Skip to content

Update all non-major dependencies - #1587

Merged
danlamanna merged 1 commit into
masterfrom
renovate/all-minor-patch
Sep 30, 2026
Merged

danlamanna merged 1 commit into
masterfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
daisyui (source) 5.7.9 → 5.7.46 age confidence dependencies patch 5.7.47
django (changelog) ==5.2.16 → ==5.2.17 age confidence project.dependencies patch
django-allauth (changelog) ==65.18.0 → ==65.19.4 age confidence project.dependencies minor 65.19.5
django-auth-style ==0.15.0 → ==0.15.1 age confidence project.dependencies patch
django-cachalot ==2.9.0 → ==2.9.1 age confidence project.dependencies patch
django-debug-toolbar (changelog) ==7.0.0 → ==7.1.1 age confidence project.optional-dependencies minor
django-resonant-settings ==0.51.1 → ==0.52.1 age confidence project.dependencies minor
django-resonant-utils ==0.19.0 → ==0.20.0 age confidence project.optional-dependencies minor
django-resonant-utils ==0.19.0 → ==0.20.0 age confidence project.dependencies minor
djangorestframework (changelog) ==3.18.0 → ==3.18.1 age confidence project.dependencies patch
elasticsearch ==9.4.1 → ==9.5.1 age confidence project.dependencies minor
elasticsearch (source) 9.4.4 → 9.5.2 age confidence service minor 9.5.3
elasticsearch (source) 9.4.4 → 9.5.2 age confidence minor 9.5.3
google-analytics-data (source) ==0.23.0 → ==0.23.2 age confidence project.dependencies patch
gunicorn (changelog) ==26.0.0 → ==26.2.0 age confidence project.dependencies minor
hatchling (source, changelog) ==1.31.0 → ==1.32.4 age confidence build-system.requires minor
ipython ==9.16.0 → ==9.17.1 age confidence project.optional-dependencies minor
numpy (changelog) ==2.5.1 → ==2.5.3 age confidence project.dependencies patch
orjson (changelog) ==3.11.9 → ==3.12.0 age confidence project.dependencies minor
pandas ==3.0.5 → ==3.0.6 age confidence project.dependencies patch
psycopg (changelog) ==3.3.4 → ==3.3.6 age confidence project.dependencies patch
pydantic (changelog) ==2.13.4 → ==2.13.5 age confidence project.dependencies patch
sentry-sdk (changelog) ==2.66.1 → ==2.70.0 age confidence project.dependencies minor 2.71.0

Release Notes

saadeghi/daisyui (daisyui)

v5.7.46

Compare Source

Bug Fixes
  • adjust tooltip tail position for themes with more radius (#​4759) (cc43e58)

v5.7.45

Compare Source

Bug Fixes

v5.7.44

Compare Source

Bug Fixes

v5.7.43

Compare Source

Bug Fixes

v5.7.42

Compare Source

Bug Fixes
  • disabled style for input, select, textarea and file-input (#​4769) (a0ca2b8)

v5.7.41

Compare Source

Bug Fixes

v5.7.40

Compare Source

Bug Fixes

v5.7.39

Compare Source

Bug Fixes
  • allow Firefox Android to use diff by tap because Firefox Android ignores CSS resize and cannot drag(#​4763) (ac97999)

v5.7.38

Compare Source

Bug Fixes

v5.7.37

Compare Source

Bug Fixes

v5.7.36

Compare Source

Bug Fixes

v5.7.35

Compare Source

Bug Fixes

v5.7.34

Compare Source

Bug Fixes

v5.7.33

Compare Source

Bug Fixes

v5.7.32

Compare Source

Bug Fixes

v5.7.28

Compare Source

Bug Fixes

v5.7.27

Compare Source

Bug Fixes

v5.7.26

Compare Source

Bug Fixes

v5.7.25

Compare Source

Bug Fixes
  • checkbox - add style for aria-checked="mixed" like :indeterminate (#​4713) (5e5b8b4)

v5.7.24

Compare Source

Bug Fixes

v5.7.23

Compare Source

Bug Fixes
  • menu-paged summary hides children (badge, icon, etc) when details is open (#​4710) (4929505)

v5.7.22

Compare Source

Bug Fixes

v5.7.21

Compare Source

Bug Fixes

v5.7.20

Compare Source

Bug Fixes
  • text-rotate - selector targets direct children, to avoid style leaking (#​4682) (44856dc)

v5.7.19

Compare Source

Bug Fixes

v5.7.18

Compare Source

Bug Fixes
  • don't force dock layout onto script/style/template children (#​4679) (b5a1209)

v5.7.17

Compare Source

Bug Fixes

v5.7.16

Compare Source

Bug Fixes
  • horizontal menu alignment (1125e2a)

v5.7.15

Compare Source

Bug Fixes

v5.7.14

Compare Source

Bug Fixes

v5.7.13

Compare Source

Bug Fixes

v5.7.12

Compare Source

Bug Fixes
  • prevent select arrow to rotate when select is focused but not open (#​4655) (3362dc2)

v5.7.11

Compare Source

Bug Fixes

v5.7.10

Compare Source

Bug Fixes
django/django (django)

v5.2.17

Compare Source

allauth/django-allauth (django-allauth)

v65.19.4

Compare Source

v65.19.3

Compare Source

v65.19.2

Compare Source

v65.19.1

Compare Source

v65.19.0

Compare Source

kitware-resonant/django-auth-style (django-auth-style)

v0.15.1

Compare Source

  • Ensure that checkboxes are rendered with the correct initial state
  • Add explicit support for Django 6.1
noripyt/django-cachalot (django-cachalot)

v2.9.1

Compare Source

  • Add support for Django 6.1
django-commons/django-debug-toolbar (django-debug-toolbar)

v7.1.1

Compare Source

Changelog

  • Serialize TaskResult in the Tasks panel to accommodate the storage mechanism.
  • Removed whitespace on Task panel’s kwargs column.

What's Changed

Full Changelog: django-commons/django-debug-toolbar@7.1.0...7.1.1

v7.1.0

Compare Source

Changelog

  • Added a Tasks panel that shows tasks queued during the request via Django’s built-in tasks framework (django.tasks, Django 6.0+). On older versions of Django, the panel explains that upgrading is required.
  • Fixed the Django version check in the SQL panel test suite for Django’s boolean parameter handling.
  • Fixed show_toolbar_with_docker on Docker runtimes such as OrbStack that can resolve host.docker.internal to an address outside the container network.
  • Restored the select and explain buttons for queries that run without parameters.
  • Fixed the error shown when panel content fails to load, which could not find the toolbar window inside the shadow root.
  • Stopped the history panel buttons from submitting their form when clicked before the panel script has loaded, which navigated away from the page.
  • Added support for Django 6.1.

What's Changed

New Contributors

Full Changelog: django-commons/django-debug-toolbar@7.0.0...7.1.0

kitware-resonant/cookiecutter-resonant (django-resonant-settings)

v0.52.1

Compare Source

Cookiecutter Changes

  • More reliably disable IPv6 in dev containers
  • Ignore Ruff rule "too-many-positional-arguments" in test code
  • Make Pytest and MyPy options slightly more strict

v0.52.0

Compare Source

Cookiecutter Changes

  • Set the HEROKU_APP env var, for use by Heroku CLI
  • Bump the dev container node feature to resolve a bug
  • Bump terraform-heroku-resonant
  • Remove the dev container feature for Git LFS
  • Properly exclude celerybeat related files
  • Remove --verbose from pytest configuration
  • Switch to a working MinIO Docker image
  • Add support for Django 6.1

django-resonant-settings Changes

  • Fix the type of the AUTHENTICATION_BACKENDS setting
  • Harden createsuperuser email verification
  • Add support for Django 6.1
kitware-resonant/django-resonant-utils (django-resonant-utils)

v0.20.0

Compare Source

  • Remove django-oauth-toolkit + django-ninja integration
    • This is now provided upstream by django-oauth-toolkit.
  • Deprecate zero-argument usage of SelectRelatedManager
  • Add support for Django 6.1
  • Fix autocomplete in FullNameSignupForm
encode/django-rest-framework (djangorestframework)

v3.18.1

Compare Source

What's Changed

Bug fixes
Other changes

New Contributors

Full Changelog: encode/django-rest-framework@3.18.0...3.18.1

elastic/elasticsearch-py (elasticsearch)

v9.5.1

Compare Source

Changelog

v9.5.0

Compare Source

Changelog

elastic/dockerfiles (elasticsearch)

v9.5.2

Compare Source

v9.5.1

Compare Source

v9.4.6

Compare Source

v9.4.5

Compare Source

googleapis/google-cloud-python (google-analytics-data)

v0.23.2: google-analytics-data: v0.23.2

Compare Source

Features

v0.23.1: google-analytics-data: v0.23.1

Compare Source

Features
benoitc/gunicorn (gunicorn)

v26.2.0: gunicorn 26.2.0

Compare Source

Cleartext HTTP/2 lands, and an HTTP/2 security fix.

Cleartext HTTP/2 (h2c)

http2_cleartext accepts prior-knowledge, upgrade, both or off (the
default). Prior knowledge serves a connection that opens with the HTTP/2
preface; upgrade honours an HTTP/1.1 Upgrade: h2c request. Both work on the
gthread, gevent and asgi workers.

This is for deployments where TLS is terminated by a proxy that speaks HTTP/2
upstream, so the hop into gunicorn no longer drops to HTTP/1.1. Only peers in
forwarded_allow_ips are considered; everyone else is served HTTP/1.x exactly
as if the setting were off. Each mechanism is enabled separately, so turning one
on does not turn the other on.

Do not expose a cleartext HTTP/2 port to the internet.

Security

HTTP2Request built its headers straight from the stream, so nothing the HTTP/1
path enforces applied over HTTP/2: the underscore and header_map policy,
duplicate Host and Content-Type, control characters in values, and the
forwarded_allow_ips trust gate. An untrusted client could set SCRIPT_NAME
and forge HTTP_* entries in the WSGI environ, and decide wsgi.url_scheme
through :scheme. Both request classes now share one policy mixin, and the
scheme comes from the transport.

If you serve HTTP/2, this is the reason to upgrade.

Other HTTP/2 fixes

WSGI responses were buffered whole before anything was sent; they stream now.
HEAD, 204 and 304 no longer carry a body. Events read while blocked on a
flow-control window were discarded, losing requests and body data outright.
sendfile() is refused on HTTP/2 responses rather than bypassing framing.

Request bodies dropped on Upgrade requests

On the ASGI worker with the fast parser, any request carrying an Upgrade
header reached the application with an empty body, whatever the header's value
and with HTTP/2 switched off entirely. Fixed in gunicorn_h1c 0.6.9, which the
fast extra now requires.

Full changelog: https://gunicorn.org/news/

v26.1.0: gunicorn 26.1.0

Compare Source

New Features
  • Glob patterns in reload_extra_files: entries containing *, ? or [
    are treated as patterns, so ui/*/config.json watches every view's config
    without listing them one by one. Patterns are re-expanded on every reload
    check rather than once at startup, so a file created later starts being
    watched without restarting gunicorn, and ** recurses. A pattern matching
    nothing warns instead of failing, since with live expansion it may match later
    (#​1643,
    #​3662).
Security
  • Dependency floors raised past known advisories: every declared floor was
    checked against the advisory database. tornado, h2, setuptools and
    pymdown-extensions permitted vulnerable versions and now require the first
    clean release; pytest and httpx were unpinned and now carry floors. The
    tornado example pinned tornado<6, which was both the source of several
    advisories and older than the >=6.5.0 the tornado worker needs, so the
    example could not run as pinned.
Bug Fixes
  • SIGHUP did not reload the logger configuration: Arbiter.reload()
    re-read the configuration file but kept using the logger built at startup,
    calling only reopen_files() on its existing handlers. Changes to
    logconfig, logconfig_dict, logconfig_json and loglevel were ignored
    until a full restart, which in containers meant replacing the pod. The
    existing logger now re-runs its setup on reload, so new handlers, formats
    and levels take effect while the process identity and its listeners are
    preserved, and re-running the setup no longer stacks duplicate syslog
    handlers. An invalid log configuration on reload is not fatal either: the
    error is reported on stderr, the previous working configuration is restored
    and the master keeps running with it
    (#​3353).

  • Truncated chunked bodies accepted: RFC 9112 section 7.1.2 ends a chunked
    body with 0 CRLF CRLF, the second CRLF being the mandatory empty trailer
    section. ChunkedReader.parse_chunk_size() swallowed the NoMoreData raised
    while scanning for it, so a body cut short right after the last chunk line was
    treated as complete instead of rejected. It now raises
    ChunkMissingTerminator
    (#​3382,
    #​3685).

  • --spew crashed on dynamically generated code: the trace hook indexed the
    2-tuple returned by inspect.getsourcelines() by line number rather than
    indexing the list of lines, so a frame with no __file__ raised
    AttributeError: 'int' object has no attribute 'rstrip' on line 1 and
    IndexError beyond it. The tuple is now unpacked and offset by the source's
    starting line (#​3344,
    #​3495).

  • Duplicate Host and Content-Type headers accepted: RFC 9110 section 5.3
    allows only one of each, and a repeat cannot be merged into a list, so the
    message means different things to gunicorn and to anything downstream. Both
    are now rejected with InvalidHeader. The check lives in the policy hook
    shared by both parsers, so the pure-Python and fast parsers agree. Duplicate
    Content-Length was already rejected and is unchanged
    (#​3366,
    #​3548).

  • Non-worker children reported as failed workers: reap_workers() reaps
    every child through waitpid(-1), including processes the kernel reparented
    onto gunicorn when it runs as PID 1 in a container, but it logged the exit
    status before checking whether the pid was ever a worker. An unrelated process
    produced Worker (pid:N) exited with code M and triggered alerts. More
    seriously, such a process exiting with code 3 or 4 raised HaltServer and shut
    the server down. Ownership is now established first: the dirty arbiter is
    reported as itself, unknown children are reaped silently at debug level, and
    only real workers can halt the server
    (#​3220,
    #​3566).

  • Dirty arbiter exits were invisible on SIGCHLD: handle_chld() called
    reap_workers() first, whose waitpid(-1) claimed the dirty arbiter before
    reap_dirty_arbiter() could identify it, so the latter always hit ECHILD and
    its reporting never ran. The dirty arbiter is now reaped first, and
    reap_workers() recognises it if it exits mid-loop.

  • Dirty arbiter returned stale responses after a worker timeout: when a
    request reached dirty_timeout the arbiter answered the client with a timeout
    error but kept the worker connection open. The worker's late response was then
    the first message waiting on that socket, so the next request routed to the
    same worker received the previous request's result, and every request after it
    stayed one response behind. The connection is now closed on timeout, so the
    late answer is discarded with it
    (#​3626).

  • ASGI connection count leaked on server-initiated close: nr_conns was
    only decremented in connection_lost(), behind a guard keyed on the same
    flag _close_transport() sets first. Every close the server started (a
    Connection: close response, a keepalive timeout, an error abort) leaked one
    count, so ASGIWorker._shutdown() ran the full graceful_timeout and warned
    about connections that were already gone. The guard now uses its own flag, so
    the decrement and the rest of the cleanup run exactly once whichever side
    closes first (#​3661).

  • Inotify reloader on cwd-relative extra files: reload_extra_files entries
    with no directory part (for example .env) produced an empty dirname, and
    watching it raised InotifyError with ENOENT. The current directory is now
    watched as . (#​3377,
    #​3667).

  • StatsD zero-valued metrics: gauges, counters, histograms and timers
    reporting 0 were silently dropped because the value was tested for
    truthiness. Only None is skipped now
    (#​3676).

  • Spurious no-body warning from sendfile(): a HEAD, 204 or 304 response
    served through sendfile() warned about dropped body bytes even when the
    file was empty and nothing was dropped. It now warns only when there are
    bytes to drop, matching write()
    (#​3684).

  • Bare except in the gevent websocket example: narrowed to
    except Exception (#​3683).

  • ASGI receive() cancellation: Let asyncio.CancelledError propagate
    from BodyReceiver instead of swallowing it and returning
    http.disconnect. Frameworks that cancel their disconnect listener after
    the response completes (Django) no longer see the cancel masked, so
    request_finished fires and close_old_connections() runs. Fixes idle
    database connections leaking since 25.1.0
    (#​3627,
    #​3654).

  • Control socket leak on SIGHUP reload: The control thread is now marked
    ready once its loop and server are live, and the stop paths wait on that
    readiness before scheduling shutdown. Reloads no longer leak one thread and
    its selector fd plus unix socket per worker, which eventually raised
    "too many open files"
    (#​3648).

  • WSGI body framing on HEAD/1xx/204/304: Mirror the ASGI strip-and-warn
    behavior on the WSGI path. Content-Length is stripped on 1xx/204 per
    RFC 9110 section 6.4.2, body bytes are dropped for no-body responses in
    both write() and sendfile(), and a single warning is logged per request
    (#​3413).

Refactoring
  • Pass log arguments to the logger instead of pre-formatting the worker
    termination message in Arbiter.reap_workers()
    (#​3678).
Changes
  • packaging is no longer a runtime dependency: it was only ever imported by
    the gevent worker, to compare gevent's version. It moved to the gevent and
    testing extras, so a plain pip install gunicorn pulls in nothing
    (#​3643).

  • Fast HTTP Parser: Require gunicorn_h1c >= 0.6.6, which rejects duplicate
    Host and Content-Type headers in the C parser itself. Gunicorn already
    refuses them on both the WSGI and ASGI paths, so this changes nothing that is
    reachable; it moves the rejection to where the bytes are read and lets the
    ASGI corpus exercise those cases against the fast parser directly.

Full changelog: https://gunicorn.org/2026-news/

pypa/hatch (hatchling)

v1.32.4: Hatchling v1.32.4

Compare Source

Fixed:

  • Revert the extra type parameter added to BuildHookInterface in 1.32.3, which broke plugins that subscripted the interface with a single argument (e.g. BuildHookInterface[MyConfig]) by raising TypeError at import time. BuilderConfig is likewise no longer generic, restoring the pre-1.32.3 plugin interface.
  • Strip spaces around version metadata when using original input for CalVer to keep leading zeroes.

v1.32.3: Hatchling v1.32.3

Fixed:

  • Preserve the version string exactly as written in core metadata, so stylized versions such as CalVer 2026.08.10 are no longer stripped of leading zeros. Distribution file names and .dist-info directories continue to use the PEP 440 normalized form.

v1.32.0: Hatchling v1.32.0

Compare Source

Changed:

  • Bump default core metadata version to 2.5

  • Add tomlkit as a runtime dependency, which is required to rewrite pyproject.toml when setting a static version

Added:

  • The version command can now set a version that is statically defined by the project.version field, updating pyproject.toml in place. Pass --force to allow an explicit downgrade

Fixed:

  • Allow the ; private annotation on project.import-names and project.import-namespaces entries rather than rejecting them as invalid import names.

  • Reject project.readme paths that are absolute or resolve outside of the project directory.

ipython/ipython (ipython)

v9.17.1

Compare Source

v9.17.0

Compare Source

v9.16.1

Compare Source

numpy/numpy (numpy)

v2.5.3

Compare Source

v2.5.2

Compare Source

ijl/orjson (orjson)

v3.12.0

Compare Source

Changed
  • Serialization implementation substantially rewritten.
  • Publish PyPI wheels for Python 3.15. For Python 3.15 and later,
    manylinux_2_39 (2024) is targeted instead of manylinux_2_17 (2012).
  • No longer publish PyPI wheels for ppc64le and s390x.
pandas-dev/pandas (pandas)

v3.0.6: pandas 3.0.6

Compare Source

We are pleased to announce the release of pandas 3.0.6.
This is a patch release in the 3.0.x series and includes some regression fixes and bug fixes. We recommend that all users of the 3.0.x series upgrade to this version. This is also the first release to support Python 3.15.

See the full whatsnew for a list of all the changes.

Pandas 3.0 supports Python 3.11 and higher.
The release can be installed from PyPI:

python -m pip install --upgrade pandas==3.0.*

Or from conda-forge

conda install -c conda-forge pandas=3.0

Please report any issues with the release on the pandas issue tracker.

Thanks to all the contributors who made this release possible.

psycopg/psycopg (psycopg)

v3.3.6

Compare Source

v3.3.5

Compare Source

pydantic/pydantic (pydantic)

v2.13.5

Compare Source

getsentry/sentry-python (sentry-sdk)

v2.70.0

Compare Source

New Features ✨

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 28 times, most recently from 12706b3 to dcc527b Compare September 10, 2026 01:16
@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 2c2c9349-a9e2-4c30-9ef4-f10a04cd56f8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from dcc527b to 9725c70 Compare September 11, 2026 15:29
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 9 times, most recently from 8ee82a3 to 4f1ee4a Compare September 24, 2026 05:06
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 13 times, most recently from 8280178 to d71dd9f Compare September 30, 2026 16:07
This was referenced Sep 30, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from d71dd9f to d1398bf Compare September 30, 2026 17:00
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from d1398bf to 47710c6 Compare September 30, 2026 17:44
@danlamanna
danlamanna merged commit 5143025 into master Sep 30, 2026
4 checks passed
@danlamanna
danlamanna deleted the renovate/all-minor-patch branch September 30, 2026 17:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant