code> when called with an invalid <code>timeout</code> argument on a pool created with <code>block=True</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p> </li> <li> <p>Fixed port-zero handling to preserve explicit <code>:0</code> values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 request authority. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>, <a href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p> </li> <li> <p>Fixed a bug where <code>PoolManager</code> passed the <code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to HTTP connection pools. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p> </li> <li> <p>Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p> </li> <li> <p>Fixed <code>HTTPSConnection.connect()</code> overriding <code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.</p> <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its <code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP target. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p> </li> <li> <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's changelog</a>.</em></p> <blockquote> <h1>2.8.0 (2026-09-15)</h1> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, <code>GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77></code>__)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, <code>GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw></code>__)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, <code>GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g></code>__)</li> </ul> <p>.. caution::</p> <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. </code></pre></p> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<code>[#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044></code>__)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<code>[#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945></code>__)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<code>[#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092></code>__)</li> </ul> <h2>Bugfixes</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a> Release 2.8.0</li> <li><a href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a> Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for brotlicffi (<a href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a> Fix <code>nox -s docs</code> warning (<a href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a> Fix loading unencrypted client keys with a password in pyOpenSSL (<a href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a> Test pickling of <code>InvalidChunkLength</code> (<a href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a> Share security policy between GitHub and Read the Docs (<a href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a> Add policy on duplicate pull requests (<a href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a> Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li> <li>Additional commits viewable in <a href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare view</a></li> </ul> </details> <br /> Updates `urllib3` from 2.7.0 to 2.8.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/releases">urllib3's releases</a>.</em></p> <blockquote> <h2>2.8.0</h2> <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2> <p><a href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3 is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects <a href="https://opencollective.com/urllib3">please consider contributing financially</a> to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.</p> <p>Thank you for your support.</p> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)</li> </ul> <blockquote> <p>[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.</p> <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.</p> </blockquote> <blockquote> <p>[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.</p> </blockquote> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li> </ul> <h2>Bugfixes</h2> <ul> <li> <p>Fixed response header handling to replace obsolete folded header lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p> </li> <li> <p>Fixed usage of <code>proxy_ssl_context</code> with <code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and will raise an error in v3.0. (<a href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p> </li> <li> <p>Changed behavior of the default <code>ConnectionPool.pool</code> initialization. <code>LifoQueue</code> is now resolved from the <code>queue</code> module after the <code>ConnectionPool</code> is instantiated instead of using the default cached <code>QueueCls</code> class property. This is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched late in the program, such as by gevent. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p> </li> <li> <p>Raised <code>UnrewindableBodyError</code> instead of <code>ValueError</code> when retrying a request whose body had <code>tell()</code> but not <code>seek()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p> </li> <li> <p>Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p> </li> <li> <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response data in 64 KiB chunks (same as the default <code>amt</code> when doing <code>HTTPResponse.stream(...)</code>). (<a href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p> </li> <li> <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal integers (<code>2130706433</code>), ensuring SSL certificate verification uses the correct mode for these addresses. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading <code>FullPoolError</code> instead of <code>ValueError</code> when called with an invalid <code>timeout</code> argument on a pool created with <code>block=True</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p> </li> <li> <p>Fixed port-zero handling to preserve explicit <code>:0</code> values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 request authority. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>, <a href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p> </li> <li> <p>Fixed a bug where <code>PoolManager</code> passed the <code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to HTTP connection pools. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p> </li> <li> <p>Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p> </li> <li> <p>Fixed <code>HTTPSConnection.connect()</code> overriding <code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.</p> <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its <code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP target. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p> </li> <li> <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's changelog</a>.</em></p> <blockquote> <h1>2.8.0 (2026-09-15)</h1> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, <code>GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77></code>__)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, <code>GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw></code>__)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, <code>GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g></code>__)</li> </ul> <p>.. caution::</p> <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. </code></pre></p> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<code>[#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044></code>__)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<code>[#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945></code>__)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<code>[#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092></code>__)</li> </ul> <h2>Bugfixes</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a> Release 2.8.0</li> <li><a href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a> Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for brotlicffi (<a href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a> Fix <code>nox -s docs</code> warning (<a href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a> Fix loading unencrypted client keys with a password in pyOpenSSL (<a href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a> Test pickling of <code>InvalidChunkLength</code> (<a href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a> Share security policy between GitHub and Read the Docs (<a href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a> Add policy on duplicate pull requests (<a href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a> Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li> <li>Additional commits viewable in <a href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
3b969324db |
chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/checkpoint-sqlite (#9135)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/releases">urllib3's releases</a>.</em></p> <blockquote> <h2>2.8.0</h2> <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2> <p><a href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3 is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects <a href="https://opencollective.com/urllib3">please consider contributing financially</a> to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.</p> <p>Thank you for your support.</p> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)</li> </ul> <blockquote> <p>[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.</p> <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.</p> </blockquote> <blockquote> <p>[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.</p> </blockquote> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li> </ul> <h2>Bugfixes</h2> <ul> <li> <p>Fixed response header handling to replace obsolete folded header lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p> </li> <li> <p>Fixed usage of <code>proxy_ssl_context</code> with <code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and will raise an error in v3.0. (<a href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p> </li> <li> <p>Changed behavior of the default <code>ConnectionPool.pool</code> initialization. <code>LifoQueue</code> is now resolved from the <code>queue</code> module after the <code>ConnectionPool</code> is instantiated instead of using the default cached <code>QueueCls</code> class property. This is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched late in the program, such as by gevent. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p> </li> <li> <p>Raised <code>UnrewindableBodyError</code> instead of <code>ValueError</code> when retrying a request whose body had <code>tell()</code> but not <code>seek()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p> </li> <li> <p>Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p> </li> <li> <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response data in 64 KiB chunks (same as the default <code>amt</code> when doing <code>HTTPResponse.stream(...)</code>). (<a href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p> </li> <li> <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal integers (<code>2130706433</code>), ensuring SSL certificate verification uses the correct mode for these addresses. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading <code>FullPoolError</code> instead of <code>ValueError</code> when called with an invalid <code>timeout</code> argument on a pool created with <code>block=True</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p> </li> <li> <p>Fixed port-zero handling to preserve explicit <code>:0</code> values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 request authority. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>, <a href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p> </li> <li> <p>Fixed a bug where <code>PoolManager</code> passed the <code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to HTTP connection pools. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p> </li> <li> <p>Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p> </li> <li> <p>Fixed <code>HTTPSConnection.connect()</code> overriding <code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.</p> <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its <code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP target. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p> </li> <li> <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's changelog</a>.</em></p> <blockquote> <h1>2.8.0 (2026-09-15)</h1> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, <code>GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77></code>__)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, <code>GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw></code>__)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, <code>GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g></code>__)</li> </ul> <p>.. caution::</p> <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. </code></pre></p> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<code>[#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044></code>__)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<code>[#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945></code>__)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<code>[#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092></code>__)</li> </ul> <h2>Bugfixes</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a> Release 2.8.0</li> <li><a href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a> Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for brotlicffi (<a href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a> Fix <code>nox -s docs</code> warning (<a href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a> Fix loading unencrypted client keys with a password in pyOpenSSL (<a href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a> Test pickling of <code>InvalidChunkLength</code> (<a href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a> Share security policy between GitHub and Read the Docs (<a href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a> Add policy on duplicate pull requests (<a href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a> Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li> <li>Additional commits viewable in <a href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
e43f0f5f1e |
chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/sdk-py (#9134)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/releases">urllib3's releases</a>.</em></p> <blockquote> <h2>2.8.0</h2> <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2> <p><a href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3 is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects <a href="https://opencollective.com/urllib3">please consider contributing financially</a> to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.</p> <p>Thank you for your support.</p> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)</li> </ul> <blockquote> <p>[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.</p> <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.</p> </blockquote> <blockquote> <p>[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.</p> </blockquote> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li> </ul> <h2>Bugfixes</h2> <ul> <li> <p>Fixed response header handling to replace obsolete folded header lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p> </li> <li> <p>Fixed usage of <code>proxy_ssl_context</code> with <code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and will raise an error in v3.0. (<a href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p> </li> <li> <p>Changed behavior of the default <code>ConnectionPool.pool</code> initialization. <code>LifoQueue</code> is now resolved from the <code>queue</code> module after the <code>ConnectionPool</code> is instantiated instead of using the default cached <code>QueueCls</code> class property. This is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched late in the program, such as by gevent. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p> </li> <li> <p>Raised <code>UnrewindableBodyError</code> instead of <code>ValueError</code> when retrying a request whose body had <code>tell()</code> but not <code>seek()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p> </li> <li> <p>Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p> </li> <li> <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response data in 64 KiB chunks (same as the default <code>amt</code> when doing <code>HTTPResponse.stream(...)</code>). (<a href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p> </li> <li> <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal integers (<code>2130706433</code>), ensuring SSL certificate verification uses the correct mode for these addresses. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading <code>FullPoolError</code> instead of <code>ValueError</code> when called with an invalid <code>timeout</code> argument on a pool created with <code>block=True</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p> </li> <li> <p>Fixed port-zero handling to preserve explicit <code>:0</code> values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 request authority. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>, <a href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p> </li> <li> <p>Fixed a bug where <code>PoolManager</code> passed the <code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to HTTP connection pools. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p> </li> <li> <p>Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p> </li> <li> <p>Fixed <code>HTTPSConnection.connect()</code> overriding <code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.</p> <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its <code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP target. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p> </li> <li> <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's changelog</a>.</em></p> <blockquote> <h1>2.8.0 (2026-09-15)</h1> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, <code>GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77></code>__)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, <code>GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw></code>__)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, <code>GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g></code>__)</li> </ul> <p>.. caution::</p> <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. </code></pre></p> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<code>[#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044></code>__)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<code>[#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945></code>__)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<code>[#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092></code>__)</li> </ul> <h2>Bugfixes</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a> Release 2.8.0</li> <li><a href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a> Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for brotlicffi (<a href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a> Fix <code>nox -s docs</code> warning (<a href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a> Fix loading unencrypted client keys with a password in pyOpenSSL (<a href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a> Test pickling of <code>InvalidChunkLength</code> (<a href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a> Share security policy between GitHub and Read the Docs (<a href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a> Add policy on duplicate pull requests (<a href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a> Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li> <li>Additional commits viewable in <a href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
8ccdedcc1b |
chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/checkpoint-postgres (#9132)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/releases">urllib3's releases</a>.</em></p> <blockquote> <h2>2.8.0</h2> <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2> <p><a href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3 is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects <a href="https://opencollective.com/urllib3">please consider contributing financially</a> to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.</p> <p>Thank you for your support.</p> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)</li> </ul> <blockquote> <p>[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.</p> <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.</p> </blockquote> <blockquote> <p>[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.</p> </blockquote> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li> </ul> <h2>Bugfixes</h2> <ul> <li> <p>Fixed response header handling to replace obsolete folded header lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p> </li> <li> <p>Fixed usage of <code>proxy_ssl_context</code> with <code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and will raise an error in v3.0. (<a href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p> </li> <li> <p>Changed behavior of the default <code>ConnectionPool.pool</code> initialization. <code>LifoQueue</code> is now resolved from the <code>queue</code> module after the <code>ConnectionPool</code> is instantiated instead of using the default cached <code>QueueCls</code> class property. This is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched late in the program, such as by gevent. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p> </li> <li> <p>Raised <code>UnrewindableBodyError</code> instead of <code>ValueError</code> when retrying a request whose body had <code>tell()</code> but not <code>seek()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p> </li> <li> <p>Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p> </li> <li> <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response data in 64 KiB chunks (same as the default <code>amt</code> when doing <code>HTTPResponse.stream(...)</code>). (<a href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p> </li> <li> <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal integers (<code>2130706433</code>), ensuring SSL certificate verification uses the correct mode for these addresses. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading <code>FullPoolError</code> instead of <code>ValueError</code> when called with an invalid <code>timeout</code> argument on a pool created with <code>block=True</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p> </li> <li> <p>Fixed port-zero handling to preserve explicit <code>:0</code> values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 request authority. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>, <a href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p> </li> <li> <p>Fixed a bug where <code>PoolManager</code> passed the <code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to HTTP connection pools. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p> </li> <li> <p>Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p> </li> <li> <p>Fixed <code>HTTPSConnection.connect()</code> overriding <code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.</p> <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its <code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP target. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p> </li> <li> <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's changelog</a>.</em></p> <blockquote> <h1>2.8.0 (2026-09-15)</h1> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, <code>GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77></code>__)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, <code>GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw></code>__)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, <code>GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g></code>__)</li> </ul> <p>.. caution::</p> <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. </code></pre></p> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<code>[#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044></code>__)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<code>[#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945></code>__)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<code>[#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092></code>__)</li> </ul> <h2>Bugfixes</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a> Release 2.8.0</li> <li><a href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a> Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for brotlicffi (<a href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a> Fix <code>nox -s docs</code> warning (<a href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a> Fix loading unencrypted client keys with a password in pyOpenSSL (<a href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a> Test pickling of <code>InvalidChunkLength</code> (<a href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a> Share security policy between GitHub and Read the Docs (<a href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a> Add policy on duplicate pull requests (<a href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a> Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li> <li>Additional commits viewable in <a href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
7ea31e5e45 |
chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/checkpoint (#9131)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/releases">urllib3's releases</a>.</em></p> <blockquote> <h2>2.8.0</h2> <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2> <p><a href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3 is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects <a href="https://opencollective.com/urllib3">please consider contributing financially</a> to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.</p> <p>Thank you for your support.</p> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)</li> </ul> <blockquote> <p>[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.</p> <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.</p> </blockquote> <blockquote> <p>[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.</p> </blockquote> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li> </ul> <h2>Bugfixes</h2> <ul> <li> <p>Fixed response header handling to replace obsolete folded header lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p> </li> <li> <p>Fixed usage of <code>proxy_ssl_context</code> with <code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and will raise an error in v3.0. (<a href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p> </li> <li> <p>Changed behavior of the default <code>ConnectionPool.pool</code> initialization. <code>LifoQueue</code> is now resolved from the <code>queue</code> module after the <code>ConnectionPool</code> is instantiated instead of using the default cached <code>QueueCls</code> class property. This is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched late in the program, such as by gevent. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p> </li> <li> <p>Raised <code>UnrewindableBodyError</code> instead of <code>ValueError</code> when retrying a request whose body had <code>tell()</code> but not <code>seek()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p> </li> <li> <p>Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p> </li> <li> <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response data in 64 KiB chunks (same as the default <code>amt</code> when doing <code>HTTPResponse.stream(...)</code>). (<a href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p> </li> <li> <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal integers (<code>2130706433</code>), ensuring SSL certificate verification uses the correct mode for these addresses. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading <code>FullPoolError</code> instead of <code>ValueError</code> when called with an invalid <code>timeout</code> argument on a pool created with <code>block=True</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p> </li> <li> <p>Fixed port-zero handling to preserve explicit <code>:0</code> values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 request authority. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>, <a href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p> </li> <li> <p>Fixed a bug where <code>PoolManager</code> passed the <code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to HTTP connection pools. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p> </li> <li> <p>Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p> </li> <li> <p>Fixed <code>HTTPSConnection.connect()</code> overriding <code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.</p> <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its <code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP target. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p> </li> <li> <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's changelog</a>.</em></p> <blockquote> <h1>2.8.0 (2026-09-15)</h1> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, <code>GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77></code>__)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, <code>GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw></code>__)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, <code>GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g></code>__)</li> </ul> <p>.. caution::</p> <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. </code></pre></p> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<code>[#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044></code>__)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<code>[#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945></code>__)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<code>[#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092></code>__)</li> </ul> <h2>Bugfixes</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a> Release 2.8.0</li> <li><a href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a> Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for brotlicffi (<a href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a> Fix <code>nox -s docs</code> warning (<a href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a> Fix loading unencrypted client keys with a password in pyOpenSSL (<a href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a> Test pickling of <code>InvalidChunkLength</code> (<a href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a> Share security policy between GitHub and Read the Docs (<a href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a> Add policy on duplicate pull requests (<a href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a> Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li> <li>Additional commits viewable in <a href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
313e0e7e0a |
chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/prebuilt (#9130)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/releases">urllib3's releases</a>.</em></p> <blockquote> <h2>2.8.0</h2> <h2>🚀 urllib3 is fundraising for HTTP/2 support</h2> <p><a href="https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support">urllib3 is raising ~$40,000 USD</a> to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects <a href="https://opencollective.com/urllib3">please consider contributing financially</a> to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.</p> <p>Thank you for your support.</p> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)</li> </ul> <blockquote> <p>[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.</p> <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.</p> </blockquote> <blockquote> <p>[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.</p> </blockquote> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5044">#5044</a>)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/4945">#4945</a>)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5092">#5092</a>)</li> </ul> <h2>Bugfixes</h2> <ul> <li> <p>Fixed response header handling to replace obsolete folded header lines (<code>obs-fold</code>) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as <code>Set-Cookie</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/1362">#1362</a>)</p> </li> <li> <p>Fixed usage of <code>proxy_ssl_context</code> with <code>ProxyManager</code> when <code>use_forwarding_for_https=True</code>. Passing <code>ssl_context</code> instead of <code>proxy_ssl_context</code> for HTTPS proxies in this configuration now emits a <code>FutureWarning</code> and will raise an error in v3.0. (<a href="https://redirect.github.com/urllib3/urllib3/issues/2577">#2577</a>)</p> </li> <li> <p>Changed behavior of the default <code>ConnectionPool.pool</code> initialization. <code>LifoQueue</code> is now resolved from the <code>queue</code> module after the <code>ConnectionPool</code> is instantiated instead of using the default cached <code>QueueCls</code> class property. This is done because sometimes the <code>queue.LifoQueue</code> is monkey-patched late in the program, such as by gevent. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3289">#3289</a>)</p> </li> <li> <p>Raised <code>UnrewindableBodyError</code> instead of <code>ValueError</code> when retrying a request whose body had <code>tell()</code> but not <code>seek()</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3779">#3779</a>)</p> </li> <li> <p>Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (<a href="https://redirect.github.com/urllib3/urllib3/issues/3785">#3785</a>)</p> </li> <li> <p>Fixed <code>HTTPResponse.drain_conn()</code> to discard unread response data in 64 KiB chunks (same as the default <code>amt</code> when doing <code>HTTPResponse.stream(...)</code>). (<a href="https://redirect.github.com/urllib3/urllib3/issues/5019">#5019</a>)</p> </li> <li> <p>Fixed <code>is_ipaddress()</code> to detect non-standard IPv4 forms accepted by <code>socket.connect</code>, such as hex (<code>0x7f000001</code>), octal (<code>0177.0.0.1</code>), and decimal integers (<code>2130706433</code>), ensuring SSL certificate verification uses the correct mode for these addresses. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5029">#5029</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen</code> raising a misleading <code>FullPoolError</code> instead of <code>ValueError</code> when called with an invalid <code>timeout</code> argument on a pool created with <code>block=True</code>. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5059">#5059</a>)</p> </li> <li> <p>Fixed port-zero handling to preserve explicit <code>:0</code> values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, <code>connection_from_url()</code>, and HTTP/2 request authority. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5071">#5071</a>, <a href="https://redirect.github.com/urllib3/urllib3/issues/5101">#5101</a>)</p> </li> <li> <p>Fixed a bug where <code>PoolManager</code> passed the <code>assert_hostname</code> and <code>assert_fingerprint</code> parameters to HTTP connection pools. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5077">#5077</a>)</p> </li> <li> <p>Fixed <code>HTTPConnectionPool.urlopen()</code> and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5079">#5079</a>)</p> </li> <li> <p>Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5091">#5091</a>)</p> </li> <li> <p>Fixed <code>HTTPSConnection.connect()</code> overriding <code>ProxyConfig.ssl_context</code>'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.</p> <p><code>HTTPSConnection</code> no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its <code>ssl_context</code> as a fallback when an HTTPS proxy forwards an HTTP target. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5093">#5093</a>)</p> </li> <li> <p>Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (<a href="https://redirect.github.com/urllib3/urllib3/issues/5095">#5095</a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/urllib3/urllib3/blob/main/CHANGES.rst">urllib3's changelog</a>.</em></p> <blockquote> <h1>2.8.0 (2026-09-15)</h1> <h2>Security</h2> <p>Fixed the following security issues:</p> <ul> <li>The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, <code>GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77></code>__)</li> <li><code>HTTPResponse.stream()</code> and <code>read_chunked()</code> could buffer a chunk-size line of unbounded length in memory. (High severity, <code>GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw></code>__)</li> <li>Chunked Deflate streaming could enter an infinite loop. (Medium severity, <code>GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g></code>__)</li> </ul> <p>.. caution::</p> <pre><code>urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. <p>Configure proxy CA certificates and client certificates in <code>proxy_ssl_context</code>, and proxy identity checks with <code>proxy_assert_hostname</code> or <code>proxy_assert_fingerprint</code>. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. </code></pre></p> <h2>Deprecations & Removals</h2> <ul> <li>Deprecated using an empty collection as the <code>Retry</code> option <code>allowed_methods</code> to retry any verb. (<code>[#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044></code>__)</li> </ul> <h2>Features</h2> <ul> <li>Added <code>Url.auth_decoded</code> and <code>Url.auth_decoded_joined</code> convenience properties to the result of <code>parse_url()</code>. (<code>[#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945></code>__)</li> <li>Added <code>basic_auth_encoding</code> and <code>proxy_basic_auth_encoding</code> parameters to <code>urllib3.util.make_headers()</code>. (<code>[#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092></code>__)</li> </ul> <h2>Bugfixes</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/urllib3/urllib3/commit/b1d30ab61fe0db8f11092805e8c5ac43e091064a"><code>b1d30ab</code></a> Release 2.8.0</li> <li><a href="https://github.com/urllib3/urllib3/commit/9016d7e8afc68185496ef07f3c3a4a743d04922e"><code>9016d7e</code></a> Skip <code>test_read_chunked_with_trailing_data_does_not_hang</code> for brotlicffi (<a href="https://redirect.github.com/urllib3/urllib3/issues/5258">#5258</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/9101f581a8b3659af23b6ff335ae77200ca33533"><code>9101f58</code></a> Fix <code>nox -s docs</code> warning (<a href="https://redirect.github.com/urllib3/urllib3/issues/5256">#5256</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed"><code>cd770b0</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f"><code>ea2ad7b</code></a> Merge commit from fork</li> <li><a href="https://github.com/urllib3/urllib3/commit/0716e31534345dc1599ea95d903c79f276239bd8"><code>0716e31</code></a> Fix loading unencrypted client keys with a password in pyOpenSSL (<a href="https://redirect.github.com/urllib3/urllib3/issues/5255">#5255</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/43c68c8b43a9dcb44ed2cf4ec91384ca0d46b37d"><code>43c68c8</code></a> Test pickling of <code>InvalidChunkLength</code> (<a href="https://redirect.github.com/urllib3/urllib3/issues/5247">#5247</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/308b279b3fb28e7bee952e152ec5baeb5bfd0817"><code>308b279</code></a> Share security policy between GitHub and Read the Docs (<a href="https://redirect.github.com/urllib3/urllib3/issues/5253">#5253</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/53fa0731b27d4b71ab0755ea5b896422d005d706"><code>53fa073</code></a> Add policy on duplicate pull requests (<a href="https://redirect.github.com/urllib3/urllib3/issues/5252">#5252</a>)</li> <li><a href="https://github.com/urllib3/urllib3/commit/5f2a6a843d0100d1351c3f94d58581ca98d17267"><code>5f2a6a8</code></a> Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (<a href="https://redirect.github.com/urllib3/urllib3/issues/5232">#5232</a>)</li> <li>Additional commits viewable in <a href="https://github.com/urllib3/urllib3/compare/2.7.0...2.8.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b9919ace32 |
chore(deps): bump pyjwt from 2.13.0 to 2.15.0 in /libs/cli (#9129)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/releases">pyjwt's releases</a>.</em></p> <blockquote> <h2>2.15.0</h2> <p>See the <a href="https://github.com/jpadilla/pyjwt/blob/2.15.0/CHANGELOG.rst">2.15.0 changelog</a> for complete release details.</p> <h2>2.14.0</h2> <p>See the <a href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0 changelog</a> for the complete release details and related security advisories.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's changelog</a>.</em></p> <blockquote> <h2><code>v2.15.0 <https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0></code>__</h2> <p>Security</p> <pre><code> - Wrap recursion errors from deeply nested JWT payloads in ``DecodeError`` instead of exposing a raw ``RecursionError``. <p>Added</p> <pre><code> - Support Python 3.15 by @kytta in `[#1202](https://github.com/jpadilla/pyjwt/issues/1202) &lt;https://github.com/jpadilla/pyjwt/pull/1202&gt;`__ Changed </code></pre> <ul> <li><code>JWKSetCache</code> now stores the parsed <code>PyJWKSet</code> rather than the raw JWKS payload, so a cache hit no longer re-parses every key. <code>JWKSetCache.put()</code> accepts either form and raises <code>PyJWKSetError</code> for anything else. As a result, <code>PyJWKClient.get_jwk_set()</code> returns the same <code>PyJWKSet</code> instance for as long as it stays cached, rather than a freshly built one per call in <code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;</code>__</li> <li><code>PyJWKClient.fetch_data()</code> now raises <code>PyJWKClientError(&quot;The JWKS endpoint did not return a JSON object&quot;)</code> when the endpoint response is not a JSON object, instead of returning it for <code>get_jwk_set()</code> to reject. Callers reaching the JWKS through <code>get_jwk_set()</code> see the same error as before in <code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;</code>__</li> </ul> <p>Fixed</p> <pre><code> - Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead of raising ``PyJWKClientError(&quot;The JWKS endpoint did not return a JSON object&quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value, so callers pre-populating the cache to avoid a network round-trip could not read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) &lt;https://github.com/jpadilla/pyjwt/issues/914&gt;`__ and `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__ - ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a ``fetch_data()`` override that filters or transforms the JWKS is no longer undone by the next cache hit in `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__ - Raise the documented ``PyJWTError`` subclass instead of leaking a ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a non-numeric, non-string value such as a list, dict, or ``null``. - Reject OKP JWK private keys when their public ``x`` component does not match the private ``d`` component. - Treat malformed JWK Set members as unusable keys rather than letting ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is not &lt;/tr&gt;&lt;/table&gt; </code></pre> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68"><code>1d41a64</code></a> chore: prepare 2.15.0 release</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3"><code>9bc0665</code></a> fix: make recursive payload tests deterministic</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b"><code>5fde08a</code></a> fix: normalize recursive JWT payload errors</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19"><code>171062d</code></a> utils: mention bytes in force_bytes type error (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1173">#1173</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6"><code>c9d4d53</code></a> docs/conf: drop duplicate 'and' from read() docstring (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1174">#1174</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53"><code>2763752</code></a> Add support for Python 3.15 (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1202">#1202</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5"><code>4adcd02</code></a> Catch http.client.HTTPException in PyJWKClient.fetch_data (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1201">#1201</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097"><code>9e501d9</code></a> fix: correct docstring typo in _validate_jti (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1179">#1179</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2"><code>4047c44</code></a> docs: clarify JWK certificate member handling (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1212">#1212</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9"><code>f4e2b59</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1210">#1210</a>)</li> <li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.15.0">compare view</a></li> </ul> </details> <br /></code></pre> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4217373227 |
chore(deps): bump pyjwt from 2.14.0 to 2.15.0 in /libs/langgraph (#9139)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.14.0 to 2.15.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/releases">pyjwt's releases</a>.</em></p> <blockquote> <h2>2.15.0</h2> <p>See the <a href="https://github.com/jpadilla/pyjwt/blob/2.15.0/CHANGELOG.rst">2.15.0 changelog</a> for complete release details.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's changelog</a>.</em></p> <blockquote> <h2><code>v2.15.0 <https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0></code>__</h2> <p>Security</p> <pre><code> - Wrap recursion errors from deeply nested JWT payloads in ``DecodeError`` instead of exposing a raw ``RecursionError``. <p>Added</p> <pre><code> - Support Python 3.15 by @kytta in `[#1202](https://github.com/jpadilla/pyjwt/issues/1202) &lt;https://github.com/jpadilla/pyjwt/pull/1202&gt;`__ Changed </code></pre> <ul> <li><code>JWKSetCache</code> now stores the parsed <code>PyJWKSet</code> rather than the raw JWKS payload, so a cache hit no longer re-parses every key. <code>JWKSetCache.put()</code> accepts either form and raises <code>PyJWKSetError</code> for anything else. As a result, <code>PyJWKClient.get_jwk_set()</code> returns the same <code>PyJWKSet</code> instance for as long as it stays cached, rather than a freshly built one per call in <code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;</code>__</li> <li><code>PyJWKClient.fetch_data()</code> now raises <code>PyJWKClientError(&quot;The JWKS endpoint did not return a JSON object&quot;)</code> when the endpoint response is not a JSON object, instead of returning it for <code>get_jwk_set()</code> to reject. Callers reaching the JWKS through <code>get_jwk_set()</code> see the same error as before in <code>[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;</code>__</li> </ul> <p>Fixed</p> <pre><code> - Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead of raising ``PyJWKClientError(&quot;The JWKS endpoint did not return a JSON object&quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value, so callers pre-populating the cache to avoid a network round-trip could not read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) &lt;https://github.com/jpadilla/pyjwt/issues/914&gt;`__ and `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__ - ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a ``fetch_data()`` override that filters or transforms the JWKS is no longer undone by the next cache hit in `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__ - Raise the documented ``PyJWTError`` subclass instead of leaking a ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a non-numeric, non-string value such as a list, dict, or ``null``. - Reject OKP JWK private keys when their public ``x`` component does not match the private ``d`` component. - Treat malformed JWK Set members as unusable keys rather than letting ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is not &lt;/tr&gt;&lt;/table&gt; </code></pre> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68"><code>1d41a64</code></a> chore: prepare 2.15.0 release</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3"><code>9bc0665</code></a> fix: make recursive payload tests deterministic</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b"><code>5fde08a</code></a> fix: normalize recursive JWT payload errors</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19"><code>171062d</code></a> utils: mention bytes in force_bytes type error (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1173">#1173</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6"><code>c9d4d53</code></a> docs/conf: drop duplicate 'and' from read() docstring (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1174">#1174</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53"><code>2763752</code></a> Add support for Python 3.15 (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1202">#1202</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5"><code>4adcd02</code></a> Catch http.client.HTTPException in PyJWKClient.fetch_data (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1201">#1201</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097"><code>9e501d9</code></a> fix: correct docstring typo in _validate_jti (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1179">#1179</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2"><code>4047c44</code></a> docs: clarify JWK certificate member handling (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1212">#1212</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9"><code>f4e2b59</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1210">#1210</a>)</li> <li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0">compare view</a></li> </ul> </details> <br /></code></pre> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
65ab10f017 |
chore(deps): bump pyjwt from 2.13.0 to 2.14.0 in /libs/langgraph (#9126)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.14.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/releases">pyjwt's releases</a>.</em></p> <blockquote> <h2>2.14.0</h2> <p>See the <a href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0 changelog</a> for the complete release details and related security advisories.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's changelog</a>.</em></p> <blockquote> <h2><code>v2.14.0 <https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0></code>__</h2> <p>Security</p> <pre><code> - Harden HMAC key validation against public-key material supplied as JWK, JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See `GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>`__, `GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>`__, `GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>`__, and `GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>`__. - Reject automatic redirects when ``PyJWKClient`` fetches a JWKS, preventing redirected destinations from being treated as trusted key sources. See `GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>`__. - Limit repeated JWKS refreshes caused by unknown key IDs while preserving normal key-rotation behavior. See `GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>`__. - Handle deeply nested and malformed JWS/JWK input without uncaught recursion errors or whole-set parsing failures. See `GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>`__ and `GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>`__. - Enforce compact JWS encoding rules during decoding. See `GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>`__. - Reject detached-payload arguments for attached JWS inputs. Thanks to `@xclow3n <https://github.com/xclow3n>`__ for reporting this behavior; fixed in commit `37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>`__. <p>Fixed</p> <pre><code> - Apply HMAC key validation consistently when keys are loaded through ``PyJWK`` and ``PyJWKClient``. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. - Reject empty HMAC keys when represented as JWKs. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. </code></pre> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df"><code>c6fe464</code></a> release: prepare v2.14.0</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42"><code>f541302</code></a> style: apply Ruff formatting</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95"><code>801cd12</code></a> fix: reject public JWK container HMAC keys</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb"><code>af8181c</code></a> fix: reject empty HMAC keys from JWKs</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1"><code>ba4853a</code></a> Throttle repeated PyJWKClient refreshes</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499"><code>2798504</code></a> fix: reject DER public keys as HMAC secrets</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07"><code>8b4e233</code></a> fix: reject loader-accepted PEM variants</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258"><code>1f8180a</code></a> fix: format JWS tests</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab"><code>cff1ac5</code></a> Fix redirect handler return annotation</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"><code>0a795b8</code></a> Reject redirects in PyJWKClient fetches</li> <li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0">compare view</a></li> </ul> </details> <br /></code></pre> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
eb69f67b65 |
fix(checkpoint-sqlite): walk delta ancestors by parent pointer (#8557)
## Summary The sqlite delta history silently drops a parent checkpoint whose id sorts above its child's, losing that parent's stored value and its pending writes. The channel hydrates short with no error. Fixes #8550 ## Problem Stage 1 walked ancestors with: ```sql WHERE thread_id = ? AND checkpoint_ns = ? AND checkpoint_id <= ? ORDER BY checkpoint_id DESC ``` Ancestry is defined by the `parent_checkpoint_id` column. These two predicates add a second requirement: that every child's id sorts above its parent's. The contract promises monotonic ids, but that only holds within one process, so ids from processes with different clocks can break it. When the requirement is violated the parent is excluded from the stream and its seed and writes go with it. Dropping the range filter alone does not fix it: in `checkpoint_id DESC` order that parent arrives *before* the target, so the walk streams past it before it has started. ## Fix A recursive CTE anchored at the target, following `parent_checkpoint_id`: ```sql WITH RECURSIVE ancestors(checkpoint_id, parent_checkpoint_id, type, checkpoint) AS ( SELECT ... FROM checkpoints WHERE thread_id = ? AND checkpoint_ns = ? AND checkpoint_id = ? UNION ALL SELECT c.... FROM ancestors a CROSS JOIN checkpoints c ON c.checkpoint_id = a.parent_checkpoint_id WHERE c.thread_id = ? AND c.checkpoint_ns = ? ) SELECT checkpoint_id, type, checkpoint FROM ancestors ``` Rows now arrive in walk order (target, parent, grandparent, ...), so `step_walk_with_row` no longer needs its off-path skip or its `parent_cid` tracking; both are removed. The query reads only true ancestors, where the old one read every row at or below the target including sibling branches. `CROSS JOIN` pins the join order. The saver never runs `ANALYZE`, and with a plain `JOIN` sqlite put `checkpoints` as the outer loop, scanning the whole thread on every recursion step. With `ancestors` outside, each step is one primary key lookup. Through `get_delta_channel_history`: | chain length | plain `JOIN` | `CROSS JOIN` | | -- | -- | -- | | 1000 | 0.032s | 0.001s | | 2000 | 0.124s | 0.003s | | 4000 | 0.475s | 0.006s | ## Cycle guard Following pointers can loop where a bounded id scan could not, and a loop is reachable through `put` alone: `put` writes with `INSERT OR REPLACE`, so re-putting an existing checkpoint id under a descendant's config repoints that checkpoint at its own descendant. The walk stops on a repeated `checkpoint_id` (one set insert per row, no depth ceiling that could truncate a long migrated thread). sqlite yields recursive rows lazily, so abandoning the cursor ends the recursion. `test_walk_terminates_when_put_makes_the_parent_chain_cycle` fails by hanging, not by asserting, if the guard regresses (confirmed by deleting the guard locally). The package has no `pytest-timeout`, so the CI job timeout is the backstop. ## Postgres No equivalent change needed. It pages the whole thread with no id bound and follows parent pointers in Python, and its upsert never rewrites `parent_checkpoint_id`, so it can neither miss this parent nor form the loop. `BaseCheckpointSaver` and `InMemorySaver` also walk parent pointers. ## Test plan New `libs/checkpoint-sqlite/tests/test_delta_parent_walk.py`: - [x] Sync and async, parametrised over both id orders; the sync case also asserts equality with `BaseCheckpointSaver` on the same rows. `parent_id_sorts_above_child` is the bug, `parent_id_sorts_below_child` the control. - [x] `test_walk_reaches_root_of_long_chain_with_descending_ids`: 40 checkpoints, only stored value at the root. - [x] `test_walk_terminates_when_put_makes_the_parent_chain_cycle`. - [x] `test_walk_step_looks_up_the_parent_by_primary_key`: asserts the recursive step's `EXPLAIN QUERY PLAN` is a key lookup, so a plain `JOIN` can't come back. Fails with it. - [x] On `main`: 3 of the 6 walk tests fail (both `parent_id_sorts_above_child` cases and the long chain). The cycle test passes on `main` too, since the old bounded scan could not loop; it guards the new path. - [x] #8550's repro returns `{'writes': [('task', 'ch', 'write-root')], 'seed': 'seed'}` sync and async (was `{'writes': []}` on `main`). - [x] `libs/checkpoint-sqlite`: `make format`, `make lint` clean; full suite 125 passed, 2 skipped. - [x] `libs/langgraph`: `-k "delta or sqlite"` 739 passed, 1 skipped. Thanks to @lylelllll for the report, the minimal repro, the base-saver comparison that isolated it to the fast path, and for suggesting the recursive CTE. Co-authored-by: lylelllll <59271327+lylelllll@users.noreply.github.com> |
||
|
|
c0279f0910 |
fix(checkpoint-postgres): derive the delta walk cursor once the target loads (#8556)
## Summary `get_delta_channel_history` on Postgres returns an empty history for any `DeltaChannel` on a target checkpoint that is not within the first stage-1 pagination page (1024 rows) of the thread. No exception, no warning: the channel just hydrates empty. Fixes #8448 ## Problem Stage 1 pages `checkpoints` newest-first from the head of the thread, and after each page `_try_advance_walks` tries to move every not-yet-seeded channel's walk along the partial `parent_of` map accumulated so far. The walk starts at the target's parent: ```python if ch not in walk_cursor_by_ch: walk_cursor_by_ch[ch] = parent_of.get(target_id) ``` The target can be any checkpoint in the thread, not just the head, so on the first page `parent_of` frequently has no row for it yet. `.get` then returns `None`, which is also what a target with no parent returns, and the two are stored identically. Because the initialisation is guarded by `ch not in walk_cursor_by_ch`, it never runs again: once the walk is parked at `None` it stays there even after the target's real row and real parent load on a later page. The result is an empty chain and no seed. Downstream `channels_from_checkpoint` does ```python replay_ch = delta_spec.from_checkpoint(history.get("seed", MISSING)) replay_ch.replay_writes(history["writes"]) ``` so `get_state`, `get_state_history` and `update_state` against an older checkpoint reconstruct a `messages` channel as `[]` on a thread with hundreds of real messages. ## Fix Start the walk only once `target_id` is actually present in `parent_of`, so "the target has not loaded yet" stops sharing a representation with "the target is a root": ```python if ch not in walk_cursor_by_ch: if target_id not in parent_of: continue walk_cursor_by_ch[ch] = parent_of[target_id] ``` `_try_advance_walks` is a static method on `BasePostgresSaver`, so `PostgresSaver` and `AsyncPostgresSaver` are both covered by the one change. ## Why it's safe `continue` leaves the channel exactly as it was, so a later page retries. The three existing stop conditions are untouched: a channel that finds its seed still seeds, one that reaches a real root still parks at `None`, and one waiting on an ancestor still keeps its cursor. Paging still terminates on a short page, which is what ends the run for a target that really is a root. ## Long-term The sibling sqlite implementation avoids this class of bug differently, by starting its stage-1 scan at the target (`checkpoint_id <= ?`) instead of at the head. Postgres could adopt the same bound and would then never fetch a checkpoint newer than the target at all, which looks like the bigger win on a long thread. It makes the read path depend on ancestors always sorting below their descendants, though, which sqlite already assumes but the Postgres fast path currently does not. #8550 now reports that assumption as a bug in sqlite, on the grounds that ancestry is defined by `parent_checkpoint_id` and the contract does not require ids to be monotonic, so the bound is the wrong direction to move Postgres in. Paging the full thread and following parent pointers is what keeps this path correct when ids are not monotonic, and with this fix Postgres returns the right history for #8550's scenario at every page size. ## Test plan New `libs/checkpoint-postgres/tests/test_delta_pagination.py`. Page size is monkeypatched rather than writing 1024+ real checkpoints per case, since the only thing that decides the behaviour is which page the target lands on. - [x] `test_async_target_older_than_the_first_page` and its sync twin, parametrised over page sizes `[_DELTA_PAGE_SIZE, 3, 2, 1]`. The thread has 8 checkpoints with a snapshot at step 1 and the target at step 4, so every size at or below 3 leaves the target off the first page. The real page size is the control. - [x] `test_root_target_has_no_history_and_still_terminates` covers the case where a `None` cursor is the correct answer, at page size 1 so the paging loop runs the length of the thread. - [x] 6 of the 9 fail on `main` (`expected a snapshot seed, got '<missing>'`); the 3 that pass are the two controls and the root case. - [x] `make format`, `make lint_package`, `make lint_tests` clean. - [x] Full `libs/checkpoint-postgres` suite, rebased on current `main`: 279 passed, 3 skipped on Postgres 16. - [x] Graph-level repro with `_DELTA_PAGE_SIZE = 5`: 10 invocations, then `get_state` on the 8th-newest checkpoint returns `[]` on `main` and the full history on this branch. Thanks to @Navneet-Scaler for the report, the mechanism write-up, and the fix in #8453, which this matches. Co-authored-by: Navneet-Scaler <147032454+Navneet-Scaler@users.noreply.github.com> |
||
|
|
07b33185ea |
fix: reject credential-bearing Git dependencies (#8542)
## Description Reject Git HTTP dependency URLs containing userinfo before Docker generation so credentials cannot persist in Dockerfiles or image layers. Validation now covers local requirement/package metadata and uv pyproject/lock inputs while keeping errors token-free. ## Test Plan - [x] Validate credentialed raw, local-manifest, and uv-managed Git URLs are rejected without echoing secrets - [x] Validate credential-free HTTPS and SSH Git URLs remain supported Made by [Open SWE](https://openswe.vercel.app/agents/81b07455-ece4-3ddc-9955-d7a5bea78d2c) --------- Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
7daa3ab49d |
feat(cli): place self-hosted deployments on a listener (#9056)
Follow-up to #8482. `langgraph deploy --push-to` can now create a deployment in a workspace that deploys through a listener in the customer's own cluster, which is the hybrid case. Before this, creation in such a workspace was impossible from the CLI: the control plane rejected it and the CLI told the user to go and create the deployment in the UI first. ## Changes - Smart Auto-Placement: The CLI now proactively checks your workspace. If you only have one listener and one Kubernetes namespace configured (and are using the managed cloud control plane), it automatically routes your deployment there. No extra flags needed. - New Disambiguation Flags: If your workspace has multiple listeners or namespaces, the CLI will ask you to choose. You can now pass --listener-id and --k8s-namespace to tell it exactly where to deploy. - Failing Fast: The CLI now validates your listener and namespace choices before it starts building and pushing the heavy Docker image. If you provide an invalid ID, it stops immediately instead of wasting your time and bandwidth. - Fixed a Duplication Bug: Previously, if you had many deployments with similar names, a pagination issue could hide your existing deployment from the CLI, causing it to accidentally create a duplicate. The CLI now queries the server for the exact deployment name to guarantee this doesn't happen. - Cleaner Errors: Error messages from the control plane are now stripped of their clunky HTTP envelopes so you get clear, readable sentences when something goes wrong. ## Testing Deployment on 3 paths, hybrid, self-hosted, nominal |
||
|
|
e868c3ccfd |
feat(cli): clarify agent flags and support env defaults (#9063)
Agent deployment options now print a private-beta notice. Rename `--environment` to `--agent-environment` and accept `LANGSMITH_AGENT_ID` / `LANGSMITH_AGENT_ENVIRONMENT` as process-environment defaults for deploy and list. Explicit flags take precedence, and the backend payload is unchanged. Validation: formatting and lint pass. A local smoke check verified environment-only deployment, explicit flag precedence, list defaults, and structured JSON output. Full CLI suite: 411 passed; the two known Docker failures remain (`test_dockerfile_command_with_docker_compose` and `test_build_generate_proper_build_context`). No new tests added; the existing test invocation uses the renamed flag. |
||
|
|
1211af45b1 |
feat(cli): Update langgraph deploy command to use agent_id and environment args (#9055)
- Accept agent_id and environment args for `lanngraph deploy` - Validate both arguments present or none - If agent arguments present, make sure deployment_id and name are not present |
||
|
|
1afaca35a0 |
feat(cli): add --image-uri flag for self-hosted deployments (#8482)
Adds `--image-uri <uri>` to `langgraph deploy` so self-hosted LangSmith customers can build, push, and deploy in one command without needing to script the three steps manually. When `--image-uri` is provided the CLI: - Builds the image tagged to the provided URI (same Docker build path as the local build flow) - Pushes using whatever Docker credentials are already in the environment (e.g. WIF, `aws ecr get-login-password`) — no auth handling in the CLI - PATCHes the deployment with `source_revision_config.image_uri` (no `revision_source`, which the self-hosted control plane rejects for `external_docker` deployments) Also fixes two self-hosted-specific issues uncovered during testing: - `LANGSMITH_ENDPOINT` is now used as a fallback when `LANGGRAPH_HOST_URL` isn't set — the CLI strips the `/api/v1` path and appends `/api-host` to reach the control plane - The httpx client now builds full URLs via string concatenation rather than relying on httpx base_url merging, which silently dropped the `/api-host` path prefix when paths started with `/` - The "Check status at" URL after a deploy now correctly points to the self-hosted LangSmith UI instead of `smith.langchain.com` **How did you verify your code works?** Tested end-to-end against a self-hosted LangSmith instance using ECR as the registry. `langgraph deploy --image-uri <ecr-uri>` successfully built, pushed, and triggered a deployment revision. Confirmed the existing SaaS flow (`langgraph deploy` without `--image-uri`) is unaffected — the new flag is opt-in and the `LANGSMITH_ENDPOINT` fallback only activates when `LANGGRAPH_HOST_URL` is unset and `LANGSMITH_ENDPOINT` is present. --------- Co-authored-by: Hari Dhanushkodi <hari-dhanushkodi@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> Co-authored-by: Hugo Durand <hugo.durand@langchain.dev> |
||
|
|
49cce0ca85 |
release(sdk-py): 0.4.5 (#8988)
Bumps the Python SDK version from 0.4.4 to 0.4.5. Adds `response_schema` to the `Interrupt` TypedDict (#8886). |
||
|
|
19273fa88b |
release(langgraph): 1.2.12 (#8987)
Bumps langgraph from 1.2.11 to 1.2.12. Ships `response_schema` on `interrupt()` (#8886). |
||
|
|
ed384f3a12 |
fix(cli): remediate AnyIO vulnerabilities in example lockfiles (#9022)
- Upgrade AnyIO from 4.13.0 to 4.14.2 in both uv example lockfiles, fixing GHSA-82r6-8w77-94w6 (TLS certificate spoofing) and GHSA-5p39-cfhj-2xmp (process-pool hangs). - Remove the orphaned examples Poetry lockfile left behind by the uv migration; current example tooling does not consume it. - Addresses all six currently open Dependabot alerts without changing unrelated dependencies. Made by [Open SWE](https://github.com/langchain-ai/open-swe) · [view thread](https://openswe.vercel.app/agents/37d08f4f-9fe6-51be-adc9-d58aa9e6e010) · openai:gpt-6-astra (medium) Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
aa742fb31e |
chore(deps): bump anyio from 4.14.2 to 4.15.1 in /libs/sdk-py (#8997)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.14.2 to 4.15.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agronholm/anyio/releases">anyio's releases</a>.</em></p> <blockquote> <h2>4.15.1</h2> <ul> <li>Implemented a compatibility fix for supporting direct access of <code>anyio.*</code> submodules from the main package even when those submodules were not directly imported first (<!-- raw HTML omitted --><a href="https://redirect.github.com/agronholm/anyio/issues/1311">#1311</a> <<a href="https://redirect.github.com/agronholm/anyio/issues/1311%5C%3E">agronholm/anyio#1311</a><!-- raw HTML omitted -->)</li> </ul> <h2>4.15.0</h2> <ul> <li> <p>Added support for the newer keyword-only arguments on <code>anyio.Path</code> methods to match the standard library <code>pathlib.Path</code>:</p> <ul> <li><code>follow_symlinks</code> on <code>exists()</code> (Python 3.12+)</li> <li><code>follow_symlinks</code> on <code>is_dir()</code> (Python 3.13+)</li> <li><code>follow_symlinks</code> on <code>is_file()</code> (Python 3.13+)</li> <li><code>follow_symlinks</code> on <code>owner()</code> (Python 3.13+)</li> <li><code>follow_symlinks</code> on <code>group()</code> (Python 3.13+)</li> <li><code>newline</code> on <code>read_text()</code> (Python 3.13+)</li> </ul> <p>(<a href="https://redirect.github.com/agronholm/anyio/pull/1286">#1286</a>, <a href="https://redirect.github.com/agronholm/anyio/pull/1293">#1293</a>; PR by <a href="https://github.com/jaideeppyne"><code>@jaideeppyne</code></a>)</p> </li> <li> <p>Added <code>amap</code>, <code>gather</code>, and <code>as_completed</code> utility functions to simplify common patterns (<a href="https://redirect.github.com/agronholm/anyio/pull/1173">#1173</a>; PR by <a href="https://github.com/Graeme22"><code>@Graeme22</code></a>)</p> </li> <li> <p>Added <code>--anyio-mode</code> command-line option as an alternative to the <code>anyio_mode</code> ini setting, and fix the pytest plugin's auto mode detection to recognize the mode when set via either mechanism(e.g: <code>pytest_asyncio</code>). (<a href="https://redirect.github.com/agronholm/anyio/pull/1242">#1242</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Added the <code>anyio.Future</code> synchronization primitive which behaves similar to <code>asyncio.Future</code>, allowing tasks to wait for a value (or exception) from another task (<a href="https://redirect.github.com/agronholm/anyio/pull/1146">#1146</a>; PR by <a href="https://github.com/Vizonex"><code>@Vizonex</code></a>)</p> </li> <li> <p>Added guidance for managing multiple memory object stream producers and consumers with cloned streams (<a href="https://redirect.github.com/agronholm/anyio/issues/330">#330</a>; PR by <a href="https://github.com/nightcityblade"><code>@nightcityblade</code></a>)</p> </li> <li> <p>Added <code>StapledObjectStream.send_nowait()</code> that delegates to the underlying <code>ObjectSendStream</code>, if it implements it (<a href="https://redirect.github.com/agronholm/anyio/pull/1241">#1241</a>; PR by <a href="https://github.com/davidbrochart"><code>@davidbrochart</code></a>)</p> </li> <li> <p>Added the <code>move_on_at()</code> and <code>fail_at()</code> functions to complement <code>move_on_after()</code> and <code>fail_after()</code></p> </li> <li> <p>Changed the default name for a task spawned with <code>TaskGroup.create_task(func())</code> to match the default task name for the analogous task spawned with <code>TaskGroup.start_soon(func)</code> or <code>TaskGroup.start(func)</code> in more situations. Previously, the default name of a <code>TaskGroup.create_task</code> task never included the module name. (The default name for a task spawned with <code>TaskGroup.start_soon</code> or <code>TaskGroup.start</code> typically includes the module name.) (<a href="https://redirect.github.com/agronholm/anyio/pull/1234">#1234</a>; PR by <a href="https://github.com/gschaffner"><code>@gschaffner</code></a>)</p> </li> <li> <p>Changed the <code>anyio</code> and <code>anyio.abc</code> modules to lazily (much like <code>810</code>) import the necessary submodules. This is done by parsing the AST of the module and building a lookup table from the <code>if TYPE_CHECKING:</code> block. A fallback mode has been provided for installations where the source code is unavailable (e.g. PyInstaller). (<a href="https://redirect.github.com/agronholm/anyio/pull/1169">#1169</a>)</p> </li> <li> <p>Fixed free-threading compatibility issues arising from the fact that on Python 3.14 free-threading builds, newly created threads inherit the current context by default, causing AnyIO to behave erroneously in relation to <code>start_blocking_portal()</code> and <code>anyio.to_thread.run_sync()</code> (<a href="https://redirect.github.com/agronholm/anyio/pull/1224">#1224</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Fixed <code>SpooledTemporaryFile.readinto()</code> and <code>readinto1()</code> reading twice before rollover, so the destination buffer was overwritten by the second read and the file position advanced twice, silently losing data (<a href="https://redirect.github.com/agronholm/anyio/pull/1215">#1215</a>; PR by <a href="https://github.com/c-tonneslan"><code>@c-tonneslan</code></a>)</p> </li> <li> <p>Added a <code>reason</code> parameter to <code>fail_after</code> (and the new <code>fail_at</code>) allowing for added exception context when raising <code>TimeoutError</code> (<a href="https://redirect.github.com/agronholm/anyio/pull/1227">#1227</a>; PR by <a href="https://github.com/Graeme22"><code>@Graeme22</code></a>)</p> </li> <li> <p>Fixed the default <code>TaskHandle.name</code> missing part of the task name for tasks started with <code>TaskGroup.start</code> on Trio (<a href="https://redirect.github.com/agronholm/anyio/issues/1231">#1231</a>; PR by <a href="https://github.com/gschaffner"><code>@gschaffner</code></a>)</p> </li> <li> <p>Fixed <code>anyio.run</code> leaking, or at least, delaying collection of loop and root_task due to the root task being cached in a <code>RunVar</code>. (<a href="https://redirect.github.com/agronholm/anyio/issues/1203">#1203</a>; PR by <a href="https://github.com/tapetersen"><code>@tapetersen</code></a>)</p> </li> <li> <p>Fixed <code>anyio.Path.with_stem()</code> silently producing a wrong path (e.g. <code>Path(".txt")</code>) instead of raising <code>ValueError</code> when given an empty stem on a path with a non-empty suffix, unlike <code>pathlib.PurePath.with_stem</code> (<a href="https://redirect.github.com/agronholm/anyio/pull/1200">#1200</a>; PR by <a href="https://github.com/Sanjays2402"><code>@Sanjays2402</code></a>)</p> </li> <li> <p>Fixed <code>UNIXSocketStream.aclose()</code> raising <code>asyncio.InvalidStateError</code> when a concurrent receive or send operation had just been cancelled on the asyncio backend (<a href="https://redirect.github.com/agronholm/anyio/issues/1267">#1267</a>; PR by <a href="https://github.com/alloutflo"><code>@alloutflo</code></a>)</p> </li> <li> <p>Fixed the pytest plugin importing the deprecated <code>_pytest.python.CallSpec2</code> alias, which triggers <code>PytestRemovedIn10Warning</code> on <code>pytest>=9.2</code> and crashes pytest at startup when <code>filterwarnings = error</code> is configured (<a href="https://redirect.github.com/agronholm/anyio/issues/1271">#1271</a>; PR by <a href="https://github.com/matthewfeickert"><code>@matthewfeickert</code></a>)</p> </li> <li> <p>Fixed an asyncio worker thread race that could raise <code>RuntimeError</code> when the event loop closed between checking its state and scheduling the worker result (<a href="https://redirect.github.com/agronholm/anyio/issues/1265">#1265</a>; PR by <a href="https://github.com/hansu650"><code>@hansu650</code></a>)</p> </li> <li> <p>Fixed <code>CapacityLimiter</code> on the asyncio backend over-granting tokens when <code>total_tokens</code> was raised while the limiter was over-subscribed (<a href="https://redirect.github.com/agronholm/anyio/pull/1223">#1223</a>; PR by <a href="https://github.com/zelinewang"><code>@zelinewang</code></a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agronholm/anyio/commit/ffcd1542cd6d127980205f90a0100078849dd703"><code>ffcd154</code></a> Bumped up the version</li> <li><a href="https://github.com/agronholm/anyio/commit/0ecf5ed98d294242509b043ebd1a0843e52d892f"><code>0ecf5ed</code></a> Added a workaround for third party code accessing unimported submodules (<a href="https://redirect.github.com/agronholm/anyio/issues/1309">#1309</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/928366259543412a2deb1e2ba09ea45ffa92ef4f"><code>9283662</code></a> Bumped up the version</li> <li><a href="https://github.com/agronholm/anyio/commit/d137692a90f76e4f71605e32ea5ca94cab3a539d"><code>d137692</code></a> Improved the instructions for AI agents</li> <li><a href="https://github.com/agronholm/anyio/commit/033fc52b8fa8e90c5d0ef24b10b3860e974a6265"><code>033fc52</code></a> Shield TemporaryDirectory cleanup from cancellation (<a href="https://redirect.github.com/agronholm/anyio/issues/1304">#1304</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/942e9a6552cc10b5aaa779d84bfc8e2c3d5fcffc"><code>942e9a6</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/agronholm/anyio/issues/1305">#1305</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/b825c3be7cb4ca1a8000b8065d4e147843deb704"><code>b825c3b</code></a> Fixed pyproject.toml changes not triggering the test suite</li> <li><a href="https://github.com/agronholm/anyio/commit/9727dc504681e2986b5bc285de9571fb467539af"><code>9727dc5</code></a> Fixed start inconsistencies between trio and asyncio (<a href="https://redirect.github.com/agronholm/anyio/issues/1198">#1198</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/b05fe6d160a640355c201363cab286a7d2581da8"><code>b05fe6d</code></a> Fixed wrong type in move_on_after (<a href="https://redirect.github.com/agronholm/anyio/issues/1297">#1297</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/44d0c93cc20079acbf38ba4dbed5ab9df323f153"><code>44d0c93</code></a> Fixed asyncio task group coroutine cleanup (<a href="https://redirect.github.com/agronholm/anyio/issues/1275">#1275</a>)</li> <li>Additional commits viewable in <a href="https://github.com/agronholm/anyio/compare/4.14.2...4.15.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b58044ac7a |
chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/cli (#8998)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.13.0 to 4.14.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agronholm/anyio/releases">anyio's releases</a>.</em></p> <blockquote> <h2>4.14.2</h2> <ul> <li>Changed <code>ByteReceiveStream.receive()</code> implementations to raise a <code>ValueError</code> when <code>max_bytes</code> is not a positive integer (<a href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting <code>float("inf")</code> when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (<code>value is math.inf</code>), so only the exact <code>math.inf</code> singleton was accepted, while every backend setter (using <code>math.isinf()</code>) accepts any positive infinity (<a href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>; PR by <a href="https://github.com/greymoth-jp"><code>@greymoth-jp</code></a>).</li> <li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker function writes enough data to <code>sys.stderr</code> to fill the (undrained) pipe buffer. The worker process now redirects <code>sys.stderr</code> to <code>os.devnull</code> as well, matching the documented behavior</li> <li>Fixed <code>TLSStream.wrap()</code> matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (<a href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li> <li>Fixed <code>anyio.open_process()</code> (and <code>run_process()</code>) ignoring the <code>extra_groups</code> argument, as it mistakenly passed the value of the <code>group</code> argument instead (<a href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li> <li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and <code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising <code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on the <code>trio</code> backend when there are no tokens available (<a href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li> <li>Fixed <code>CapacityLimiter</code> on the asyncio backend over-granting tokens (<code>borrowed_tokens</code> exceeding <code>total_tokens</code> and <code>available_tokens</code> going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises <code>WouldBlock</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>; PR by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a>)</li> <li>Fixed unnecessary CPU spin when delivering cancellation from <code>CancelScope</code> on asyncio under certain conditions, including improper cancel scope nesting (<a href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li> </ul> <h2>4.14.1</h2> <ul> <li>Fixed teardown of higher-scoped async fixtures failing on asyncio with <code>RuntimeError: Attempted to exit cancel scope in a different task than it was entered in</code> when an async test raise an outcome exception (e.g., <code>pytest.skip()</code>, <code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of <code>0</code> when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (<a href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>; PR by <a href="https://github.com/nyxst4ck"><code>@nyxst4ck</code></a>)</li> </ul> <h2>4.14.0</h2> <ul> <li> <p>Added support for Python 3.15</p> </li> <li> <p>Added an asynchronous implementation of the <code>itertools</code> module (<a href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>; PR by <a href="https://github.com/11kkw"><code>@11kkw</code></a>)</p> </li> <li> <p>Added the <code>local_port</code> parameter to <code>connect_tcp()</code> to allow binding to a specific local port before connecting (<a href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>; PR by <a href="https://github.com/nullwiz"><code>@nullwiz</code></a>)</p> </li> <li> <p>Added support for custom capacity limiters in async path and file I/O functions and classes</p> </li> <li> <p>Added the <code>create_task()</code> task group method for easier asyncio migration (returns a <code>TaskHandle</code>) (<a href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p> </li> <li> <p>Changed <code>TaskGroup.start_soon()</code> to return a <code>TaskHandle</code></p> </li> <li> <p>Added an option for <code>TaskGroup.start()</code> to return a <code>TaskHandle</code> (which then contains the start value in the <code>start_value</code> property)</p> </li> <li> <p>Added the <code>cancel()</code> convenience method to <code>TaskGroup</code> as a shortcut for cancelling the task group's cancel scope</p> </li> <li> <p>Improved the error message when a known backend is not installed to suggest the install command (<a href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Improved <code>anyio.Path</code> to preserve subclass types by returning <code>Self</code> in methods that return path objects (<a href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Changed the parameter type annotation in <code>anyio.Path.write_bytes()</code> to accept any <code>ReadableBuffer</code>, thus allowing it to accept <code>bytearray</code> and <code>memoryview</code> to match <code>pathlib.Path.write_bytes()</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>; PR by <a href="https://github.com/SAY-5"><code>@SAY-5</code></a>)</p> </li> <li> <p>Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:</p> <ul> <li><code>TaskGroup.start_soon()</code></li> <li><code>TaskGroup.start()</code></li> <li><code>anyio.from_thread.run()</code></li> </ul> <p>This reverts an earlier change from v3.7.0 which was made in error. (<a href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p> </li> <li> <p>Changed <code>anyio.run</code> to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (<a href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>; PR by <a href="https://github.com/gschaffner"><code>@gschaffner</code></a>)</p> </li> <li> <p>Changed several classes (and their subclasses) to have <code>__slots__</code> (with <code>__weakref__</code>):</p> <ul> <li><code>anyio.CancelScope</code></li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a> Bumped up the version</li> <li><a href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a> Fixed 100% CPU spin on cancel scope misuse (<a href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a> Fix CapacityLimiter over-granting tokens on asyncio (<a href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a> Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky</li> <li><a href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a> Relaxed timeouts to fix test flakiness</li> <li><a href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a> Fix test flakiness caused by slow callback duration logging</li> <li><a href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a> Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li> <li><a href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a> Pin setup-uv to a commit sha across downstream jobs (<a href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a> Fixed stderr writes in a worker subprocess causing a deadlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a> Fix flaky test_tcp_listener_same_port using a hardcoded port (<a href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li> <li>Additional commits viewable in <a href="https://github.com/agronholm/anyio/compare/4.13.0...4.14.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
daa514a988 |
chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/checkpoint-conformance (#8996)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.13.0 to 4.14.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agronholm/anyio/releases">anyio's releases</a>.</em></p> <blockquote> <h2>4.14.2</h2> <ul> <li>Changed <code>ByteReceiveStream.receive()</code> implementations to raise a <code>ValueError</code> when <code>max_bytes</code> is not a positive integer (<a href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting <code>float("inf")</code> when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (<code>value is math.inf</code>), so only the exact <code>math.inf</code> singleton was accepted, while every backend setter (using <code>math.isinf()</code>) accepts any positive infinity (<a href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>; PR by <a href="https://github.com/greymoth-jp"><code>@greymoth-jp</code></a>).</li> <li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker function writes enough data to <code>sys.stderr</code> to fill the (undrained) pipe buffer. The worker process now redirects <code>sys.stderr</code> to <code>os.devnull</code> as well, matching the documented behavior</li> <li>Fixed <code>TLSStream.wrap()</code> matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (<a href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li> <li>Fixed <code>anyio.open_process()</code> (and <code>run_process()</code>) ignoring the <code>extra_groups</code> argument, as it mistakenly passed the value of the <code>group</code> argument instead (<a href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li> <li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and <code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising <code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on the <code>trio</code> backend when there are no tokens available (<a href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li> <li>Fixed <code>CapacityLimiter</code> on the asyncio backend over-granting tokens (<code>borrowed_tokens</code> exceeding <code>total_tokens</code> and <code>available_tokens</code> going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises <code>WouldBlock</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>; PR by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a>)</li> <li>Fixed unnecessary CPU spin when delivering cancellation from <code>CancelScope</code> on asyncio under certain conditions, including improper cancel scope nesting (<a href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li> </ul> <h2>4.14.1</h2> <ul> <li>Fixed teardown of higher-scoped async fixtures failing on asyncio with <code>RuntimeError: Attempted to exit cancel scope in a different task than it was entered in</code> when an async test raise an outcome exception (e.g., <code>pytest.skip()</code>, <code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of <code>0</code> when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (<a href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>; PR by <a href="https://github.com/nyxst4ck"><code>@nyxst4ck</code></a>)</li> </ul> <h2>4.14.0</h2> <ul> <li> <p>Added support for Python 3.15</p> </li> <li> <p>Added an asynchronous implementation of the <code>itertools</code> module (<a href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>; PR by <a href="https://github.com/11kkw"><code>@11kkw</code></a>)</p> </li> <li> <p>Added the <code>local_port</code> parameter to <code>connect_tcp()</code> to allow binding to a specific local port before connecting (<a href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>; PR by <a href="https://github.com/nullwiz"><code>@nullwiz</code></a>)</p> </li> <li> <p>Added support for custom capacity limiters in async path and file I/O functions and classes</p> </li> <li> <p>Added the <code>create_task()</code> task group method for easier asyncio migration (returns a <code>TaskHandle</code>) (<a href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p> </li> <li> <p>Changed <code>TaskGroup.start_soon()</code> to return a <code>TaskHandle</code></p> </li> <li> <p>Added an option for <code>TaskGroup.start()</code> to return a <code>TaskHandle</code> (which then contains the start value in the <code>start_value</code> property)</p> </li> <li> <p>Added the <code>cancel()</code> convenience method to <code>TaskGroup</code> as a shortcut for cancelling the task group's cancel scope</p> </li> <li> <p>Improved the error message when a known backend is not installed to suggest the install command (<a href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Improved <code>anyio.Path</code> to preserve subclass types by returning <code>Self</code> in methods that return path objects (<a href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Changed the parameter type annotation in <code>anyio.Path.write_bytes()</code> to accept any <code>ReadableBuffer</code>, thus allowing it to accept <code>bytearray</code> and <code>memoryview</code> to match <code>pathlib.Path.write_bytes()</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>; PR by <a href="https://github.com/SAY-5"><code>@SAY-5</code></a>)</p> </li> <li> <p>Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:</p> <ul> <li><code>TaskGroup.start_soon()</code></li> <li><code>TaskGroup.start()</code></li> <li><code>anyio.from_thread.run()</code></li> </ul> <p>This reverts an earlier change from v3.7.0 which was made in error. (<a href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p> </li> <li> <p>Changed <code>anyio.run</code> to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (<a href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>; PR by <a href="https://github.com/gschaffner"><code>@gschaffner</code></a>)</p> </li> <li> <p>Changed several classes (and their subclasses) to have <code>__slots__</code> (with <code>__weakref__</code>):</p> <ul> <li><code>anyio.CancelScope</code></li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a> Bumped up the version</li> <li><a href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a> Fixed 100% CPU spin on cancel scope misuse (<a href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a> Fix CapacityLimiter over-granting tokens on asyncio (<a href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a> Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky</li> <li><a href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a> Relaxed timeouts to fix test flakiness</li> <li><a href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a> Fix test flakiness caused by slow callback duration logging</li> <li><a href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a> Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li> <li><a href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a> Pin setup-uv to a commit sha across downstream jobs (<a href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a> Fixed stderr writes in a worker subprocess causing a deadlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a> Fix flaky test_tcp_listener_same_port using a hardcoded port (<a href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li> <li>Additional commits viewable in <a href="https://github.com/agronholm/anyio/compare/4.13.0...4.14.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
022043a679 |
chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint (#8995)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.12.1 to 4.14.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agronholm/anyio/releases">anyio's releases</a>.</em></p> <blockquote> <h2>4.14.2</h2> <ul> <li>Changed <code>ByteReceiveStream.receive()</code> implementations to raise a <code>ValueError</code> when <code>max_bytes</code> is not a positive integer (<a href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting <code>float("inf")</code> when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (<code>value is math.inf</code>), so only the exact <code>math.inf</code> singleton was accepted, while every backend setter (using <code>math.isinf()</code>) accepts any positive infinity (<a href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>; PR by <a href="https://github.com/greymoth-jp"><code>@greymoth-jp</code></a>).</li> <li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker function writes enough data to <code>sys.stderr</code> to fill the (undrained) pipe buffer. The worker process now redirects <code>sys.stderr</code> to <code>os.devnull</code> as well, matching the documented behavior</li> <li>Fixed <code>TLSStream.wrap()</code> matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (<a href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li> <li>Fixed <code>anyio.open_process()</code> (and <code>run_process()</code>) ignoring the <code>extra_groups</code> argument, as it mistakenly passed the value of the <code>group</code> argument instead (<a href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li> <li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and <code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising <code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on the <code>trio</code> backend when there are no tokens available (<a href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li> <li>Fixed <code>CapacityLimiter</code> on the asyncio backend over-granting tokens (<code>borrowed_tokens</code> exceeding <code>total_tokens</code> and <code>available_tokens</code> going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises <code>WouldBlock</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>; PR by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a>)</li> <li>Fixed unnecessary CPU spin when delivering cancellation from <code>CancelScope</code> on asyncio under certain conditions, including improper cancel scope nesting (<a href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li> </ul> <h2>4.14.1</h2> <ul> <li>Fixed teardown of higher-scoped async fixtures failing on asyncio with <code>RuntimeError: Attempted to exit cancel scope in a different task than it was entered in</code> when an async test raise an outcome exception (e.g., <code>pytest.skip()</code>, <code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of <code>0</code> when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (<a href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>; PR by <a href="https://github.com/nyxst4ck"><code>@nyxst4ck</code></a>)</li> </ul> <h2>4.14.0</h2> <ul> <li> <p>Added support for Python 3.15</p> </li> <li> <p>Added an asynchronous implementation of the <code>itertools</code> module (<a href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>; PR by <a href="https://github.com/11kkw"><code>@11kkw</code></a>)</p> </li> <li> <p>Added the <code>local_port</code> parameter to <code>connect_tcp()</code> to allow binding to a specific local port before connecting (<a href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>; PR by <a href="https://github.com/nullwiz"><code>@nullwiz</code></a>)</p> </li> <li> <p>Added support for custom capacity limiters in async path and file I/O functions and classes</p> </li> <li> <p>Added the <code>create_task()</code> task group method for easier asyncio migration (returns a <code>TaskHandle</code>) (<a href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p> </li> <li> <p>Changed <code>TaskGroup.start_soon()</code> to return a <code>TaskHandle</code></p> </li> <li> <p>Added an option for <code>TaskGroup.start()</code> to return a <code>TaskHandle</code> (which then contains the start value in the <code>start_value</code> property)</p> </li> <li> <p>Added the <code>cancel()</code> convenience method to <code>TaskGroup</code> as a shortcut for cancelling the task group's cancel scope</p> </li> <li> <p>Improved the error message when a known backend is not installed to suggest the install command (<a href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Improved <code>anyio.Path</code> to preserve subclass types by returning <code>Self</code> in methods that return path objects (<a href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Changed the parameter type annotation in <code>anyio.Path.write_bytes()</code> to accept any <code>ReadableBuffer</code>, thus allowing it to accept <code>bytearray</code> and <code>memoryview</code> to match <code>pathlib.Path.write_bytes()</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>; PR by <a href="https://github.com/SAY-5"><code>@SAY-5</code></a>)</p> </li> <li> <p>Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:</p> <ul> <li><code>TaskGroup.start_soon()</code></li> <li><code>TaskGroup.start()</code></li> <li><code>anyio.from_thread.run()</code></li> </ul> <p>This reverts an earlier change from v3.7.0 which was made in error. (<a href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p> </li> <li> <p>Changed <code>anyio.run</code> to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (<a href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>; PR by <a href="https://github.com/gschaffner"><code>@gschaffner</code></a>)</p> </li> <li> <p>Changed several classes (and their subclasses) to have <code>__slots__</code> (with <code>__weakref__</code>):</p> <ul> <li><code>anyio.CancelScope</code></li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a> Bumped up the version</li> <li><a href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a> Fixed 100% CPU spin on cancel scope misuse (<a href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a> Fix CapacityLimiter over-granting tokens on asyncio (<a href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a> Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky</li> <li><a href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a> Relaxed timeouts to fix test flakiness</li> <li><a href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a> Fix test flakiness caused by slow callback duration logging</li> <li><a href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a> Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li> <li><a href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a> Pin setup-uv to a commit sha across downstream jobs (<a href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a> Fixed stderr writes in a worker subprocess causing a deadlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a> Fix flaky test_tcp_listener_same_port using a hardcoded port (<a href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li> <li>Additional commits viewable in <a href="https://github.com/agronholm/anyio/compare/4.12.1...4.14.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
d7b99cc3ab |
chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/sdk-py (#8994)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.12.1 to 4.14.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agronholm/anyio/releases">anyio's releases</a>.</em></p> <blockquote> <h2>4.14.2</h2> <ul> <li>Changed <code>ByteReceiveStream.receive()</code> implementations to raise a <code>ValueError</code> when <code>max_bytes</code> is not a positive integer (<a href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting <code>float("inf")</code> when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (<code>value is math.inf</code>), so only the exact <code>math.inf</code> singleton was accepted, while every backend setter (using <code>math.isinf()</code>) accepts any positive infinity (<a href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>; PR by <a href="https://github.com/greymoth-jp"><code>@greymoth-jp</code></a>).</li> <li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker function writes enough data to <code>sys.stderr</code> to fill the (undrained) pipe buffer. The worker process now redirects <code>sys.stderr</code> to <code>os.devnull</code> as well, matching the documented behavior</li> <li>Fixed <code>TLSStream.wrap()</code> matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (<a href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li> <li>Fixed <code>anyio.open_process()</code> (and <code>run_process()</code>) ignoring the <code>extra_groups</code> argument, as it mistakenly passed the value of the <code>group</code> argument instead (<a href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li> <li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and <code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising <code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on the <code>trio</code> backend when there are no tokens available (<a href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li> <li>Fixed <code>CapacityLimiter</code> on the asyncio backend over-granting tokens (<code>borrowed_tokens</code> exceeding <code>total_tokens</code> and <code>available_tokens</code> going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises <code>WouldBlock</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>; PR by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a>)</li> <li>Fixed unnecessary CPU spin when delivering cancellation from <code>CancelScope</code> on asyncio under certain conditions, including improper cancel scope nesting (<a href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li> </ul> <h2>4.14.1</h2> <ul> <li>Fixed teardown of higher-scoped async fixtures failing on asyncio with <code>RuntimeError: Attempted to exit cancel scope in a different task than it was entered in</code> when an async test raise an outcome exception (e.g., <code>pytest.skip()</code>, <code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of <code>0</code> when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (<a href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>; PR by <a href="https://github.com/nyxst4ck"><code>@nyxst4ck</code></a>)</li> </ul> <h2>4.14.0</h2> <ul> <li> <p>Added support for Python 3.15</p> </li> <li> <p>Added an asynchronous implementation of the <code>itertools</code> module (<a href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>; PR by <a href="https://github.com/11kkw"><code>@11kkw</code></a>)</p> </li> <li> <p>Added the <code>local_port</code> parameter to <code>connect_tcp()</code> to allow binding to a specific local port before connecting (<a href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>; PR by <a href="https://github.com/nullwiz"><code>@nullwiz</code></a>)</p> </li> <li> <p>Added support for custom capacity limiters in async path and file I/O functions and classes</p> </li> <li> <p>Added the <code>create_task()</code> task group method for easier asyncio migration (returns a <code>TaskHandle</code>) (<a href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p> </li> <li> <p>Changed <code>TaskGroup.start_soon()</code> to return a <code>TaskHandle</code></p> </li> <li> <p>Added an option for <code>TaskGroup.start()</code> to return a <code>TaskHandle</code> (which then contains the start value in the <code>start_value</code> property)</p> </li> <li> <p>Added the <code>cancel()</code> convenience method to <code>TaskGroup</code> as a shortcut for cancelling the task group's cancel scope</p> </li> <li> <p>Improved the error message when a known backend is not installed to suggest the install command (<a href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Improved <code>anyio.Path</code> to preserve subclass types by returning <code>Self</code> in methods that return path objects (<a href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Changed the parameter type annotation in <code>anyio.Path.write_bytes()</code> to accept any <code>ReadableBuffer</code>, thus allowing it to accept <code>bytearray</code> and <code>memoryview</code> to match <code>pathlib.Path.write_bytes()</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>; PR by <a href="https://github.com/SAY-5"><code>@SAY-5</code></a>)</p> </li> <li> <p>Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:</p> <ul> <li><code>TaskGroup.start_soon()</code></li> <li><code>TaskGroup.start()</code></li> <li><code>anyio.from_thread.run()</code></li> </ul> <p>This reverts an earlier change from v3.7.0 which was made in error. (<a href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p> </li> <li> <p>Changed <code>anyio.run</code> to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (<a href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>; PR by <a href="https://github.com/gschaffner"><code>@gschaffner</code></a>)</p> </li> <li> <p>Changed several classes (and their subclasses) to have <code>__slots__</code> (with <code>__weakref__</code>):</p> <ul> <li><code>anyio.CancelScope</code></li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a> Bumped up the version</li> <li><a href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a> Fixed 100% CPU spin on cancel scope misuse (<a href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a> Fix CapacityLimiter over-granting tokens on asyncio (<a href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a> Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky</li> <li><a href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a> Relaxed timeouts to fix test flakiness</li> <li><a href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a> Fix test flakiness caused by slow callback duration logging</li> <li><a href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a> Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li> <li><a href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a> Pin setup-uv to a commit sha across downstream jobs (<a href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a> Fixed stderr writes in a worker subprocess causing a deadlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a> Fix flaky test_tcp_listener_same_port using a hardcoded port (<a href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li> <li>Additional commits viewable in <a href="https://github.com/agronholm/anyio/compare/4.12.1...4.14.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b19edd783b |
chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint-sqlite (#8993)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.12.1 to 4.14.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agronholm/anyio/releases">anyio's releases</a>.</em></p> <blockquote> <h2>4.14.2</h2> <ul> <li>Changed <code>ByteReceiveStream.receive()</code> implementations to raise a <code>ValueError</code> when <code>max_bytes</code> is not a positive integer (<a href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting <code>float("inf")</code> when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (<code>value is math.inf</code>), so only the exact <code>math.inf</code> singleton was accepted, while every backend setter (using <code>math.isinf()</code>) accepts any positive infinity (<a href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>; PR by <a href="https://github.com/greymoth-jp"><code>@greymoth-jp</code></a>).</li> <li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker function writes enough data to <code>sys.stderr</code> to fill the (undrained) pipe buffer. The worker process now redirects <code>sys.stderr</code> to <code>os.devnull</code> as well, matching the documented behavior</li> <li>Fixed <code>TLSStream.wrap()</code> matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (<a href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li> <li>Fixed <code>anyio.open_process()</code> (and <code>run_process()</code>) ignoring the <code>extra_groups</code> argument, as it mistakenly passed the value of the <code>group</code> argument instead (<a href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li> <li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and <code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising <code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on the <code>trio</code> backend when there are no tokens available (<a href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li> <li>Fixed <code>CapacityLimiter</code> on the asyncio backend over-granting tokens (<code>borrowed_tokens</code> exceeding <code>total_tokens</code> and <code>available_tokens</code> going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises <code>WouldBlock</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>; PR by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a>)</li> <li>Fixed unnecessary CPU spin when delivering cancellation from <code>CancelScope</code> on asyncio under certain conditions, including improper cancel scope nesting (<a href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li> </ul> <h2>4.14.1</h2> <ul> <li>Fixed teardown of higher-scoped async fixtures failing on asyncio with <code>RuntimeError: Attempted to exit cancel scope in a different task than it was entered in</code> when an async test raise an outcome exception (e.g., <code>pytest.skip()</code>, <code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of <code>0</code> when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (<a href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>; PR by <a href="https://github.com/nyxst4ck"><code>@nyxst4ck</code></a>)</li> </ul> <h2>4.14.0</h2> <ul> <li> <p>Added support for Python 3.15</p> </li> <li> <p>Added an asynchronous implementation of the <code>itertools</code> module (<a href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>; PR by <a href="https://github.com/11kkw"><code>@11kkw</code></a>)</p> </li> <li> <p>Added the <code>local_port</code> parameter to <code>connect_tcp()</code> to allow binding to a specific local port before connecting (<a href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>; PR by <a href="https://github.com/nullwiz"><code>@nullwiz</code></a>)</p> </li> <li> <p>Added support for custom capacity limiters in async path and file I/O functions and classes</p> </li> <li> <p>Added the <code>create_task()</code> task group method for easier asyncio migration (returns a <code>TaskHandle</code>) (<a href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p> </li> <li> <p>Changed <code>TaskGroup.start_soon()</code> to return a <code>TaskHandle</code></p> </li> <li> <p>Added an option for <code>TaskGroup.start()</code> to return a <code>TaskHandle</code> (which then contains the start value in the <code>start_value</code> property)</p> </li> <li> <p>Added the <code>cancel()</code> convenience method to <code>TaskGroup</code> as a shortcut for cancelling the task group's cancel scope</p> </li> <li> <p>Improved the error message when a known backend is not installed to suggest the install command (<a href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Improved <code>anyio.Path</code> to preserve subclass types by returning <code>Self</code> in methods that return path objects (<a href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Changed the parameter type annotation in <code>anyio.Path.write_bytes()</code> to accept any <code>ReadableBuffer</code>, thus allowing it to accept <code>bytearray</code> and <code>memoryview</code> to match <code>pathlib.Path.write_bytes()</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>; PR by <a href="https://github.com/SAY-5"><code>@SAY-5</code></a>)</p> </li> <li> <p>Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:</p> <ul> <li><code>TaskGroup.start_soon()</code></li> <li><code>TaskGroup.start()</code></li> <li><code>anyio.from_thread.run()</code></li> </ul> <p>This reverts an earlier change from v3.7.0 which was made in error. (<a href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p> </li> <li> <p>Changed <code>anyio.run</code> to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (<a href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>; PR by <a href="https://github.com/gschaffner"><code>@gschaffner</code></a>)</p> </li> <li> <p>Changed several classes (and their subclasses) to have <code>__slots__</code> (with <code>__weakref__</code>):</p> <ul> <li><code>anyio.CancelScope</code></li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a> Bumped up the version</li> <li><a href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a> Fixed 100% CPU spin on cancel scope misuse (<a href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a> Fix CapacityLimiter over-granting tokens on asyncio (<a href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a> Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky</li> <li><a href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a> Relaxed timeouts to fix test flakiness</li> <li><a href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a> Fix test flakiness caused by slow callback duration logging</li> <li><a href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a> Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li> <li><a href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a> Pin setup-uv to a commit sha across downstream jobs (<a href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a> Fixed stderr writes in a worker subprocess causing a deadlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a> Fix flaky test_tcp_listener_same_port using a hardcoded port (<a href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li> <li>Additional commits viewable in <a href="https://github.com/agronholm/anyio/compare/4.12.1...4.14.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
c81c13533e |
chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/langgraph (#8958)
Bumps [soupsieve](https://github.com/facelessuser/soupsieve) from 2.8.4 to 2.9. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/facelessuser/soupsieve/releases">soupsieve's releases</a>.</em></p> <blockquote> <h2>2.9</h2> <ul> <li><strong>NEW</strong>: Drop Python 3.9 support.</li> <li><strong>NEW</strong>: Lazy compile selector patterns to improve initial import speed.</li> <li><strong>FIX</strong>: Correct <code>:nth-child</code>/<code>:nth-of-type</code> (and <code>-last-</code> variants) for <code>An+B</code> values whose sequence steps onto index 0 or onto the last child (e.g. <code>:nth-child(2n-2)</code>, <code>:nth-child(n-1)</code>, <code>:nth-child(n+5)</code>), which previously matched the wrong elements or nothing at all (<a href="https://github.com/gaoflow"><code>@gaoflow</code></a>).</li> <li><strong>FIX</strong>: More efficient CSS ID matching (<a href="https://github.com/kaimandalic"><code>@kaimandalic</code></a>).</li> <li><strong>FIX</strong>: Fix inefficient trimming of comments and white space (<a href="https://github.com/kaimandalic"><code>@kaimandalic</code></a>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004"><code>8763f91</code></a> Format changelog message</li> <li><a href="https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda"><code>cf198fc</code></a> Fix inefficient trimming of comments and white space</li> <li><a href="https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef"><code>ce44e49</code></a> Merge commit from fork</li> <li><a href="https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19"><code>751c57b</code></a> Fix :nth-child/:nth-of-type matching for An+B index boundaries (<a href="https://redirect.github.com/facelessuser/soupsieve/issues/297">#297</a>)</li> <li><a href="https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b"><code>08e9ede</code></a> Drop Python 3.9</li> <li><a href="https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81"><code>d6e6830</code></a> Rework selector mapping</li> <li><a href="https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3"><code>d2d1581</code></a> Utilize property for accessing lazy regular expression pattern</li> <li><a href="https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d"><code>b8701de</code></a> Build patterns and regexes lazily in css_parser (<a href="https://redirect.github.com/facelessuser/soupsieve/issues/296">#296</a>)</li> <li>See full diff in <a href="https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
448a763779 |
feat(langgraph): add response_schema to interrupt() (#8886)
Adds an optional keyword-only `response_schema` to `interrupt()`, carried on `Interrupt.response_schema` as JSON Schema so clients (LangGraph Studio first) can render a typed form for the resume value instead of a free-form JSON box. Default `None`, so nothing changes for existing graphs. - Accepts a JSON Schema dict (passed through, not validated) or a Pydantic model / `TypedDict` / dataclass, converted with `TypeAdapter.json_schema()`. For those, the resume value is validated and the validated object is what `interrupt()` returns; an invalid value raises from the node before it is committed, so the next resume works. - Additive on the `stream_mode="debug"` payload: interrupt dicts gain `response_schema` (it is a dataclass field, serialized with `asdict`). - `libs/sdk-py`: mirrors the field on the `Interrupt` TypedDict as `NotRequired`; the server omits the key when no schema was given. JS counterpart: langchain-ai/langgraphjs#2824. Verified: new tests parametrized across every checkpointer backend (schema kinds, coercion, invalid resume) plus the full `libs/langgraph` suite and downstream `prebuilt`, `cli`, `sdk-py`; round-tripped end to end through the agent server with this branch installed. |
||
|
|
e539ac122f |
chore(deps): fix vulnerable dev dependencies (#8449)
## Summary Patch both `js-yaml` release lines in `libs/cli/js-examples` for GHSA-2883-xcg3-v3hh: Jest's transitive copy to 3.15.2 and ESLint's to 4.3.2. Updates the existing fix rather than opening a duplicate; no runtime dependencies added and no major-version overrides. Addresses Dependabot alerts [#398](https://github.com/langchain-ai/langgraph/security/dependabot/398) and [#397](https://github.com/langchain-ai/langgraph/security/dependabot/397). These are real vulnerable versions in example development tooling; patch rather than dismiss. Alerts remain open until this reaches `main` and GitHub rescans. ## Verification - [x] Yarn 1.22.22 regenerated the lockfile with lifecycle scripts disabled; diff limited to the two js-yaml entries and scoped resolutions. - [x] `yarn install --frozen-lockfile --ignore-scripts --force --non-interactive` in `libs/cli/js-examples`. - [x] `yarn why js-yaml`: ESLint 4.3.2 and Jest/Istanbul 3.15.2. - [x] Resolved versions checked against freshly retrieved GitHub advisory patched versions for both alerts. - [x] `yarn format:check` and `git diff --check`. - [ ] Build fails in unchanged `tests/graph.int.test.ts:7`: `input` is not a valid update property (also recorded in the earlier PR verification). - [ ] Unit-test script fails because it uses Jest's removed `--testPathPattern` option; Jest requires `--testPathPatterns`. - [ ] Lint fails because ESLint 10 requires `eslint.config.*`, which this example lacks. The build/test/lint configuration issues are outside this scoped dependency patch and remain unresolved. No full test-pass claim. --------- Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com> |
||
|
|
ff4529380d |
chore(deps): bump httpx2 from 2.10.0 to 2.12.0 in /libs/cli (#8863)
Bumps [httpx2](https://github.com/pydantic/httpx2) from 2.10.0 to 2.12.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pydantic/httpx2/releases">httpx2's releases</a>.</em></p> <blockquote> <h2>v2.12.0</h2> <h2>Highlights</h2> <h3>🛡️ Bounded response decompression</h3> <p><code>httpx2</code> now decodes <code>gzip</code>, <code>deflate</code>, Brotli, and Zstandard responses incrementally. Each decode step emits at most 1 MiB, so streaming a highly compressed response no longer requires materializing an entire inflated network chunk in memory (<a href="https://redirect.github.com/pydantic/httpx2/pull/1126">pydantic/httpx2#1126</a>).</p> <h3>📦 Shared Zstandard API</h3> <p>Python 3.13 and earlier now use <code>backports.zstd</code>, which provides the same bounded incremental decompression API as <code>compression.zstd</code> on Python 3.14 and later (<a href="https://redirect.github.com/pydantic/httpx2/pull/1146">pydantic/httpx2#1146</a>).</p> <h2>httpx2</h2> <h3>Changed</h3> <ul> <li>Use <code>backports.zstd</code> for Zstandard decoding on Python 3.13 and earlier by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1146">pydantic/httpx2#1146</a></li> </ul> <h3>Fixed</h3> <ul> <li>Bound peak memory while streaming compressed responses and close response streams when decoding fails by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1126">pydantic/httpx2#1126</a></li> </ul> <h2>httpcore2</h2> <p>No changes since <code>2.11.0</code>. Version bumped to stay in lockstep with <code>httpx2</code>.</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/pydantic/httpx2/compare/v2.11.0...v2.12.0">https://github.com/pydantic/httpx2/compare/v2.11.0...v2.12.0</a></p> <h2>v2.11.0</h2> <h2>Highlights</h2> <h3>🌐 Public origin API</h3> <p><code>httpx2</code> now includes an immutable and hashable <code>Origin</code> value object, available through <code>URL.origin</code>. It provides normalized scheme, host, and effective port comparisons without including URL paths, queries, fragments, or credentials (<a href="https://redirect.github.com/pydantic/httpx2/pull/1134">pydantic/httpx2#1134</a>).</p> <h3>🛠️ Request compatibility and validation</h3> <ul> <li>Explicit <code>Transfer-Encoding</code> headers now take precedence over body-derived <code>Content-Length</code> headers (<a href="https://redirect.github.com/pydantic/httpx2/pull/1137">pydantic/httpx2#1137</a>).</li> <li>Deprecated status code aliases are available again (<a href="https://redirect.github.com/pydantic/httpx2/pull/1135">pydantic/httpx2#1135</a>).</li> <li>Multipart part headers are validated before serialization (<a href="https://redirect.github.com/pydantic/httpx2/pull/1142">pydantic/httpx2#1142</a>).</li> </ul> <h2>httpx2</h2> <h3>Added</h3> <ul> <li>Add the public <code>Origin</code> value object and <code>URL.origin</code> property by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1134">pydantic/httpx2#1134</a></li> </ul> <h3>Changed</h3> <ul> <li>Require Brotli 1.2.0 or later for the <code>brotli</code> extra by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1141">pydantic/httpx2#1141</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md">httpx2's changelog</a>.</em></p> <blockquote> <h2>2.12.0 (August 18th, 2026)</h2> <h3>Changed</h3> <ul> <li>Use <code>backports.zstd</code> for Zstandard decoding on Python 3.13 and earlier. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1146">#1146</a>)</li> </ul> <h3>Fixed</h3> <ul> <li>Bound peak memory while streaming compressed responses and close response streams when decoding fails. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1126">#1126</a>)</li> </ul> <h2>2.11.0 (August 18th, 2026)</h2> <h3>Added</h3> <ul> <li>Add the public <code>Origin</code> value object and <code>URL.origin</code> property for normalized, hashable origin comparisons. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1134">#1134</a>)</li> </ul> <h3>Changed</h3> <ul> <li>Require Brotli 1.2.0 or later for the <code>brotli</code> extra. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1141">#1141</a>)</li> </ul> <h3>Fixed</h3> <ul> <li>Restore deprecated status code aliases. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1135">#1135</a>)</li> <li>Extract HTTP/2 release notes from changelog headings correctly. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1136">#1136</a>)</li> <li>Respect explicit <code>Transfer-Encoding</code> headers and expose buffered request body lengths to WSGI applications. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1137">#1137</a>)</li> <li>Validate multipart part header names and values before serialization. (<a href="https://redirect.github.com/pydantic/httpx2/pull/1142">#1142</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pydantic/httpx2/commit/71ae23be5448f859c2b4e21d9972ddfa7b8d759d"><code>71ae23b</code></a> Version 2.12.0 (<a href="https://redirect.github.com/pydantic/httpx2/issues/1147">#1147</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/4fd0c70a3f207c618b145934792f791bccfb39f8"><code>4fd0c70</code></a> Decode compressed response bodies incrementally (<a href="https://redirect.github.com/pydantic/httpx2/issues/1126">#1126</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/d588e528a11eb20323031ee571fadc668bb81b3f"><code>d588e52</code></a> Use <code>backports.zstd</code> on Python 3.13 and earlier (<a href="https://redirect.github.com/pydantic/httpx2/issues/1146">#1146</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/344589da2a992f7e5a0c25c68cc78c25ec6d70bd"><code>344589d</code></a> Version 2.11.0 (<a href="https://redirect.github.com/pydantic/httpx2/issues/1143">#1143</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/de96d810ee4e309d118982fe7084a46a2bcd600d"><code>de96d81</code></a> Validate multipart part headers (<a href="https://redirect.github.com/pydantic/httpx2/issues/1142">#1142</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/51c32698ce029140cb69a26921d017e3edda80fa"><code>51c3269</code></a> Require brotli 1.2.0 in the brotli extra (<a href="https://redirect.github.com/pydantic/httpx2/issues/1141">#1141</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/829b93a2393212996f613e635261f777d9ec6eab"><code>829b93a</code></a> Respect explicit Transfer-Encoding headers (<a href="https://redirect.github.com/pydantic/httpx2/issues/1137">#1137</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/4fa6c8ee96fb79035c6820e4f44a10b6262d9c9f"><code>4fa6c8e</code></a> Fix changelog extraction regex for H2 release headings (<a href="https://redirect.github.com/pydantic/httpx2/issues/1136">#1136</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/8a6f37063514ee2a2601607c20be72667fdfa3be"><code>8a6f370</code></a> Restore deprecated status code aliases (<a href="https://redirect.github.com/pydantic/httpx2/issues/1135">#1135</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/d03f1ec6a1a323f951a8c21cd14f9c02f2d1e855"><code>d03f1ec</code></a> Add public Origin API (<a href="https://redirect.github.com/pydantic/httpx2/issues/1134">#1134</a>)</li> <li>See full diff in <a href="https://github.com/pydantic/httpx2/compare/v2.10.0...v2.12.0">compare view</a></li> </ul> </details> <br /> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com> |
||
|
|
c0b884e6d8 |
chore(deps): bump js-yaml from 4.3.1 to 4.3.2 in /libs/cli/js-monorepo-example (#8867)
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.3.1 to 4.3.2. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md">js-yaml's changelog</a>.</em></p> <blockquote> <h2>4.3.2 - 2026-08-26</h2> <h3>Changed</h3> <ul> <li>[backport] Hard-limit merge sequence size to 100.</li> </ul> <h3>Security</h3> <ul> <li>[backport] Count empty mappings in merge sequences toward <code>maxTotalMergeKeys</code> to limit CPU usage, <a href="https://redirect.github.com/nodeca/js-yaml/issues/797">#797</a>.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191"><code>79ca68d</code></a> 4.3.2 released</li> <li><a href="https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b"><code>d90b661</code></a> Backport merge limits from v5.4.1</li> <li>See full diff in <a href="https://github.com/nodeca/js-yaml/compare/4.3.1...4.3.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
3299a1f563 |
chore(deps): bump httpcore2 from 2.5.0 to 2.10.0 in /libs/cli (#8864)
Bumps [httpcore2](https://github.com/pydantic/httpx2) from 2.5.0 to 2.10.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pydantic/httpx2/releases">httpcore2's releases</a>.</em></p> <blockquote> <h2>v2.10.0</h2> <h2>Highlights</h2> <h3>🚀 Performance and memory improvements</h3> <ul> <li>Sending large HTTP/2 request bodies no longer copies the body quadratically - sending a 256 MiB body went from ~36s to under 0.1s (<a href="https://redirect.github.com/pydantic/httpx2/pull/1127">pydantic/httpx2#1127</a>).</li> <li>SSE parsing is up to 35x faster on highly fragmented streams (<a href="https://redirect.github.com/pydantic/httpx2/pull/1117">pydantic/httpx2#1117</a>).</li> <li>Cookie extraction is now skipped for responses without a <code>Set-Cookie</code> header, making typical requests roughly 8% faster (<a href="https://redirect.github.com/pydantic/httpx2/pull/1107">pydantic/httpx2#1107</a>).</li> </ul> <h3>🕸️ WebAssembly / Emscripten support</h3> <p><code>httpx2</code> now runs on Pyodide / Emscripten, using a JavaScript <code>fetch</code>-based transport defined in <code>httpx2-jsfetch</code> (<a href="https://redirect.github.com/pydantic/httpx2/pull/1119">pydantic/httpx2#1119</a>, <a href="https://redirect.github.com/pydantic/httpx2/pull/1114">pydantic/httpx2#1114</a>). Thanks <a href="https://github.com/hoodmane"><code>@hoodmane</code></a>!</p> <h2>httpx2</h2> <h3>Added</h3> <ul> <li>Add support for running on WebAssembly / Emscripten via Pyodide by <a href="https://github.com/hoodmane"><code>@hoodmane</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1119">pydantic/httpx2#1119</a></li> <li>Add <code>max_event_size</code> to cap SSE event buffering by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1071">pydantic/httpx2#1071</a></li> <li>Add RFC 9110 status code constants by <a href="https://github.com/mbeijen"><code>@mbeijen</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1069">pydantic/httpx2#1069</a></li> <li>Add support for Python 3.15 by <a href="https://github.com/hugovk"><code>@hugovk</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1090">pydantic/httpx2#1090</a></li> </ul> <h3>Changed</h3> <ul> <li>Improve SSE chunk buffering performance by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1117">pydantic/httpx2#1117</a></li> <li>Skip cookie extraction without <code>Set-Cookie</code> by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1107">pydantic/httpx2#1107</a></li> <li>Return <code>str | None</code> instead of <code>Any</code> from <code>Headers.get</code> by <a href="https://github.com/ItsDrike"><code>@ItsDrike</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1121">pydantic/httpx2#1121</a></li> </ul> <h3>Fixed</h3> <ul> <li>Enforce WebSocket max message size across fragments by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1085">pydantic/httpx2#1085</a></li> <li>Ignore unsolicited and duplicate Pong frames by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1122">pydantic/httpx2#1122</a></li> </ul> <h2>httpcore2</h2> <h3>Added</h3> <ul> <li>Add support for Python 3.15 by <a href="https://github.com/hugovk"><code>@hugovk</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1090">pydantic/httpx2#1090</a></li> </ul> <h3>Changed</h3> <ul> <li>Avoid quadratic copying when sending large HTTP/2 request bodies by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1127">pydantic/httpx2#1127</a></li> </ul> <h3>Fixed</h3> <ul> <li>Propagate the original exception instead of raising <code>KeyError</code> when an HTTP/2 stream fails by <a href="https://github.com/yhay81"><code>@yhay81</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1093">pydantic/httpx2#1093</a></li> <li>Start TLS for the <code>wss</code> scheme in SOCKS5 proxy connections by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/pydantic/httpx2/pull/1104">pydantic/httpx2#1104</a></li> </ul> <h2>🙏 New Contributors</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pydantic/httpx2/commit/a966320e75477b8c55ee78fdb8f57ead6a574cb0"><code>a966320</code></a> Version 2.10.0 (<a href="https://redirect.github.com/pydantic/httpx2/issues/1129">#1129</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/586f968f5510aa4d3b7edd1f1b039684c42945ee"><code>586f968</code></a> Avoid quadratic copying when sending large HTTP/2 request bodies (<a href="https://redirect.github.com/pydantic/httpx2/issues/1127">#1127</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/dee1d1ace3021404d0aa255957821eda97c94c43"><code>dee1d1a</code></a> Return <code>str | None</code> instead of <code>Any</code> from <code>Headers.get</code> (<a href="https://redirect.github.com/pydantic/httpx2/issues/1121">#1121</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/dec24ad57d1d337de7de23c011eb566a145e7b40"><code>dec24ad</code></a> Use <code>httpx2-jsfetch</code> on Emscripten (<a href="https://redirect.github.com/pydantic/httpx2/issues/1119">#1119</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/454b8b2197f62d699ff3ad762917643926b4da77"><code>454b8b2</code></a> Ignore unsolicited and duplicate Pong frames (<a href="https://redirect.github.com/pydantic/httpx2/issues/1122">#1122</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414"><code>cbfc0e0</code></a> Improve SSE chunk buffering performance (<a href="https://redirect.github.com/pydantic/httpx2/issues/1117">#1117</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/ad141d876c7d3c3f58555cbb0a178ec2c1f15b51"><code>ad141d8</code></a> Refactor SSE parser coordination (<a href="https://redirect.github.com/pydantic/httpx2/issues/1118">#1118</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/e0b01245e42d2091034ee9455cbb068bc0d6c0c6"><code>e0b0124</code></a> Make <code>_client</code> depend on the <code>_transports</code> package instead of its submodules ...</li> <li><a href="https://github.com/pydantic/httpx2/commit/e52f963c62f397f225c8d29573aedbe5ae613906"><code>e52f963</code></a> Skip dependencies not needed on Emscripten (<a href="https://redirect.github.com/pydantic/httpx2/issues/1114">#1114</a>)</li> <li><a href="https://github.com/pydantic/httpx2/commit/5d9eedc98186c612d0e426df417f78f6ec21e9ca"><code>5d9eedc</code></a> Add <code>max_event_size</code> to cap SSE event buffering (<a href="https://redirect.github.com/pydantic/httpx2/issues/1071">#1071</a>)</li> <li>Additional commits viewable in <a href="https://github.com/pydantic/httpx2/compare/v2.5.0...v2.10.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
0199b519e1 |
fix(cli): clarify missing deploy config (#8854)
Shows an actionable, docs-linked error when `langgraph deploy` is run without a `langgraph.json` instead of exposing a traceback. |
||
|
|
81bf17b231 | fix(langgraph): type undeclared v3 stream projections (#8596) | ||
|
|
11738d83db |
chore(langgraph): bump mistune to 3.3.4 (#8804)
Updates the `libs/langgraph/uv.lock` development dependency from Mistune 3.3.0 to 3.3.4, resolving GHSA-6m44-fpc8-c3rq (Dependabot #389). The change is scoped to the affected lockfile. Validation: `uv lock --project libs/langgraph --locked`. Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com> |
||
|
|
1983e60971 |
chore(deps): bump browserslist from 4.28.1 to 4.28.8 in /libs/cli/js-examples (#8797)
Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.28.1 to 4.28.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/browserslist/browserslist/releases">browserslist's releases</a>.</em></p> <blockquote> <h2>4.28.8</h2> <ul> <li>Fixed <code>including kaios</code> in baseline queries (by <a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a>).</li> </ul> <h2>4.28.7</h2> <ul> <li>Improved parsing performance.</li> <li>Fixed unbounded memory growth (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> <li>Fixed prototype write issue (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> </ul> <h2>4.28.6</h2> <ul> <li>Fixed Electron version queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.5</h2> <ul> <li>Fixed <code>></code> and <code>>=</code> queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.4</h2> <ul> <li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li> </ul> <h2>4.28.3</h2> <ul> <li>Fixed baseline query case-insensitivity (by <a href="https://github.com/swwind"><code>@swwind</code></a>).</li> </ul> <h2>4.28.2</h2> <ul> <li>Fix prototype pollution (by <a href="https://github.com/chluo1997"><code>@chluo1997</code></a>).</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md">browserslist's changelog</a>.</em></p> <blockquote> <h2>4.28.8</h2> <ul> <li>Fixed <code>including kaios</code> in baseline queries (by <a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a>).</li> </ul> <h2>4.28.7</h2> <ul> <li>Improved parsing performance.</li> <li>Fixed unbounded memory growth (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> <li>Fixed prototype write issue (by <a href="https://github.com/alanturing881"><code>@alanturing881</code></a>).</li> </ul> <h2>4.28.6</h2> <ul> <li>Fixed Electron version queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.5</h2> <ul> <li>Fixed <code>></code> and <code>>=</code> queries (by <a href="https://github.com/spokodev"><code>@spokodev</code></a>).</li> </ul> <h2>4.28.4</h2> <ul> <li>Fixed <code>SyntaxError</code> regression of 4.28.3.</li> </ul> <h2>4.28.3</h2> <ul> <li>Fixed baseline query case-insensitivity (by <a href="https://github.com/swwind"><code>@swwind</code></a>).</li> </ul> <h2>4.28.2</h2> <ul> <li>Fix prototype pollution (by <a href="https://github.com/chluo1997"><code>@chluo1997</code></a>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad"><code>f2f2e6c</code></a> Release 4.28.8 version</li> <li><a href="https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377"><code>d0787c8</code></a> Update dependencies</li> <li><a href="https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f"><code>fcf8fa9</code></a> Merge pull request <a href="https://redirect.github.com/browserslist/browserslist/issues/939">#939</a> from Jaybhade/fix/baseline-kaios-without-downstream</li> <li><a href="https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c"><code>57ecd64</code></a> fix: support "including kaios" without downstream</li> <li><a href="https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1"><code>093a0f6</code></a> Update EM banner</li> <li><a href="https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276"><code>b637868</code></a> Release 4.28.7 version</li> <li><a href="https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46"><code>313f465</code></a> Update dependencies</li> <li><a href="https://github.com/browserslist/browserslist/commit/c935c5a206f8b13db8846818bc03643e147dcbdf"><code>c935c5a</code></a> Fix regexp performance</li> <li><a href="https://github.com/browserslist/browserslist/commit/d7e9e653cb53399065943f59f0b3063987b0a008"><code>d7e9e65</code></a> Rewrite structure parsing to make it always fast</li> <li><a href="https://github.com/browserslist/browserslist/commit/ec4a55efd76bdfa506ec7ce4fea1691559e9ca8f"><code>ec4a55e</code></a> Fix import order</li> <li>Additional commits viewable in <a href="https://github.com/browserslist/browserslist/compare/4.28.1...4.28.8">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for browserslist since your current version.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langgraph/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |