Skip to content

chore(deps): Bump the python-dependencies group across 1 directory with 26 updates - #130

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-dependencies-18b8419ed7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-dependencies-18b8419ed7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 26 updates in the / directory:

Package From To
fastapi 0.141.1 0.142.0
uvicorn 0.52.4 0.54.0
sqlalchemy 2.0.52 2.1.1
pypdf 6.18.0 6.19.0
pyjwt 2.13.0 2.15.1
filelock 3.32.5 4.0.6
idna 3.19 3.20
anthropic 1.4.0 1.9.0
psycopg2-binary 2.9.12 2.9.13
ruff 0.16.6 0.16.9
ast-serialize 0.11.0 0.11.2
boto3 1.43.89 1.43.104
botocore 1.43.89 1.43.104
coverage 7.16.0 7.16.2
deprecated 1.3.1 3.0.0
greenlet 3.5.5 3.5.6
httpcore2 2.12.0 2.13.1
httpx2 2.12.0 2.13.1
jiter 0.16.0 0.17.0
librt 0.15.0 0.16.0
pydantic-core 2.46.5 2.49.0
starlette 1.6.0 1.7.0
urllib3 2.7.0 2.8.0
watchfiles 1.2.0 1.3.0
werkzeug 3.1.8 3.1.9
wrapt 2.4.0 2.5.0

Updates fastapi from 0.141.1 to 0.142.0

Release notes

Sourced from fastapi's releases.

0.142.0

Features

Refactors

Docs

Translations

Internal

... (truncated)

Commits

Updates uvicorn from 0.52.4 to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Version 0.53.0

🌐 Opt-in HTTP/2 support

uvicorn 0.53.0 adds experimental HTTP/2 through zttp, alongside a new zuvloop integration and connection-handling improvements.

uv add uvicorn==0.53.0
  • Serve HTTP/1.1 and HTTP/2 with zttp (#2982, #3101). Install zttp, then enable HTTP/2 with --http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.
  • HTTP/2 remains experimental. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

⚙️ More event loop choice

  • Run Uvicorn with zuvloop (#3104). Install zuvloop separately and select it explicitly with --loop zuvloop on CPython 3.14 or newer.

🛡️ More reliable connections and proxies

  • Honor Connection: close token lists (#3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.
  • Trust IPv6 loopback proxies by default (#3119). The default FORWARDED_ALLOW_IPS value now includes ::1.
  • Keep upgraded WebSockets alive (#3107). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.

Full changelog: 0.52.4...0.53.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)

0.53.0 (September 14, 2026)

This release adds experimental HTTP/2 support through zttp. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

Added

  • Add experimental HTTP/2 support through zttp (#2982, #3101)
  • Add support for zuvloop (#3104)

Fixed

  • Handle comma-separated, case-insensitive Connection: close tokens across HTTP implementations (#3103)
  • Trust IPv6 loopback in the default FORWARDED_ALLOW_IPS value (#3119)
  • Cancel the HTTP keep-alive timer when upgrading to WebSocket (#3107)
Commits

Updates sqlalchemy from 2.0.52 to 2.1.1

Release notes

Sourced from sqlalchemy's releases.

2.1.1

Released: September 25, 2026

platform

  • [platform] [bug] Removed the legacy underscore-separated extra names such as mssql_pymssql and postgresql_psycopg from pyproject.toml. They normalize to the same names as the existing dash-separated extras, which is disallowed by PEP 685, and caused the 2.1.0 source distribution to fail to build with installers that enforce this rule, such as uv. The underscore spellings continue to work when installing, as installers normalize extra names before matching them.

    References: #13604

2.1.0

Released: September 24, 2026

orm

  • [orm] [feature] Added _orm.composite.column_template parameter to _orm.composite(). When the composite class is a dataclass, this parameter accepts a string template such as "person_%s", containing exactly one %s placeholder, that's used to generate column names for dataclass fields that don't otherwise have an explicit name, rather than using the bare field name. This removes the need to hand-write a _orm.mapped_column() for each field when the same composite dataclass is mapped multiple times on the same class with different column-name prefixes. Pull request courtesy Leonardo Rosa.

    References: #12575

  • [orm] [bug] Fixed issue where pickling an ORM object that had an instance level lazy loader established, such as when the _orm.raiseload() option is used, would emit a spurious warning regarding the loader containing additional criteria, if the object had itself been unpickled from a previous serialization. This would occur for objects that cross more than one serialization boundary, such as when using multiprocessing.

    This change is also backported to: 2.0.53

    References: #13574

  • [orm] [bug] Fixed issue where calling _orm.aliased() against an existing _orm.aliased() construct, without passing an explicit selectable, would disregard the selectable of the existing construct and produce an

... (truncated)

Commits

Updates pypdf from 6.18.0 to 6.19.0

Release notes

Sourced from pypdf's releases.

Version 6.19.0, 2026-09-16

What's new

Security (SEC)

Deprecations (DEP)

Performance Improvements (PI)

Bug Fixes (BUG)

Full Changelog

Version 6.18.1, 2026-09-11

What's new

Security (SEC)

Bug Fixes (BUG)

Robustness (ROB)

Documentation (DOC)

Full Changelog

Changelog

Sourced from pypdf's changelog.

Version 6.19.0, 2026-09-16

Security (SEC)

  • Limit size of alphabetical page labels (#4096)

Deprecations (DEP)

  • Replace PdfWriter method add_js (#3979)

Performance Improvements (PI)

  • Move static value out of loop body for appearance stream data (#4087)
  • Reduce number of full data lookups for attachment mapping API (#4081)

Bug Fixes (BUG)

  • Do not copy unrelated pages when appending pages with non-terminal fields (#4078)
  • Use page reference for existing internal link targets (#4076)
  • Arabic-Indic digits are reversed during text extraction (#4077)
  • Parse a string rect for add_uri into a rectangle (#4074)

Full Changelog

Version 6.18.1, 2026-09-11

Security (SEC)

  • Further restrict FlateDecode recovery (#4073)
  • Limit entry count for TrueType and Type1 font /Widths (#4072)
  • Limit allowed length of tokens in parse_bfchar (#4071)

Bug Fixes (BUG)

  • Use current text matrix for visitor_text (#4062)
  • Repeat the letter for /S /A and /S /a page labels past Z (#4065)
  • Use font color for FreeText default appearance (#4051)

Robustness (ROB)

  • Fix compatibility with fonttools < 4.58.0 (#4050, #4059)

Documentation (DOC)

  • Use combined matrix in visitor examples (#4066)

Full Changelog

Commits
  • d62cb58 REL: 6.19.0
  • 0d8b5a8 SEC: Limit size of alphabetical page labels (#4096)
  • 959467a PI: Move static value out of loop body for appearance stream data (#4087)
  • 20822b2 DEV: Bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 (#4093)
  • 25f2301 DEP: Replace PdfWriter method add_js (#3979)
  • a924438 BUG: Do not copy unrelated pages when appending pages with non-terminal field...
  • cf5cec2 BUG: Use page reference for existing internal link targets (#4076)
  • 96d81f0 BUG: Arabic-Indic digits are reversed during text extraction (#4077)
  • 2d21901 DEV: Fix Color class for latest mypy (#4082)
  • 893a010 MAINT: Split PdfDocCommon._flatten (#4070)
  • Additional commits viewable in compare view

Updates pyjwt from 2.13.0 to 2.15.1

Release notes

Sourced from pyjwt's releases.

2.15.1

See the 2.15.1 changelog for complete release details.

2.15.0

See the 2.15.0 changelog for complete release details.

2.14.0

See the 2.14.0 changelog for the complete release details and related security advisories.

Changelog

Sourced from pyjwt's changelog.

v2.15.1 <https://github.com/jpadilla/pyjwt/compare/2.15.0...2.15.1>__

Fixed


- Accept trailing Base64URL ``=`` padding when decoding JWS segments, so
  tokens issued by AWS ALB and similar systems verify instead of raising
  ``DecodeError: Invalid crypto padding``. Non-alphabet junk such as
  ``!!!!`` remains rejected (`[#1209](https://github.com/jpadilla/pyjwt/issues/1209) <https://github.com/jpadilla/pyjwt/issues/1209>`__).

v2.15.0 &lt;https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&gt;__

Security

  • Wrap recursion errors from deeply nested JWT payloads in DecodeError instead of exposing a raw RecursionError.

Added


- Support Python 3.15 by @kytta in `[#1202](https://github.com/jpadilla/pyjwt/issues/1202) <https://github.com/jpadilla/pyjwt/pull/1202>`__

Changed

  • JWKSetCache now stores the parsed PyJWKSet rather than the raw JWKS payload, so a cache hit no longer re-parses every key. JWKSetCache.put() accepts either form and raises PyJWKSetError for anything else. As a result, PyJWKClient.get_jwk_set() returns the same PyJWKSet instance for as long as it stays cached, rather than a freshly built one per call in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) <https://github.com/jpadilla/pyjwt/pull/1208>__
  • PyJWKClient.fetch_data() now raises PyJWKClientError("The JWKS endpoint did not return a JSON object") when the endpoint response is not a JSON object, instead of returning it for get_jwk_set() to reject. Callers reaching the JWKS through get_jwk_set() see the same error as before in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) <https://github.com/jpadilla/pyjwt/pull/1208>__

Fixed


- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead
  of raising ``PyJWKClientError("The JWKS endpoint did not return a JSON
  object")``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value,
  so callers pre-populating the cache to avoid a network round-trip could not
  read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) <https://github.com/jpadilla/pyjwt/issues/914>`__ and
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) <https://github.com/jpadilla/pyjwt/pull/1208>`__
</tr></table> 

... (truncated)

Commits
  • 7d5ef55 chore: prepare 2.15.1 release
  • 7bf3252 Accept canonical Base64URL padding in JWT segments (#1216)
  • 1d41a64 chore: prepare 2.15.0 release
  • 9bc0665 fix: make recursive payload tests deterministic
  • 5fde08a fix: normalize recursive JWT payload errors
  • 171062d utils: mention bytes in force_bytes type error (#1173)
  • c9d4d53 docs/conf: drop duplicate 'and' from read() docstring (#1174)
  • 2763752 Add support for Python 3.15 (#1202)
  • 4adcd02 Catch http.client.HTTPException in PyJWKClient.fetch_data (#1201)
  • 9e501d9 fix: correct docstring typo in _validate_jti (#1179)
  • Additional commits viewable in compare view

Updates filelock from 3.32.5 to 4.0.6

Release notes

Sourced from filelock's releases.

4.0.6

What's Changed

Full Changelog: tox-dev/filelock@4.0.5...4.0.6

4.0.5

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.4...4.0.5

4.0.4

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.3...4.0.4

4.0.3

What's Changed

Full Changelog: tox-dev/filelock@4.0.2...4.0.3

4.0.2

What's Changed

... (truncated)

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.0.9 (2026-10-01)


  • ReadWriteLock and AsyncReadWriteLock close the descriptor that checks the database path once SQLite has connected, so on PyPy a dropped lock leaves no descriptor open until garbage collection runs. :pr:763
  • ReadWriteLock and AsyncReadWriteLock refuse a symlink at the database path instead of following it, so a user who can create names in a shared lock directory cannot point the lock at another file (GHSA-j8f7-rjxc-mr56).

4.0.8 (2026-10-01)


  • ReadWriteLock.release() and SoftReadWriteLock.release() from a thread that does not hold the write lock now raise RuntimeError instead of dropping the holder's lock and letting a second writer in. :pr:761

4.0.7 (2026-09-29)


  • File locks now raise ValueError at construction when mode denies the owner read or write, such as mode=0o444, instead of failing on a later acquire and staying broken until someone deletes the lock file. :pr:760

4.0.6 (2026-09-28)


  • Reject negative blocking timeouts other than -1 before reentrant ReadWriteLock and SoftReadWriteLock acquisition. Preserve unlimited waits and nonblocking acquisition. :pr:756

4.0.5 (2026-09-28)


  • Fix MarkerSoftFileLock acquisition and prevent contenders from evicting live protocol-2 owners after two seconds. Reclaim recognized records after owner death; preserve unknown contracts. :pr:749
  • Honor instance timeout and blocking settings in sync and async ReadWriteLock acquisition, including waits between tasks on one instance. Preserve explicit per-call overrides. :pr:750
  • Skip access-denial checks when the process can read mode-0o000 files. Keep mode-bit checks enabled for privileged processes on filesystems that support POSIX permissions. :pr:753
  • Skip vanished StrictSoftFileLock claims after a read-permission retry expires. Recheck the directory before raising a protocol error so concurrent removal does not turn a stale claim listing into an acquisition failure. :pr:754

... (truncated)

Commits

Updates idna from 3.19 to 3.20

Release notes

Sourced from idna's releases.

v3.20

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Changelog

Sourced from idna's changelog.

3.20 (2026-09-17)

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Commits
  • d55e65e Release 3.20
  • 0c0824a Pre-release 3.20rc0
  • bd7c316 Note Python 3.15 support in the 3.20 changelog
  • b6cce85 Merge pull request #276 from kjd/unicode-18
  • 9a4bc59 Update to Unicode 18.0.0
  • dfab5a0 Merge branch 'python-3.15'
  • 417c354 Read the latest Unicode version from the DerivedAge.txt header instead of the...
  • cd17392 Merge pull request #274 from kjd/fix-decode-length-check
  • c5796d7 Skip the decode round-trip check for domains past encode's length limit
  • d6ee690 Update to Python 3.15 release candidate in CI and add trove classifier
  • Additional commits viewable in compare view

Updates anthropic from 1.4.0 to 1.9.0

Release notes

Sourced from anthropic's releases.

v1.9.0

1.9.0 (2026-09-28)

Full Changelog: v1.8.0...v1.9.0

Features

  • api: add between_tools thinking type (a9a577d)
  • api: add claude-sonnet-5-5 (a5a25e9)
  • api: add include_inherited and source to workspace rate limits (0bf4af8)
  • api: add typed event type values to the Managed Agents events list filter (1b82cd9)
  • api: cache diagnostics GA — diagnostics on Message / MessageCreateParams (22062b8)
  • tools: optionally run tool calls while the reply streams (26d0812)

Bug Fixes

  • client: send no placeholder filename for unnamed file uploads (9e9709d)
  • helpers: degrade between_tools thinking to disabled on fallback hops (#952) (a3834d4)
  • messages: accept diagnostics in stream() and parse() (#929) (fad840c)

Chores

  • api: list the known model ids first in the Model types (e5a082a)
  • ci: choose the CI runner by repository (39ccf62)
  • client: stop sending beta header from parse and tool runner (#907) (1428100)
  • docs: clarify that stream: true returns the raw event stream (82918fa)
  • docs: make Managed Agents actor descriptions resource-neutral (34ef524)
  • docs: restore the research-preview notice on the Dream type (f03e32e)

Documentation

  • add field docstring spacing rule to CLAUDE.md (e5c35f4)
  • api: prefer each field's own description over its shared type's (d79a2e7)
  • claude.md: add function body spacing rule (3174f8f)
  • list importable type names in api.md (56a42ab)

v1.8.0

1.8.0 (2026-09-22)

Full Changelog: v1.7.0...v1.8.0

Features

  • api: add support for claude-opus-5-5, inline tool definitions and MCP tool-list pinning (beta) (b5cc700)

Bug Fixes

... (truncated)

Changelog

Sourced from anthropic's changelog.

1.9.0 (2026-09-28)

Full Changelog: v1.8.0...v1.9.0

Features

  • api: add between_tools thinking type (a9a577d)
  • api: add claude-sonnet-5-5 (a5a25e9)
  • api: add include_inherited and source to workspace rate limits (0bf4af8)
  • api: add typed event type values to the Managed Agents events list filter (1b82cd9)
  • api: cache diagnostics GA — diagnostics on Message / MessageCreateParams (22062b8)
  • tools: optionally run tool calls while the reply streams (26d0812)

Bug Fixes

  • client: send no placeholder filename for unnamed file uploads (9e9709d)
  • helpers: degrade between_tools thinking to disabled on fallback hops (#952) (a3834d4)
  • messages: accept diagnostics in stream() and parse() (#929) (fad840c)

Chores

  • api: list the known model ids first in the Model types (e5a082a)
  • ci: choose the CI runner by repository (39ccf62)
  • client: stop sending beta header from parse and tool runner (#907) (1428100)
  • docs: clarify that stream: true returns the raw event stream (82918fa)
  • docs: make Managed Agents actor descriptions resource-neutral (34ef524)
  • docs: restore the research-preview notice on the Dream type (f03e32e)

Documentation

  • add field docstring spacing rule to CLAUDE.md (e5c35f4)
  • api: prefer each field's own description over its shared type's (d79a2e7)
  • claude.md: add function body spacing rule (3174f8f)
  • list importable type names in api.md (56a42ab)

1.8.0 (2026-09-22)

Full Changelog: v1.7.0...v1.8.0

Features

  • api: add support for claude-opus-5-5, inline tool definitions and MCP tool-list pinning (beta) (b5cc700)

Bug Fixes

  • api: share one evaluated_permission enum across Managed Agents events (f4f51c8)

... (truncated)

Commits
  • a7285e9 Merge pull request #1958 from anthropics/release-please--branches--main--chan...
  • 3e2ac95 release: 1.9.0
  • 24b1d55 codegen metadata
  • a5a25e9 feat(api): add claude-sonnet-5-5
  • 2264bd8 codegen metadata
  • 9e9709d fix(client): send no placeholder filename for unnamed file uploads
  • 1b82cd9 feat(api): add typed event type values to the Managed Agents events list filter
  • 26d0812 feat(tools): optionally run tool calls while the reply streams
  • ebb8239 codegen metadata
  • a3834d4 fix(helpers): degrade between_tools thinking to disabled on fallback hops (#952)
  • Additional commits viewable in compare view

Updates psycopg2-binary from 2.9.12 to 2.9.13

Changelog

Sourced from psycopg2-binary's changelog.

Current release

What's new in psycopg 2.9.13 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Add support for Python 3.15 (:ticket:[#1848](https://github.com/psycopg/psycopg2/issues/1848)).
  • Fix parsing of malformed bytea input.
  • Fix parsing of malformed int64 input in arrays (:ticket:[#1847](https://github.com/psycopg/psycopg2/issues/1847)).
  • Add a pyproject.toml file to declare a PEP 517 build backend (:ticket:[#1788](https://github.com/psycopg/psycopg2/issues/1788)).
  • Drop support for Python 3.9.

What's new in psycopg 2.9.12 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Fix infinite loop with malformed interval (:ticket:1835).

What's new in psycopg 2.9.11 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Add support for Python 3.14.
  • Avoid a segfault passing more arguments than placeholders if Python is built with assertions enabled (:ticket:[#1791](https://github.com/psycopg/psycopg2/issues/1791)).
  • Add riscv64 platform binary packages (:ticket:[#1813](https://github.com/psycopg/psycopg2/issues/1813)).
  • ~psycopg2.errorcodes map and ~psycopg2.errors classes updated to PostgreSQL 18.
  • Drop support for Python 3.8.

What's new in psycopg 2.9.10 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Add support for Python 3.13.
  • Receive notifications on commit (:ticket:[#1728](https://github.com/psycopg/psycopg2/issues/1728))....

    Description has been truncated

…th 26 updates

Bumps the python-dependencies group with 26 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [fastapi](https://github.com/fastapi/fastapi) | `0.141.1` | `0.142.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.54.0` |
| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.52` | `2.1.1` |
| [pypdf](https://github.com/py-pdf/pypdf) | `6.18.0` | `6.19.0` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.15.1` |
| [filelock](https://github.com/tox-dev/py-filelock) | `3.32.5` | `4.0.6` |
| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |
| [anthropic](https://github.com/anthropics/anthropic-sdk-python) | `1.4.0` | `1.9.0` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.9` |
| [ast-serialize](https://github.com/mypyc/ast_serialize) | `0.11.0` | `0.11.2` |
| [boto3](https://github.com/boto/boto3) | `1.43.89` | `1.43.104` |
| [botocore](https://github.com/boto/botocore) | `1.43.89` | `1.43.104` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.16.0` | `7.16.2` |
| [deprecated](https://github.com/laurent-laporte-pro/deprecated) | `1.3.1` | `3.0.0` |
| [greenlet](https://github.com/python-greenlet/greenlet) | `3.5.5` | `3.5.6` |
| [httpcore2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.1` |
| [httpx2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.1` |
| [jiter](https://github.com/pydantic/jiter) | `0.16.0` | `0.17.0` |
| [librt](https://github.com/mypyc/librt) | `0.15.0` | `0.16.0` |
| [pydantic-core](https://github.com/pydantic/pydantic) | `2.46.5` | `2.49.0` |
| [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` |
| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |
| [watchfiles](https://github.com/samuelcolvin/watchfiles) | `1.2.0` | `1.3.0` |
| [werkzeug](https://github.com/pallets/werkzeug) | `3.1.8` | `3.1.9` |
| [wrapt](https://github.com/GrahamDumpleton/wrapt) | `2.4.0` | `2.5.0` |



Updates `fastapi` from 0.141.1 to 0.142.0
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.141.1...0.142.0)

Updates `uvicorn` from 0.52.4 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.52.4...0.54.0)

Updates `sqlalchemy` from 2.0.52 to 2.1.1
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

Updates `pypdf` from 6.18.0 to 6.19.0
- [Release notes](https://github.com/py-pdf/pypdf/releases)
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md)
- [Commits](py-pdf/pypdf@6.18.0...6.19.0)

Updates `pyjwt` from 2.13.0 to 2.15.1
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.13.0...2.15.1)

Updates `filelock` from 3.32.5 to 4.0.6
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@3.32.5...4.0.6)

Updates `idna` from 3.19 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.19...v3.20)

Updates `anthropic` from 1.4.0 to 1.9.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-python/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-python@v1.4.0...v1.9.0)

Updates `psycopg2-binary` from 2.9.12 to 2.9.13
- [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS)
- [Commits](psycopg/psycopg2@2.9.12...2.9.13)

Updates `ruff` from 0.16.6 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.6...0.16.9)

Updates `ast-serialize` from 0.11.0 to 0.11.2
- [Commits](mypyc/ast_serialize@v0.11.0...v0.11.2)

Updates `boto3` from 1.43.89 to 1.43.104
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.89...1.43.104)

Updates `botocore` from 1.43.89 to 1.43.104
- [Commits](boto/botocore@1.43.89...1.43.104)

Updates `coverage` from 7.16.0 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.0...7.16.2)

Updates `deprecated` from 1.3.1 to 3.0.0
- [Release notes](https://github.com/laurent-laporte-pro/deprecated/releases)
- [Changelog](https://github.com/laurent-laporte-pro/deprecated/blob/master/CHANGELOG-1.3.md)
- [Commits](laurent-laporte-pro/deprecated@v1.3.1...v3.0.0)

Updates `greenlet` from 3.5.5 to 3.5.6
- [Changelog](https://github.com/python-greenlet/greenlet/blob/master/CHANGES.rst)
- [Commits](python-greenlet/greenlet@3.5.5...3.5.6)

Updates `httpcore2` from 2.12.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Commits](pydantic/httpx2@v2.12.0...v2.13.1)

Updates `httpx2` from 2.12.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](pydantic/httpx2@v2.12.0...v2.13.1)

Updates `jiter` from 0.16.0 to 0.17.0
- [Release notes](https://github.com/pydantic/jiter/releases)
- [Commits](pydantic/jiter@v0.16.0...v0.17.0)

Updates `librt` from 0.15.0 to 0.16.0
- [Commits](mypyc/librt@v0.15.0...v0.16.0)

Updates `pydantic-core` from 2.46.5 to 2.49.0
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/main/HISTORY.md)
- [Commits](https://github.com/pydantic/pydantic/commits)

Updates `starlette` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.6.0...1.7.0)

Updates `urllib3` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

Updates `watchfiles` from 1.2.0 to 1.3.0
- [Release notes](https://github.com/samuelcolvin/watchfiles/releases)
- [Commits](samuelcolvin/watchfiles@v1.2.0...v1.3.0)

Updates `werkzeug` from 3.1.8 to 3.1.9
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.8...3.1.9)

Updates `wrapt` from 2.4.0 to 2.5.0
- [Release notes](https://github.com/GrahamDumpleton/wrapt/releases)
- [Changelog](https://github.com/GrahamDumpleton/wrapt/blob/develop/docs/changes.rst)
- [Commits](GrahamDumpleton/wrapt@2.4.0...2.5.0)

---
updated-dependencies:
- dependency-name: fastapi
  dependency-version: 0.142.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: sqlalchemy
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: pypdf
  dependency-version: 6.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: pyjwt
  dependency-version: 2.15.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: filelock
  dependency-version: 4.0.6
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: python-dependencies
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: anthropic
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: psycopg2-binary
  dependency-version: 2.9.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: ast-serialize
  dependency-version: 0.11.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: boto3
  dependency-version: 1.43.104
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: botocore
  dependency-version: 1.43.104
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: deprecated
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: python-dependencies
- dependency-name: greenlet
  dependency-version: 3.5.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: httpcore2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: httpx2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: jiter
  dependency-version: 0.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: librt
  dependency-version: 0.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: pydantic-core
  dependency-version: 2.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: watchfiles
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: werkzeug
  dependency-version: 3.1.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: wrapt
  dependency-version: 2.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants