Skip to content

fix(deps): update python-dependencies - #14

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/python-dependencies
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/python-dependencies

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
SQLAlchemy (changelog) ==2.0.54 → ==2.1.1 age confidence
filelock ==4.0.3 → ==4.0.6 age confidence
pytz (source) ==2026.3.post1 → ==2026.4 age confidence
ruff (source, changelog) ==0.16.8 → ==0.16.9 age confidence
semgrep (changelog) ==1.177.0 → ==1.178.0 age confidence
starlette (changelog) ==1.6.0 → ==1.7.0 age confidence
uvicorn (changelog) ==0.53.0 → ==0.54.0 age confidence

Release Notes

tox-dev/py-filelock (filelock)

v4.0.6

Compare Source

What's Changed

Full Changelog: tox-dev/filelock@4.0.5...4.0.6

v4.0.5

Compare Source

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.4...4.0.5

v4.0.4

Compare Source

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.3...4.0.4

stub42/pytz (pytz)

v2026.4

Compare Source

astral-sh/ruff (ruff)

v0.16.9

Compare Source

Released on 2026-09-24.

Preview features
  • [ruff] Avoid false positives for overloaded division (RUF069) (#​28309)
Bug fixes
  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#​28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#​28767)
Rule changes
  • Update LibCST-based fixes for Python 3.15 (#​28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#​28542)
Documentation
  • Fix horizontal overflow on the rules documentation page (#​28699)
  • Update rules table with category information (#​28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#​28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#​28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#​27794)
  • [ruff] Mention related isort settings (RUF022) (#​28719)
Contributors
semgrep/semgrep (semgrep)

v1.178.0

Compare Source

### Changed
  • The bundled tree-sitter C runtime is now 0.26.3. (CODE-9425)
### Fixed
  • Fixed an occasional hang when semgrep-core exited on Windows. (windows-hang)
Kludex/starlette (starlette)

v1.7.0: Version 1.7.0

Compare Source

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING]
OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #​3438, #​3463, and #​3520.
  • Expose the matched route through scope["route"] #​3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #​3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #​3563.
  • Support partitioned cookies in SessionMiddleware #​3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #​3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #​3471.
  • Support Python 3.15 #​3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #​3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #​2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #​3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #​3476.
  • Return 400 for invalid multipart parser input #​3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #​3516 and #​3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #​3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #​3568.
  • Handle standalone If-None-Match: * in StaticFiles #​3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #​3532.
  • Persist session mutations made with popitem() and |= #​3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #​3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #​3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #​3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #​3498 and #​3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #​2858.

Full changelog: 1.6.0...1.7.0

Kludex/uvicorn (uvicorn)

v0.54.0: Version 0.54.0

Compare Source

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#​3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#​3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Oct 5, 2026
@renovate
renovate Bot force-pushed the renovate/python-dependencies branch from f43fa63 to c597f1d Compare October 5, 2026 05:38
@renovate
renovate Bot force-pushed the renovate/python-dependencies branch from c597f1d to 11bbb94 Compare October 6, 2026 01:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants