Skip to content

chore(deps): bump the all group across 1 directory with 21 updates - #1290

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/all-9eab276878
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/all-9eab276878

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the all group with 21 updates in the / directory:

Package From To
pydantic 2.13.4 2.13.5
google-api-core 2.31.0 2.39.0
googleapis-common-protos 1.75.0 1.75.4
packaging 26.2 26.3
sse-starlette 3.4.4 3.5.0
starlette 1.2.1 1.7.0
fastapi 0.136.3 0.141.1
cryptography 48.0.1 50.0.1
opentelemetry-api 1.42.1 1.45.0
opentelemetry-sdk 1.42.1 1.45.0
pyjwt 2.13.0 2.15.0
alembic 1.18.4 1.20.0
pytest 9.0.3 9.1.1
pytest-mock 3.15.1 3.16.0
ruff 0.15.16 0.16.9
uv-dynamic-versioning 0.14.0 0.14.1
types-requests 2.33.0.20260518 2.33.0.20260906
pre-commit 4.6.0 4.6.2
trio 0.33.0 0.34.0
uvicorn 0.49.0 0.54.0
ty 0.0.44 0.0.84

Updates pydantic from 2.13.4 to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates google-api-core from 2.31.0 to 2.39.0

Release notes

Sourced from google-api-core's releases.

google-cloud-texttospeech: v2.38.0

2.38.0 (2026-10-01)

Features

  • declare Python3.15 support (8775794)
Commits
  • c0208c6 chore: release main (#18421)
  • e654dc2 chore(main): release google-auth 2.58.1 (#18462)
  • 1665e68 fix(auth): allow mTLS retry when credentials raise NotImplementedError on ref...
  • 89310be chore(main): release google-crc32c 1.9.0 (#18459)
  • 9cb21d0 fix: regenerate gencode with protobuf 6.33.5 (#18461)
  • 54f1019 feat: update API sources and regenerate (#18446)
  • a04c831 feat(firestore): add BSONDecimal128 support (#18395)
  • 1bf979a fix(crc32c): remove stale pypy reference from README (#18458)
  • fdaa618 chore(crc32c): run manylinux wheel validation and upload in isolated Python 3...
  • 5fe1ef3 feat: add 3.15 support to gapic library classifiers (#18450)
  • Additional commits viewable in compare view

Updates googleapis-common-protos from 1.75.0 to 1.75.4

Commits
  • c0208c6 chore: release main (#18421)
  • e654dc2 chore(main): release google-auth 2.58.1 (#18462)
  • 1665e68 fix(auth): allow mTLS retry when credentials raise NotImplementedError on ref...
  • 89310be chore(main): release google-crc32c 1.9.0 (#18459)
  • 9cb21d0 fix: regenerate gencode with protobuf 6.33.5 (#18461)
  • 54f1019 feat: update API sources and regenerate (#18446)
  • a04c831 feat(firestore): add BSONDecimal128 support (#18395)
  • 1bf979a fix(crc32c): remove stale pypy reference from README (#18458)
  • fdaa618 chore(crc32c): run manylinux wheel validation and upload in isolated Python 3...
  • 5fe1ef3 feat: add 3.15 support to gapic library classifiers (#18450)
  • Additional commits viewable in compare view

Updates packaging from 26.2 to 26.3

Release notes

Sourced from packaging's releases.

26.3

What's Changed

Features

  • Add a public VersionRange API and SpecifierSet.to_range(), representing the versions a specifier set accepts as an interval set that supports intersection, union, difference, complement, set relations, membership tests, and filtering. VersionRange.to_specifier_set() converts a range back to a SpecifierSet where a PEP 440 form exists. (#1267, #1270, #1298)
  • PEP 808: accept Metadata-Version: 2.6. (#1194)
  • Add a limit argument to parse_tag() for compressed tag sets. (#1220)
  • Add a prefer_sdist_predicate argument to Pylock.select() to prefer source distributions over wheels for selected packages. (#1334)
  • Add pure_python_tags() to generate the pure-Python tags for a Python version without touching the running platform. (#1346)
  • Add SpecifierSet.is_subset(), SpecifierSet.is_superset(), and SpecifierSet.is_disjoint(), which compare the versions two specifier sets accept. (#1313)

Behavior adaptations

  • Drop support for Python 3.8; packaging now requires Python 3.9 or later. (#1157)
  • Prefer native linux_* platform tags over manylinux and musllinux tags on Linux. (#160)

Fixes for versions and specifiers

  • Raise InvalidVersion instead of TypeError when Version is given a non-string. (#1319)
  • Raise InvalidVersion for non-string pre-release letters passed to Version.from_parts. (#1241)
  • Fix an AttributeError when hashing internally trimmed versions. (#1242)
  • Fix SpecifierSet.is_unsatisfiable for post-release boundary intersections. (#1257)

Fixes for requirements and markers

  • Make Requirement.__hash__ consistent with __eq__ for trailing-zero-equivalent specifiers (e.g. foo==1.0.0 and foo==1.0.0.0), so equal requirements hash equal and deduplicate in sets and dicts. (#1232)
  • Normalize requested extra names before comparing or hashing requirements. (#644)
  • Preserve a Requirement's specifier prereleases override across a pickle round trip. (#1204)
  • Raise InvalidRequirement instead of InvalidSpecifier when a requirement contains an invalid specifier. (#1332)
  • Clarify the error for post-release prefix wildcards like ==1.0.post1.*. (#1299)
  • Preserve quoting semantics when serializing marker values, so round-tripped markers parse back to the same marker. (#1213)
  • Keep the parentheses of a nested group when serializing markers. (#1316)
  • Normalize extra and dependency_groups values in nested markers at parse time. (#1246, #1310)
  • Raise UndefinedComparison when a set-valued variable like extras is used outside the membership form. (#1265)
  • Raise UndefinedEnvironmentName (a KeyError subclass) for missing environment keys during marker evaluation. (#1276)
  • Wrap malformed string literal errors in InvalidMarker / InvalidRequirement instead of leaking a low-level error. (#1249)
  • Reject requirements and markers with a trailing line break. (#1345)

Fixes for metadata and licenses

  • Collect all from_email validation errors into one ExceptionGroup instead of raising the first. (#1268)
  • Accept the UTF-8 charset case-insensitively in email payloads. (#1330)
  • Reject malformed Description-Content-Type values. (#1329)
  • Don't rewrite user values that contain {field} placeholders in error messages. (#1327)
  • Route multipart email payloads to unparsed instead of asserting. (#1247)
  • Make InvalidMetadata and CyclicDependencyGroup picklable. (#1328)
  • Fold every line boundary str.splitlines recognizes when writing a header with RFC822Message. (#1356)

... (truncated)

Changelog

Sourced from packaging's changelog.

26.3 - 2026-08-03


Features:
  • Add a public :class:~packaging.ranges.VersionRange API and
    :meth:SpecifierSet.to_range() <packaging.specifiers.SpecifierSet.to_range>,
    representing the versions a specifier set accepts as an interval set that
    supports intersection, union, difference, complement, set relations,
    membership tests, and filtering.
    :meth:~packaging.ranges.VersionRange.to_specifier_set converts a range back
    to a :class:~packaging.specifiers.SpecifierSet where a PEP 440 form exists.
    (:pull:1267, :pull:1270, :pull:1298)
  • PEP 808: accept Metadata-Version: 2.6. (:pull:1194)
  • Add a limit argument to parse_tag() for compressed tag sets.
    (:issue:1220)
  • Add a prefer_sdist_predicate argument to Pylock.select() to prefer
    source distributions over wheels for selected packages. (:pull:1334)
  • Add :func:~packaging.tags.pure_python_tags to generate the pure-Python
    tags for a Python version without touching the running platform.
    (:pull:1346)
  • Add :meth:SpecifierSet.is_subset() <packaging.specifiers.SpecifierSet.is_subset>, :meth:~packaging.specifiers.SpecifierSet.is_superset,
    and :meth:~packaging.specifiers.SpecifierSet.is_disjoint, which compare the
    versions two specifier sets accept. (:pull:1313)

Behavior adaptations:

  • Drop support for Python 3.8; packaging now requires Python 3.9 or later.
    (:pull:1157)
  • Prefer native linux_* platform tags over manylinux and musllinux
    tags on Linux. (:issue:160)

Fixes for versions and specifiers:

  • Raise InvalidVersion instead of TypeError when Version is given a
    non-string. (:pull:1319)
  • Raise InvalidVersion for non-string pre-release letters passed to
    Version.from_parts. (:pull:1241)
  • Fix an AttributeError when hashing internally trimmed versions.
    (:pull:1242)
  • Fix SpecifierSet.is_unsatisfiable for post-release boundary
    intersections. (:pull:1257)

Fixes for requirements and markers:

  • Make Requirement.__hash__ consistent with __eq__ for
    trailing-zero-equivalent specifiers (e.g. foo==1.0.0 and
    foo==1.0.0.0), so equal requirements hash equal and deduplicate in
    sets and dicts. (:pull:1232)
    </tr></table>

... (truncated)

Commits
  • 929fd4b Bump for release
  • f300ebf chore(deps): bump the pre-commit group with 5 updates (#1357)
  • f91d975 ci(downstream): bump hatchling to 1.31.0 and fix its pytest rootdir (#1361)
  • b1a7124 chore(deps): bump the github-actions group with 7 updates (#1358)
  • 2d873eb fix(metadata): fold every line boundary when writing headers (#1356)
  • 413d006 docs: changelog for 26.3 (#1343)
  • 4eb0753 docs(metadata): explain selective field validation (#1342)
  • 77e9ed4 feat(tags): add pure Python tag generator (#1346)
  • 7cea5e8 ci: drop 3.13t on Windows (3.13.14t may fail to build, run takes 9 minutes) (...
  • 45a8b34 docs: add missing versionadded/versionchanged directives (#1344)
  • Additional commits viewable in compare view

Updates sse-starlette from 3.4.4 to 3.5.0

Release notes

Sourced from sse-starlette's releases.

v3.5.0

Fixed

  • A stopped uvicorn server no longer cancels SSE streams of later servers in the same process (#211, regression since 3.1.1). Typical trigger: test suites starting a real server per test.

Behaviour change

  • AppStatus.should_exit is no longer set when sse-starlette detects uvicorn's own Server.should_exit (fallback path, e.g. uvicorn "module:app"). Streams still close on shutdown. If you read AppStatus.should_exit to detect shutdown, use shutdown_event instead.
  • A real SIGTERM/SIGINT still sets AppStatus.should_exit process-wide; see README "Testing" if your tests send real signals to an in-process server.

Upgrade note

  • If you called AppStatus.disable_automatic_graceful_drain() only to work around #211, remove it to get automatic stream draining back.

What's Changed

Full Changelog: sysid/sse-starlette@v3.4.11...v3.5.0

v3.4.11

What's Changed

New Contributors

Full Changelog: sysid/sse-starlette@v3.4.10...v3.4.11

v3.4.10

What's Changed

New Contributors

Full Changelog: sysid/sse-starlette@v3.4.9...v3.4.10

v3.4.9

What's Changed

Full Changelog: sysid/sse-starlette@v3.4.8...v3.4.9

v3.4.8

... (truncated)

Commits
  • 1705b2d Bump version to 3.5.0
  • 16179fd Merge pull request #212 from sysid/fix/issue211
  • 3821353 fix(shutdown): re-resolve uvicorn server on every watcher poll
  • 6925c68 fix(tests): import httpx2 instead of removed httpx dependency
  • aa3b89e build(deps): bump starlette to 1.7.0 for anyio BlockingPortal deprecation
  • 329a72c build(deps): bump anyio, autobahn, setuptools for security advisories
  • d43a29f test(experimentation): assert consumer line counts in main thread
  • 96afe01 fix(shutdown): stop latching AppStatus.should_exit from uvicorn state
  • 6754ef3 Bump version to 3.4.11
  • 25bcc15 fix(examples): make broadcast stream terminal after cleanup
  • Additional commits viewable in compare view

Updates starlette from 1.2.1 to 1.7.0

Release notes

Sourced from starlette's releases.

Version 1.7.0

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING] OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

Full changelog: 1.6.0...1.7.0

Version 1.6.0

What's Changed

New Contributors

Full Changelog: Kludex/starlette@1.5.1...1.6.0

... (truncated)

Changelog

Sourced from starlette's changelog.

1.7.0 (September 23, 2026)

This release adds experimental OpenTelemetry tracing and requires AnyIO 4.

!!! warning "OpenTelemetryMiddleware is experimental" Its API and emitted telemetry may change in minor releases without a deprecation period #3574.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

1.6.0 (August 8, 2026)

Added

  • Add max_body_size to Starlette and route classes #3431.
  • Expose http.response.debug information via response extensions #3130.

1.5.1 (August 8, 2026)

... (truncated)

Commits
  • 2269e9a Version 1.7.0 (#3575)
  • 4fe55eb Preserve FileResponse status for range requests (#3568)
  • 1f08daf Mark OpenTelemetryMiddleware as experimental (#3574)
  • 57de5fa Support HTTP response trailers in TestClient (#3563)
  • 03f12b7 Allow HTTPException to use non-standard status codes (#3545)
  • 76fd00f Reject WebSocket requests to StaticFiles (#3532)
  • f03f65c docs: fix 'its not available' and 'This ensure' wording (#3526)
  • 485aca4 docs: the test client is built on httpx2, not httpx (#3525)
  • fd662b1 Implement identity on SimpleUser and UnauthenticatedUser (#3271)
  • 41db6a7 Stabilize CodSpeed upload buffer allocations (#3524)
  • Additional commits viewable in compare view

Updates fastapi from 0.136.3 to 0.141.1

Release notes

Sourced from fastapi's releases.

0.141.1

Fixes

  • 🐛 Fix support for background tasks and headers from dependencies in app.frontend(). PR #16105 by @​tiangolo.

Docs

0.141.0

Features

  • ✨ Add app.frontend(check_dir="auto"), to make local development more convenient with fastapi dev. PR #16102 by @​tiangolo.

0.140.13

Fixes

Docs

0.140.12

Fixes

0.140.11

Fixes

  • 🐛 Fix response_model_* params ignored for non-generator endpoints with Iterable[..] return type. PR #15093 by @​YuriiMotov.

0.140.10

Fixes

Internal

0.140.9

Fixes

  • 🐛 Fix exclude_defaults not propagated to dict keys and values in jsonable_encoder. PR #16043 by @​MBGrao.

... (truncated)

Commits
  • 95f8322 🔖 Release version 0.141.1 (#16106)
  • f137944 📝 Update release notes
  • d623544 🐛 Fix support for background tasks and headers from dependencies in `app.fron...
  • 1d211b9 📝 Update release notes
  • 8a1f876 📝 Document FASTAPI_ENV in FastAPI CLI guide (#16104)
  • c7e7b65 🔖 Release version 0.141.0 (#16103)
  • 6bceb84 📝 Update release notes
  • 5429fed ✨ Add app.frontend(check_dir="auto"), to make local development more conven...
  • 628663f 🔖 Release version 0.140.13 (#16096)
  • 0b54fd0 📝 Update release notes
  • Additional commits viewable in compare view

Updates cryptography from 48.0.1 to 50.0.1

Changelog

Sourced from cryptography's changelog.

50.0.1 - 2026-08-25


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.

.. _v50-0-0:

50.0.0 - 2026-07-31

  • SECURITY ISSUE: :func:~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a RecipientInfo's encryptedKey, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages. A random key is now substituted on failure, as described in :rfc:3218. Credit to @​X1AOxiang for reporting the issue. CVE-2026-69247
  • Deprecated Diffie-Hellman key exchange over finite fields (FFDH). Everything FFDH is deprecated, including the types in cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or parameters with the key loading APIs. Users should migrate to a more modern key exchange algorithm.
  • Added xof() class methods to :class:~cryptography.hazmat.primitives.hashes.SHAKE128 and :class:~cryptography.hazmat.primitives.hashes.SHAKE256 for constructing algorithm instances configured for use with :class:~cryptography.hazmat.primitives.hashes.XOFHash.
  • The :mod:X.509 verification <cryptography.x509.verification> APIs are now considered stable and are subject to our API stability policy.
  • Added the :doc:/cobblestone recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification <https://c2sp.org/chunked-encryption>_ for streaming authenticated encryption of large messages.
  • Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT, instead of silently ignoring them.
  • Added support for using :class:~cryptography.x509.Name as a field type in the :doc:/hazmat/asn1/index module.
  • Loading a public key or an EC private key now rejects DER where the subjectPublicKey (or EC publicKey) BIT STRING declares a non-zero number of unused bits, instead of silently ignoring it.
  • Parsing a CRL entry's InvalidityDate extension now rejects a GeneralizedTime that carries fractional seconds or another non-DER form, matching the strict encoding already required for every other X.509 time field.
  • :func:~cryptography.x509.ocsp.load_der_ocsp_request and :func:~cryptography.x509.ocsp.load_der_ocsp_response now reject a request or response whose version field is not v1, the only version defined by RFC 6960, matching the version validation already performed when loading

... (truncated)

Commits

Updates opentelemetry-api from 1.42.1 to 1.45.0

Release notes

Sourced from opentelemetry-api's releases.

Version 1.45.0/0.66b0

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions define as a valid value for this metric. (#5509)
  • opentelemetry-semantic-conventions: update semantic conventions to v1.44.0 (#5511)
  • opentelemetry-sdk: add host.id to the host resource detector (#5653)
  • opentelemetry-test-utils: add CapturingSampler to record what samplers receive in instrumentation tests (#5681)

Changed

  • Enable PIE (flake8-pie) ruff rule and fix all violations (#5150)
  • The public opentelemetry.util.types.AttributeValue type in package opentelemetry-api is being expanded to include None, heterogeneous sequences of primitive types (and nested sequences) as opposed to only homogeneous primitive sequences, and Mappings of strings to any primitive types or sequences/mappings (which themselves must only contain primitive types or sequences/mappings validated the same way). If a bytes type is set as an attribute value in the SDK, it will no longer be utf-8 decoded to a string, instead it will be passed along as is in accordance with the OTEL spec, since bytes is a valid type in the OTLP proto. (#5266)
  • opentelemetry-exporter-otlp-proto-http: add a max_request_size argument to the OTLP HTTP exporters (traces, logs, metrics); serialized requests larger than the limit are dropped before sending, measured before compression. Defaults to 64 MiB (enabled); set to 0 to disable. Mirrors opentelemetry-go#8157. (#5369)
  • [BREAKING] opentelemetry-api: subclasses of Logger need to implement the enabled method (#5380)
  • opentelemetry-exporter-otlp-proto-http: refactor to use shared opentelemetry-exporter-otlp-common and opentelemetry-exporter-http-transport packages and switch default HTTP backend to urllib3 (#5389)
  • opentelemetry-sdk: unify logging force_flush time...

    Description has been truncated

@dependabot dependabot Bot added dependencies python:uv Pull requests that update python:uv code labels Oct 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 1, 2026 06:54
@dependabot dependabot Bot added dependencies python:uv Pull requests that update python:uv code labels Oct 1, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/all-9eab276878 branch from 0a97787 to b4465ce Compare October 1, 2026 17:50
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🧪 Code Coverage (vs main)

⬇️ Download Full Report

No coverage changes.

Generated by coverage-comment.yml

Bumps the all group with 21 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |
| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.31.0` | `2.39.0` |
| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.75.0` | `1.75.4` |
| [packaging](https://github.com/pypa/packaging) | `26.2` | `26.3` |
| [sse-starlette](https://github.com/sysid/sse-starlette) | `3.4.4` | `3.5.0` |
| [starlette](https://github.com/Kludex/starlette) | `1.2.1` | `1.7.0` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |
| [cryptography](https://github.com/pyca/cryptography) | `48.0.1` | `50.0.1` |
| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.42.1` | `1.45.0` |
| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.42.1` | `1.45.0` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.15.0` |
| [alembic](https://github.com/sqlalchemy/alembic) | `1.18.4` | `1.20.0` |
| [pytest](https://github.com/pytest-dev/pytest) | `9.0.3` | `9.1.1` |
| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` | `3.16.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.16` | `0.16.9` |
| [uv-dynamic-versioning](https://github.com/ninoseki/uv-dynamic-versioning) | `0.14.0` | `0.14.1` |
| [types-requests](https://github.com/python/typeshed) | `2.33.0.20260518` | `2.33.0.20260906` |
| [pre-commit](https://github.com/pre-commit/pre-commit) | `4.6.0` | `4.6.2` |
| [trio](https://github.com/python-trio/trio) | `0.33.0` | `0.34.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.49.0` | `0.54.0` |
| [ty](https://github.com/astral-sh/ty) | `0.0.44` | `0.0.84` |



Updates `pydantic` from 2.13.4 to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.13.4...v2.13.5)

Updates `google-api-core` from 2.31.0 to 2.39.0
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/CHANGELOG.md)
- [Commits](googleapis/google-cloud-python@google-api-core-v2.31.0...google-api-core-v2.39.0)

Updates `googleapis-common-protos` from 1.75.0 to 1.75.4
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](googleapis/google-cloud-python@googleapis-common-protos-v1.75.0...googleapis-common-protos-v1.75.4)

Updates `packaging` from 26.2 to 26.3
- [Release notes](https://github.com/pypa/packaging/releases)
- [Changelog](https://github.com/pypa/packaging/blob/main/CHANGELOG.rst)
- [Commits](pypa/packaging@26.2...26.3)

Updates `sse-starlette` from 3.4.4 to 3.5.0
- [Release notes](https://github.com/sysid/sse-starlette/releases)
- [Commits](sysid/sse-starlette@v3.4.4...v3.5.0)

Updates `starlette` from 1.2.1 to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.2.1...1.7.0)

Updates `fastapi` from 0.136.3 to 0.141.1
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.136.3...0.141.1)

Updates `cryptography` from 48.0.1 to 50.0.1
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@48.0.1...50.0.1)

Updates `opentelemetry-api` from 1.42.1 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.42.1...v1.45.0)

Updates `opentelemetry-sdk` from 1.42.1 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.42.1...v1.45.0)

Updates `pyjwt` from 2.13.0 to 2.15.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.13.0...2.15.0)

Updates `alembic` from 1.18.4 to 1.20.0
- [Release notes](https://github.com/sqlalchemy/alembic/releases)
- [Changelog](https://github.com/sqlalchemy/alembic/blob/main/CHANGES)
- [Commits](https://github.com/sqlalchemy/alembic/commits)

Updates `pytest` from 9.0.3 to 9.1.1
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest@9.0.3...9.1.1)

Updates `pytest-mock` from 3.15.1 to 3.16.0
- [Release notes](https://github.com/pytest-dev/pytest-mock/releases)
- [Changelog](https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest-mock@v3.15.1...v3.16.0)

Updates `ruff` from 0.15.16 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.16...0.16.9)

Updates `uv-dynamic-versioning` from 0.14.0 to 0.14.1
- [Release notes](https://github.com/ninoseki/uv-dynamic-versioning/releases)
- [Commits](ninoseki/uv-dynamic-versioning@v0.14.0...v0.14.1)

Updates `types-requests` from 2.33.0.20260518 to 2.33.0.20260906
- [Commits](https://github.com/python/typeshed/commits)

Updates `pre-commit` from 4.6.0 to 4.6.2
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md)
- [Commits](pre-commit/pre-commit@v4.6.0...v4.6.2)

Updates `trio` from 0.33.0 to 0.34.0
- [Release notes](https://github.com/python-trio/trio/releases)
- [Commits](python-trio/trio@v0.33.0...v0.34.0)

Updates `uvicorn` from 0.49.0 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.49.0...0.54.0)

Updates `ty` from 0.0.44 to 0.0.84
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.44...0.0.84)

---
updated-dependencies:
- dependency-name: alembic
  dependency-version: 1.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: cryptography
  dependency-version: 50.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all
- dependency-name: fastapi
  dependency-version: 0.141.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: google-api-core
  dependency-version: 2.39.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: googleapis-common-protos
  dependency-version: 1.75.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: opentelemetry-api
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: opentelemetry-sdk
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: packaging
  dependency-version: '26.3'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: pre-commit
  dependency-version: 4.6.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: pytest
  dependency-version: 9.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: pytest-mock
  dependency-version: 3.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: sse-starlette
  dependency-version: 3.4.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: trio
  dependency-version: 0.34.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: ty
  dependency-version: 0.0.84
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: types-requests
  dependency-version: 2.33.0.20260906
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: uv-dynamic-versioning
  dependency-version: 0.14.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/all-9eab276878 branch from b4465ce to efcec70 Compare October 1, 2026 18:00

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants