Repository navigation
deps: python-all batch — SQLAlchemy 2.1, FastAPI 0.142 and 13 more; Stripe 16 held back - #200
Merged
Merged
Conversation
Updates the requirements on [fastapi](https://github.com/fastapi/fastapi), [uvicorn](https://github.com/Kludex/uvicorn), [python-multipart](https://github.com/Kludex/python-multipart), [pydantic](https://github.com/pydantic/pydantic), [pillow](https://github.com/python-pillow/Pillow), [mammoth](https://github.com/mwilliamson/python-mammoth), [pikepdf](https://github.com/pikepdf/pikepdf), [reportlab](https://www.reportlab.com/), [markdown](https://github.com/Python-Markdown/markdown), [python-dotenv](https://github.com/theskumar/python-dotenv), [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy), [stripe](https://github.com/stripe/stripe-python), [httpx](https://github.com/encode/httpx), [ruff](https://github.com/astral-sh/ruff), [uv](https://github.com/astral-sh/uv) and [cyclonedx-bom](https://github.com/CycloneDX/cyclonedx-python) to permit the latest version. Updates `fastapi` to 0.142.2 - [Release notes](https://github.com/fastapi/fastapi/releases) - [Commits](fastapi/fastapi@0.141.1...0.142.2) Updates `uvicorn` to 0.54.0 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.52.4...0.54.0) Updates `python-multipart` to 0.0.32 - [Release notes](https://github.com/Kludex/python-multipart/releases) - [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md) - [Commits](Kludex/python-multipart@0.0.18...0.0.32) Updates `pydantic` to 2.13.5 - [Release notes](https://github.com/pydantic/pydantic/releases) - [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md) - [Commits](pydantic/pydantic@v2.13.4...v2.13.5) Updates `pillow` to 12.3.0 - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@10.3.0...12.3.0) Updates `mammoth` to 1.13.0 - [Changelog](https://github.com/mwilliamson/python-mammoth/blob/master/NEWS) - [Commits](mwilliamson/python-mammoth@1.12.1...1.13.0) Updates `pikepdf` to 10.16.0 - [Release notes](https://github.com/pikepdf/pikepdf/releases) - [Commits](pikepdf/pikepdf@v10.13.0.post1...v10.16.0) Updates `reportlab` to 5.0.1 Updates `markdown` to 3.11 - [Release notes](https://github.com/Python-Markdown/markdown/releases) - [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md) - [Commits](Python-Markdown/markdown@3.10.3...3.11.0) Updates `python-dotenv` to 1.2.4 - [Release notes](https://github.com/theskumar/python-dotenv/releases) - [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md) - [Commits](theskumar/python-dotenv@v1.2.3...v1.2.4) Updates `sqlalchemy` to 2.1.3 - [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases) - [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst) - [Commits](https://github.com/sqlalchemy/sqlalchemy/commits) Updates `stripe` to 16.0.0 - [Release notes](https://github.com/stripe/stripe-python/releases) - [Changelog](https://github.com/stripe/stripe-python/blob/master/CHANGELOG.md) - [Commits](stripe/stripe-python@v15.6.1...v16.0.0) Updates `httpx` to 0.28.1 - [Release notes](https://github.com/encode/httpx/releases) - [Changelog](https://github.com/encode/httpx/blob/master/CHANGELOG.md) - [Commits](encode/httpx@0.27.0...0.28.1) Updates `ruff` from 0.16.9 to 0.16.10 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.9...0.16.10) Updates `uv` from 0.12.19 to 0.12.22 - [Release notes](https://github.com/astral-sh/uv/releases) - [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md) - [Commits](astral-sh/uv@0.12.19...0.12.22) Updates `cyclonedx-bom` to 5.5.0 - [Release notes](https://github.com/CycloneDX/cyclonedx-python/releases) - [Changelog](https://github.com/CycloneDX/cyclonedx-python/blob/main/CHANGELOG.md) - [Commits](CycloneDX/cyclonedx-python@v5.0.0...v5.5.0) --- updated-dependencies: - dependency-name: fastapi dependency-version: 0.142.2 dependency-type: direct:production dependency-group: python-all - dependency-name: uvicorn dependency-version: 0.54.0 dependency-type: direct:production dependency-group: python-all - dependency-name: python-multipart dependency-version: 0.0.32 dependency-type: direct:production dependency-group: python-all - dependency-name: pydantic dependency-version: 2.13.5 dependency-type: direct:production dependency-group: python-all - dependency-name: pillow dependency-version: 12.3.0 dependency-type: direct:production dependency-group: python-all - dependency-name: mammoth dependency-version: 1.13.0 dependency-type: direct:production dependency-group: python-all - dependency-name: pikepdf dependency-version: 10.16.0 dependency-type: direct:production dependency-group: python-all - dependency-name: reportlab dependency-version: 5.0.1 dependency-type: direct:production dependency-group: python-all - dependency-name: markdown dependency-version: '3.11' dependency-type: direct:production dependency-group: python-all - dependency-name: python-dotenv dependency-version: 1.2.4 dependency-type: direct:production dependency-group: python-all - dependency-name: sqlalchemy dependency-version: 2.1.3 dependency-type: direct:production dependency-group: python-all - dependency-name: stripe dependency-version: 16.0.0 dependency-type: direct:production dependency-group: python-all - dependency-name: httpx dependency-version: 0.28.1 dependency-type: direct:development dependency-group: python-all - dependency-name: ruff dependency-version: 0.16.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-all - dependency-name: uv dependency-version: 0.12.22 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-all - dependency-name: cyclonedx-bom dependency-version: 5.5.0 dependency-type: direct:production dependency-group: python-all ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
This was referenced Oct 6, 2026
…w 16 Dependabot's python-all group raised 16 floors in requirements*.txt; the lockfiles were not recompiled, so lint-and-test (constrained install) and lockfile-drift were red by design. requirements.lock and requirements-uv.lock are recompiled with uv 0.12.22 (requirements-sbom.lock needed no change). Moves in the image: SQLAlchemy 2.0.52 -> 2.1.4, FastAPI 0.141.1 -> 0.142.2 (adds opentelemetry-api 1.45.0, dormant without an SDK), uvicorn 0.54.0, pikepdf 10.16.0, mammoth 1.13.0, Markdown 3.11, python-dotenv 1.2.4. FastAPI and opentelemetry-api are held to the versions Dependabot proposed via --upgrade-package, because the newest ones were younger than the three-day cooldown; the drift gate's plain recompile reproduces the file byte for byte. SQLAlchemy stays on 2.1.4 despite its age: it fixes a connection leak and a masked error on the asyncio/asyncpg path. Stripe is capped at >=15.6.1,<16 and excluded from the Dependabot group: stripe 16 pins API version 2026-09-30.endive, which no longer accepts payment_method_types on Checkout session creation, so every checkout would be rejected once keys are set. The tests mock that call; a new assertion in tests/test_billing_consent.py compares the sent kwargs with the installed SDK's SessionCreateParams, and it fails with stripe 16 (checked) until the call is ported in its own PR. Reviewed by security-auditor (hashes equal PyPI's for every moved package, provenance unchanged or better, opentelemetry-api inert) and code-reviewer. Verified: full suite 1664 passed / 80 skipped against exactly these versions (local venv; Postgres and Linux-only tests run in CI); ruff clean; gitleaks and the pre-commit scope guard clean. pip-audit: no new finding from this batch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the requirements on fastapi, uvicorn, python-multipart, pydantic, pillow, mammoth, pikepdf, reportlab, markdown, python-dotenv, sqlalchemy, stripe, httpx, ruff, uv and cyclonedx-bom to permit the latest version.
Updates
fastapito 0.142.2Release notes
Sourced from fastapi's releases.
Commits
78c4324🔖 Release version 0.142.2 (#16419)2579ed0📝 Update release notes1d4953d🐛 Allow startup when automatic OpenTelemetry configuration fails (#16418)3e33a03🔖 Release version 0.142.1 (#16415)12ea7f5📝 Update release notesac88f56🐛 Fix repeated endpoint wrapping in included routers (#16414)bd41128🔖 Release version 0.142.0 (#16411)7aa21e5📝 Update release notes4b3949c✨ Add native OpenTelemetry support (#16403)c30032a📝 Update release notesUpdates
uvicornto 0.54.0Release notes
Sourced from uvicorn's releases.
Changelog
Sourced from uvicorn's changelog.
... (truncated)
Commits
3eb9a9aVersion 0.54.0 (#3161)cd7ef6dRemove races from supervisor tests (#3134)a56c7ccSupport HTTP/2 response trailers (#3146)9bd4404chore(deps): bump anyio from 4.13.0 to 4.14.2 (#3145)21f39efAdd HTTP/2 Early Hints support (#3137)421708fVersion 0.53.0 (#3136)f1a1bffUnset the keep-alive timer when upgrading to WebSocket (#3107)63971edDocument HTTP/2 support (#3130)7d1a005Remove race from multiprocess health check test (#3128)5ac6265Add ::1 to FORWARDED_ALLOW_IPS (#3119)Updates
python-multipartto 0.0.32Release notes
Sourced from python-multipart's releases.
Changelog
Sourced from python-multipart's changelog.
... (truncated)
Commits
238ead6Version 0.0.32 (#302)8672979Replace per-byte partial-boundary scan with rfind lookbehind (#300)8190779Bump the python-packages group with 7 updates (#301)0d3c086Use uv package ecosystem for Dependabot (#299)4cffc68Version 0.0.31 (#298)c814948Reject negativeContent-Lengthinparse_form(#297)6b837d4Bound header field name size before validating (#296)e0c4f9dBump the github-actions group with 3 updates (#294)b8a01bbBump the python-packages group with 3 updates (#293)6732164Speed up multipart header parsing and callback dispatch (#295)Updates
pydanticto 2.13.5Release notes
Sourced from pydantic's releases.
Changelog
Sourced from pydantic's changelog.
... (truncated)
Commits
001dea0Bumppypa/gh-action-pypi-publishaction to v1.14.2558379fBump twine to v7.0.02cfd5d3Do not check for docs builda735beeFix more Clippy lints7eed4a1Fix Clippy 0.1.95 warningsb353bbbPrepare release v2.13.563d2cccCount validated model fields once in smart unionsa53ec2eSpeed up PyPy CI testsd65e0f9Workaround circular import error in Mypy47a6dbfFix missing GC traversal inpydantic-coreforGeneralFieldsSerializerUpdates
pillowto 12.3.0Release notes
Sourced from pillow's releases.
... (truncated)
Changelog
Sourced from pillow's changelog.
... (truncated)
Commits
bb1d8e812.3.0 version bumpe63fc48Add release notes for SBOM and performance improvements (#9747)13b701bAdd release notes for #96795564ca7List methodsa0920fdSpeed up ImageChops operations (#9738)07e9a6cSpeed upImage.filter()(#9736)a94578cSpeed upImage.getchannel(),Image.merge(),Image.putalpha()and `Image...53e02c4Speed upImage.fill(),Image.linear_gradient()and `Image.radial_gradient...af03747Speed upImage.resample()(#9739)5c9ca56Speed upalpha_composite,matrix,negative,quantize(#9740)Updates
mammothto 1.13.0Changelog
Sourced from mammoth's changelog.
... (truncated)
Commits
f3b7b9fBump version to 1.13.0072b5c9Clarify implication of markdown escaping2c722f1Escape markdown image alt text and src8dd0ce0Escape markdown link hrefs2a5cf02Escape HTML IDs in markdown writeraa2253aHandle paragraphs and runs that have been moved and tracked as a revisionb582d77Read the children of w:customXml elementsaa85b79Bump version to 1.12.22c398cfStart warning message with capital letterd9678f1Handle missing complex field start charactersUpdates
pikepdfto 10.16.0Release notes
Sourced from pikepdf's releases.
Commits
23290bdBump version: v10.16.054be8feFail closed on malformed /Next chains; run sanitizer in explicit modec7a71f2Sanitize actions on every node of the AcroForm field tree62a1fd2Merge branch 'pr-746'f98cc01Sever over-deep /Next action chains in sanitizer1947edbMerge branch 'pr-744'd3d0440Update release notes111dc16Remove hardcoded path to qpdf on Windows7aff911Update docs for Windows ARM64 build22e0547Add Windows ARM64 buildUpdates
reportlabto 5.0.1Updates
markdownto 3.11Changelog
Sourced from markdown's changelog.
... (truncated)
Commits
0ffbf00Bump version to 3.11.0547a934Show adminitions as rendered examples in contrbuting guide571f050Cleanup archived changeloga5176b0Ensure py-render codeblock title in properly escaped.819fff9Document the use of attr_list with def_list.36cdbd3Final cleanup for Zensical transition8a96db5Add py-render custom code block formater5d1363cFix quadratic-time backtracking when a reference link has no URL0d6afd1Add Markdown renderer as superfences formatter175fb5aEnsure removing Abbreviations does not raise an error.Updates
python-dotenvto 1.2.4Release notes
Sourced from python-dotenv's releases.
Changelog
Sourced from python-dotenv's changelog.
... (truncated)
Commits
a565c2cBump version: 1.2.3 → 1.2.44a7abd0docs: add 1.2.4 release notes (#663, #698, #700)f215c02fix: dotenv get exits 0 for empty string values (#700)58f2d7ctest: make test_run_with_command_flags portable and meaningful (#709)e0310e5fix: honor --no-override when expanding variables in dotenv run (#698)a00cb2edocs: add CHANGELOG entry for #663 (fix #600)f5485a6fix: parse empty unquoted value with inline comment as empty stringUpdates
sqlalchemyto 2.1.3Release notes
Sourced from sqlalchemy's releases.
Commits
Updates
stripeto 16.0.0Release notes
Sourced from stripe's releases.
Changelog
Sourced from stripe's changelog.