Skip to content

chore(deps): bump the python-dependencies group in /cdk/runtimes/eoapi/raster with 3 updates - #140

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/cdk/runtimes/eoapi/raster/python-dependencies-202c9f224a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/cdk/runtimes/eoapi/raster/python-dependencies-202c9f224a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group in /cdk/runtimes/eoapi/raster with 3 updates: numpy, numexpr and mangum.

Updates numpy from 2.3.3 to 2.5.2

Release notes

Sourced from numpy's releases.

v2.5.2 (Aug 9, 2026)

NumPy 2.5.2 Release Notes

The NumPy 2.5.2 is a patch release that fixes bugs discovered after the 2.5.1 release. The big news is that it includes wheels for the newly released Python 3.15.0rc1.

This release supports Python versions 3.12-3.15

C API changes

PyArray_StringDTypeObject is opaque under the abi3t stable ABI

The PyArray_StringDTypeObject was accidentally exposed in NumPy 2.5 when targeting the free-threading-compatible stable ABI (Py_TARGET_ABI3T). PyArray_StringDTypeObject is now an opaque struct: extensions compiled that way cannot access its fields, since the struct layout depends on the size of the object header. Any code that accessed PyArray_StringDTypeObject fields in an abi3t build would have crashed, so we are making this API change in a bugfix release.

The NpyString allocator API remains usable by passing the descriptor object pointer, e.g. NpyString_acquire_allocator((PyArray_StringDTypeObject *)descr).

(gh-31771)

Contributors

A total of 16 people contributed to this release. People with a "+" by their names contributed a patch for the first time.

  • Abhijeetsingh Meena +
  • Charalampos Stratakis
  • Charles Harris
  • Chris Ninham +
  • David Woods
  • Geonho +
  • Gopu Yeshwanth Reddy +
  • Iason Krommydas
  • Ijtihed Kilani
  • Jelle Zijlstra +
  • Joren Hammudoglu
  • Kumar Aditya
  • Mike Boyle
  • Nathan Goldbaum
  • Raghuveer Devulapalli
  • Sebastian Berg

... (truncated)

Changelog

Sourced from numpy's changelog.

This is a walkthrough of the NumPy 2.4.0 release on Linux, which will be the first feature release using the numpy/numpy-release <https://github.com/numpy/numpy-release>__ repository.

The commands can be copied into the command line, but be sure to replace 2.4.0 with the correct version. This should be read together with the :ref:general release guide <prepare_release>.

Facility preparation

Before beginning to make a release, use the requirements/*_requirements.txt files to ensure that you have the needed software. Most software can be installed with pip, but some will require apt-get, dnf, or whatever your system uses for software. You will also need a GitHub personal access token (PAT) to push the documentation. There are a few ways to streamline things:

  • Git can be set up to use a keyring to store your GitHub personal access token. Search online for the details.

Prior to release

Add/drop Python versions

When adding or dropping Python versions, multiple config and CI files need to be edited in addition to changing the minimum version in pyproject.toml. Make these changes in an ordinary PR against main and backport if necessary. We currently release wheels for new Python versions after the first Python RC once manylinux and cibuildwheel support that new Python version.

Backport pull requests

Changes that have been marked for this release must be backported to the maintenance/2.4.x branch.

Update 2.4.0 milestones

Look at the issues/prs with 2.4.0 milestones and either push them off to a later version, or maybe remove the milestone. You may need to add a milestone.

Check the numpy-release repo

... (truncated)

Commits
  • 48fecee REL: Prepare for the NumPy 2.5.2 release (#32226)
  • ecf599c Merge pull request #32221 from charris/backport-32151
  • 3c7ac97 Merge pull request #32220 from charris/backport-32205
  • 23b30f4 BUG: avoid segfaults when legacy copyswap slot is not defined (#32151)
  • 4964ca8 TYP: isclose shape-typing fix for 2d array-likes (#32205)
  • c37ed94 MAINT: Skip limited_api tests on some platforms. (#32214)
  • 5cfd73b Merge pull request #32206 from charris/update-cibuildwheel
  • d8262bc MAINT: Update cibuildwheel to v4.2.0
  • 988d94d Merge pull request #32158 from charris/backport-32133
  • b2e4f97 BUG: avoid possible stack overflow in arraydescr_dealloc (#32133)
  • Additional commits viewable in compare view

Updates numexpr from 2.13.1 to 2.14.2

Changelog

Sourced from numexpr's changelog.

Changes from 2.14.2 to 2.14.3

  • Under development.
  • Replaced expression-string blacklist filtering with AST validation before evaluation, and disabled Python builtins while sanitization is enabled. This closes sanitizer bypasses in both cached and disable_cache=True evaluation. Expressions using unsupported Python syntax are now rejected before evaluation. Parser errors raise SyntaxError; expressions rejected by the sanitizer raise ValueError; and unknown functions raise TypeError. Sanitization can still be explicitly disabled with sanitize=False or NUMEXPR_SANITIZE=0.

Changes from 2.14.1 to 2.14.2

  • Added a disable_cache parameter to evaluate() to bypass the internal expression cache. Thanks to 27rabbitlt.
  • Added Windows ARM64 wheel builds.
  • Dropped support for Python 3.10.
  • No longer build free-threaded Python 3.13 wheels, matching NumPy's own support.
  • Avoid keeping arrays passed as out= alive in the re_evaluate cache (#558).
  • Guarded out-of-range shift counts (shift amount >= bit width) in the integer <</>> opcodes, which was undefined behavior in C and could return garbage results. Thanks to uwezkhan (#559).
  • Fixed run_interpreter() unconditionally returning success even when the VM engine failed, so execution errors are now correctly raised instead of silently discarded (#557).
  • Fixed a reference leak of constsig on the allocation-failure path in NumExpr_init() (#561).

Changes from 2.14.0 to 2.14.1

  • Rolled back static typing support to ensure compatibiity with NumPy 1.26.
  • Added CI tests for NumPy 1.26
Commits
  • 3b5ddaa Getting ready for release 2.14.2
  • d48823a Fix constsig leak on itemsizes allocation failure in NumExpr_init. Closes #561.
  • 371d064 Merge branch 'master' of github.com:pydata/numexpr
  • 2059974 Return the actual result code from run_interpreter()
  • d5f712d Merge pull request #559 from uwezkhan/shift-count-guard
  • 462d4d1 Merge pull request #562 from pydata/pre-commit-ci-update-config
  • 3e2bdd1 [pre-commit.ci] pre-commit autoupdate
  • caa29dc Guard out-of-range shift counts in integer opcodes
  • ca91acf Drop support for Python 3.10
  • b065396 Merge pull request #560 from gaoflow/fix-558-out-cache-weakref
  • Additional commits viewable in compare view

Updates mangum from 0.19.0 to 0.22.0

Release notes

Sourced from mangum's releases.

0.22.0 - Python 3.15, tested against the real thing

Python 3.15, tested against the real thing

Mangum 0.22.0 moves the supported Python window forward and backs every release with end-to-end tests against a real Lambda runtime.

pip install mangum==0.22.0
  • Python 3.15 is supported. The full suite and strict type checking pass on 3.15 (#404).
  • Python 3.9 is no longer supported. The minimum is now Python 3.10 (#393).
  • Adapters are now verified against a real Lambda runtime. The test suite deploys Mangum to LocalStack and drives it through a Lambda Function URL and an API Gateway REST API with real HTTP requests - covering the HTTP v2 and REST v1 event formats plus lifespan startup, instead of relying only on hand-written mock events (#400, #401).

Full changelog: 0.21.0...0.22.0

Version 0.21.0

This release reverted the previous attempt on support Python 3.14 because it was not working as expected, and added proper support for Python 3.14 with minimal changes.


Full Changelog: Kludex/mangum@0.20.0...0.21.0

Version 0.20.0

What's Changed

New Contributors

Full Changelog: Kludex/mangum@0.19.0...0.20.0

Changelog

Sourced from mangum's changelog.

0.22.0

0.21.0

This release reverted the previous attempt on support Python 3.14 because it was not working as expected, and added proper support for Python 3.14 with minimal changes.

0.20.0

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-dependencies group in /cdk/runtimes/eoapi/raster with 3 updates: [numpy](https://github.com/numpy/numpy), [numexpr](https://github.com/pydata/numexpr) and [mangum](https://github.com/Kludex/mangum).


Updates `numpy` from 2.3.3 to 2.5.2
- [Release notes](https://github.com/numpy/numpy/releases)
- [Changelog](https://github.com/numpy/numpy/blob/main/doc/RELEASE_WALKTHROUGH.rst)
- [Commits](numpy/numpy@v2.3.3...v2.5.2)

Updates `numexpr` from 2.13.1 to 2.14.2
- [Release notes](https://github.com/pydata/numexpr/releases)
- [Changelog](https://github.com/pydata/numexpr/blob/master/RELEASE_NOTES.rst)
- [Commits](pydata/numexpr@v2.13.1...v2.14.2)

Updates `mangum` from 0.19.0 to 0.22.0
- [Release notes](https://github.com/Kludex/mangum/releases)
- [Changelog](https://github.com/Kludex/mangum/blob/main/CHANGELOG.md)
- [Commits](Kludex/mangum@0.19.0...0.22.0)

---
updated-dependencies:
- dependency-name: numpy
  dependency-version: 2.5.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: numexpr
  dependency-version: 2.14.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: mangum
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 29, 2026
@dependabot
dependabot Bot deployed to synthtest September 29, 2026 16:19 Active

This branch was successfully deployed

1 active deployment
synthtest — 568aab57 Deployed Sep 29, 2026 by dependabot[bot] via CDK Operations #525
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants