Skip to content

fix(deps): update python-dependencies - #14

Merged
pagefault3228 merged 1 commit into
mainfrom
renovate/python-dependencies
Oct 8, 2026
Merged

pagefault3228 merged 1 commit into
mainfrom
renovate/python-dependencies

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
SQLAlchemy (changelog) ==2.0.54 → ==2.1.1 age confidence
fastapi (changelog) ==0.141.1 → ==0.142.2 age confidence
filelock ==4.0.3 → ==4.0.8 age confidence
pytz (source) ==2026.3.post1 → ==2026.4 age confidence
ruff (source, changelog) ==0.16.8 → ==0.16.10 age confidence
semgrep (changelog) ==1.177.0 → ==1.178.0 age confidence
starlette (changelog) ==1.6.0 → ==1.7.0 age confidence
uvicorn (changelog) ==0.53.0 → ==0.54.0 age confidence

Release Notes

fastapi/fastapi (fastapi)

v0.142.2

Compare Source

Fixes

v0.142.1

Compare Source

Fixes

v0.142.0

Compare Source

Features
Refactors
Docs
Translations
Internal
tox-dev/py-filelock (filelock)

v4.0.8

Compare Source

What's Changed

Full Changelog: tox-dev/filelock@4.0.7...4.0.8

v4.0.7

Compare Source

What's Changed

Full Changelog: tox-dev/filelock@4.0.6...4.0.7

v4.0.6

Compare Source

What's Changed

Full Changelog: tox-dev/filelock@4.0.5...4.0.6

v4.0.5

Compare Source

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.4...4.0.5

v4.0.4

Compare Source

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.3...4.0.4

stub42/pytz (pytz)

v2026.4

Compare Source

astral-sh/ruff (ruff)

v0.16.10

Compare Source

Released on 2026-10-01.

Preview features
  • Add a migration guide for categories (#​28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#​29000)
Performance
  • Reduce memory used by diagnostics (#​28951)
Server
  • Avoid running uv format in untrusted workspaces (#​28873)
Documentation
  • Fix links to moved changelog sections and renamed mdtests (#​28941)
  • Add Python 3.15 as a supported version (#​28907)
  • Add ty as a type checker example (#​28906)
Other changes
  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#​29047)
Contributors

v0.16.9

Compare Source

Released on 2026-09-24.

Preview features
  • [ruff] Avoid false positives for overloaded division (RUF069) (#​28309)
Bug fixes
  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#​28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#​28767)
Rule changes
  • Update LibCST-based fixes for Python 3.15 (#​28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#​28542)
Documentation
  • Fix horizontal overflow on the rules documentation page (#​28699)
  • Update rules table with category information (#​28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#​28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#​28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#​27794)
  • [ruff] Mention related isort settings (RUF022) (#​28719)
Contributors
semgrep/semgrep (semgrep)

v1.178.0

Compare Source

### Changed
  • The bundled tree-sitter C runtime is now 0.26.3. (CODE-9425)
### Fixed
  • Fixed an occasional hang when semgrep-core exited on Windows. (windows-hang)
Kludex/starlette (starlette)

v1.7.0: Version 1.7.0

Compare Source

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING]
OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #​3438, #​3463, and #​3520.
  • Expose the matched route through scope["route"] #​3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #​3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #​3563.
  • Support partitioned cookies in SessionMiddleware #​3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #​3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #​3471.
  • Support Python 3.15 #​3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #​3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #​2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #​3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #​3476.
  • Return 400 for invalid multipart parser input #​3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #​3516 and #​3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #​3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #​3568.
  • Handle standalone If-None-Match: * in StaticFiles #​3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #​3532.
  • Persist session mutations made with popitem() and |= #​3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #​3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #​3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #​3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #​3498 and #​3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #​2858.

Full changelog: 1.6.0...1.7.0

Kludex/uvicorn (uvicorn)

v0.54.0: Version 0.54.0

Compare Source

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#​3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#​3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Oct 5, 2026
@renovate
renovate Bot force-pushed the renovate/python-dependencies branch 5 times, most recently from f6cb7d5 to 435bb14 Compare October 8, 2026 11:07
@renovate
renovate Bot force-pushed the renovate/python-dependencies branch from 435bb14 to 745cc4a Compare October 8, 2026 18:38
@pagefault3228
pagefault3228 merged commit d4adf3c into main Oct 8, 2026
6 checks passed
@pagefault3228
pagefault3228 deleted the renovate/python-dependencies branch October 8, 2026 23:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant