Skip to content

deps: python-all batch — SQLAlchemy 2.1, FastAPI 0.142 and 13 more; Stripe 16 held back - #200

Merged
MrChengLen merged 3 commits into
mainfrom
dependabot/pip/python-all-8ae3af6e5e
Oct 8, 2026
Merged

MrChengLen merged 3 commits into
mainfrom
dependabot/pip/python-all-8ae3af6e5e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on fastapi, uvicorn, python-multipart, pydantic, pillow, mammoth, pikepdf, reportlab, markdown, python-dotenv, sqlalchemy, stripe, httpx, ruff, uv and cyclonedx-bom to permit the latest version.
Updates fastapi to 0.142.2

Release notes

Sourced from fastapi's releases.

0.142.2

Fixes

  • 🐛 Allow startup when automatic OpenTelemetry configuration fails. PR #16418 by @​tiangolo.
Commits

Updates uvicorn to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)

0.53.0 (September 14, 2026)

This release adds experimental HTTP/2 support through zttp. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

Added

  • Add experimental HTTP/2 support through zttp (#2982, #3101)
  • Add support for zuvloop (#3104)

Fixed

  • Handle comma-separated, case-insensitive Connection: close tokens across HTTP implementations (#3103)
  • Trust IPv6 loopback in the default FORWARDED_ALLOW_IPS value (#3119)
  • Cancel the HTTP keep-alive timer when upgrading to WebSocket (#3107)

0.52.4 (August 18, 2026)

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

0.52.3 (August 13, 2026)

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

0.52.2 (August 13, 2026)

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

0.52.1 (August 1, 2026)

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)

... (truncated)

Commits

Updates python-multipart to 0.0.32

Release notes

Sourced from python-multipart's releases.

Version 0.0.32

What's Changed

Full Changelog: Kludex/python-multipart@0.0.31...0.0.32

Changelog

Sourced from python-multipart's changelog.

0.0.32 (2026-06-04)

  • Speed up partial-boundary scanning for CR/LF-dense part data #300.

0.0.31 (2026-06-04)

  • Speed up multipart header parsing and callback dispatch #295.
  • Bound header field name size before validating #296.
  • Validate Content-Length is non-negative in parse_form #297.

0.0.30 (2026-05-31)

  • Parse application/x-www-form-urlencoded bodies per the WHATWG URL standard, treating only & as a field separator #290.
  • Ignore RFC 2231/5987 extended parameters (name*, filename*) in parse_options_header, keeping the plain parameter authoritative per RFC 7578 §4.2 #291.

0.0.29 (2026-05-17)

  • Handle malformed RFC 2231 continuations in parse_options_header #270.

0.0.28 (2026-05-10)

  • Speed up partial-boundary tail scan via bytes.find #281.
  • Cap multipart boundary length at 256 bytes #282.

0.0.27 (2026-04-27)

  • Add multipart header limits #267.
  • Pass parse offsets via constructors #268.

0.0.26 (2026-04-10)

  • Skip preamble before the first multipart boundary more efficiently #262.
  • Silently discard epilogue data after the closing multipart boundary #259.

0.0.25 (2026-04-10)

  • Add MIME content type info to File #143.
  • Handle CTE values case-insensitively #258.
  • Remove custom FormParser classes #257.
  • Add UPLOAD_DELETE_TMP to FormParser config #254.
  • Emit field_end for trailing bare field names on finalize #230.
  • Handle multipart headers case-insensitively #252.
  • Apply Apache-2.0 properly #247.

0.0.24 (2026-04-05)

  • Validate chunk_size in parse_form() #244.

0.0.23 (2026-04-05)

... (truncated)

Commits
  • 238ead6 Version 0.0.32 (#302)
  • 8672979 Replace per-byte partial-boundary scan with rfind lookbehind (#300)
  • 8190779 Bump the python-packages group with 7 updates (#301)
  • 0d3c086 Use uv package ecosystem for Dependabot (#299)
  • 4cffc68 Version 0.0.31 (#298)
  • c814948 Reject negative Content-Length in parse_form (#297)
  • 6b837d4 Bound header field name size before validating (#296)
  • e0c4f9d Bump the github-actions group with 3 updates (#294)
  • b8a01bb Bump the python-packages group with 3 updates (#293)
  • 6732164 Speed up multipart header parsing and callback dispatch (#295)
  • Additional commits viewable in compare view

Updates pydantic to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731

v2.13.4 (2026-05-06)

GitHub release

What's Changed

Packaging

Fixes

v2.13.3 (2026-04-20)

GitHub release

What's Changed

Fixes

v2.13.2 (2026-04-17)

GitHub release

What's Changed

Fixes

  • Fix ValidationInfo.field_name missing with model_validate_json() by @​Viicos in #13084

v2.13.1 (2026-04-15)

... (truncated)

Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates pillow to 12.3.0

Release notes

Sourced from pillow's releases.

12.3.0

https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html

Removals

Documentation

Dependencies

Testing

... (truncated)

Changelog

Sourced from pillow's changelog.

Changelog (Pillow)

11.1.0 and newer

See GitHub Releases:

11.0.0 (2024-10-15)

  • Update licence to MIT-CMU #8460 [hugovk]

  • Conditionally define ImageCms type hint to avoid requiring core #8197 [radarhere]

  • Support writing LONG8 offsets in AppendingTiffWriter #8417 [radarhere]

  • Use ImageFile.MAXBLOCK when saving TIFF images #8461 [radarhere]

  • Do not close provided file handles with libtiff when saving #8458 [radarhere]

  • Support ImageFilter.BuiltinFilter for I;16* images #8438 [radarhere]

  • Use ImagingCore.ptr instead of ImagingCore.id #8341 [homm, radarhere, hugovk]

  • Updated EPS mode when opening images without transparency #8281 [Yay295, radarhere]

  • Use transparency when combining P frames from APNGs #8443 [radarhere]

  • Support all resampling filters when resizing I;16* images #8422 [radarhere]

  • Free memory on early return #8413 [radarhere]

  • Cast int before potentially exceeding INT_MAX #8402 [radarhere]

... (truncated)

Commits
  • bb1d8e8 12.3.0 version bump
  • e63fc48 Add release notes for SBOM and performance improvements (#9747)
  • 13b701b Add release notes for #9679
  • 5564ca7 List methods
  • a0920fd Speed up ImageChops operations (#9738)
  • 07e9a6c Speed up Image.filter() (#9736)
  • a94578c Speed up Image.getchannel(), Image.merge(), Image.putalpha() and `Image...
  • 53e02c4 Speed up Image.fill(), Image.linear_gradient() and `Image.radial_gradient...
  • af03747 Speed up Image.resample() (#9739)
  • 5c9ca56 Speed up alpha_composite, matrix, negative, quantize (#9740)
  • Additional commits viewable in compare view

Updates mammoth to 1.13.0

Changelog

Sourced from mammoth's changelog.

1.13.0

  • Read the children of w:customXml elements.

  • Handle paragraphs and runs that have been moved and tracked as a revision.

  • Improve escaping in Markdown writer. This avoids some cases where source documents could inject arbitrary HTML into the converted document.

1.12.2

  • Avoid excessive backtracking when parsing an unterminated string with many escape sequences. The previous behaviour would allow maliciously crafted documents to cause a denial of service.

    Note that it is still strongly recommended to process untrusted documents in a separate thread with a timeout to avoid potential similar issues.

  • Handle complex field separator and end characters without corresponding start characters.

1.12.1

  • Fix: on Windows, when an image's content type includes a backslash in the subpart, files may be written outside of the directory set by --output-dir.

  • Detect and ignore numbering levels that use numStyleLink to refer to themselves.

1.12.0

  • Handle hyperlinked wp:anchor and wp:inline elements.

  • Handle hyperlink complex fields with unquoted hrefs.

1.11.0

  • Ignore style definitions using a style ID that has already been used.

  • Fix conversion of unmerged table cells.

  • Disable external file accesses by default. External file access can be enabled using the external_file_access argument.

  • Handle numbering levels defined without an index.

1.10.0

  • Add "Heading" and "Body" styles, as found in documents created by Apple Pages, to the default style map.

... (truncated)

Commits
  • f3b7b9f Bump version to 1.13.0
  • 072b5c9 Clarify implication of markdown escaping
  • 2c722f1 Escape markdown image alt text and src
  • 8dd0ce0 Escape markdown link hrefs
  • 2a5cf02 Escape HTML IDs in markdown writer
  • aa2253a Handle paragraphs and runs that have been moved and tracked as a revision
  • b582d77 Read the children of w:customXml elements
  • aa85b79 Bump version to 1.12.2
  • 2c398cf Start warning message with capital letter
  • d9678f1 Handle missing complex field start characters
  • Additional commits viewable in compare view

Updates pikepdf to 10.16.0

Release notes

Sourced from pikepdf's releases.

v10.16.0

  • Added binary wheels for Windows on ARM64. Thanks to @​ndabas. {issue}744
  • Binary wheels now bundle qpdf 12.4.2, which is also the new minimum version of qpdf, since it is the first release with Windows ARM64 binaries.
  • {func}pikepdf.sanitize.remove_javascript, {func}pikepdf.sanitize.remove_external_access, {func}pikepdf.sanitize.remove_multimedia and the matching {class}pikepdf.sanitize.Sanitizer steps missed actions attached to form field dictionaries. Actions survived on a field stored separately from its widget annotation, on a hidden field with no widget (such as a calculation helper), on nested fields under /Kids, and on widgets that appear on no page. The sanitizer now walks the whole /AcroForm field tree. Thanks to Stjorn for the report.
  • The same sanitizer steps left an action /Next chain untouched past its depth limit of 50, so a targeted action (for example a /JavaScript action) buried deeper survived, and the step that preserves benign downstream actions could promote it to a shallower position. The chain is now severed at the limit, which also drops any benign actions past it. Thanks to @​Nayana-Naik73. {issue}746
  • The sanitizer now also drops anything in a /Next chain that is not an action dictionary, such as a nested array, instead of passing it through unexamined. It raised AttributeError or ValueError on some such values (for example /Next [42]), and now runs in explicit conversion mode regardless of the caller's settings, so malformed values of the wrong type are skipped rather than crashing it.
Commits
  • 23290bd Bump version: v10.16.0
  • 54be8fe Fail closed on malformed /Next chains; run sanitizer in explicit mode
  • c7a71f2 Sanitize actions on every node of the AcroForm field tree
  • 62a1fd2 Merge branch 'pr-746'
  • f98cc01 Sever over-deep /Next action chains in sanitizer
  • 1947edb Merge branch 'pr-744'
  • d3d0440 Update release notes
  • 111dc16 Remove hardcoded path to qpdf on Windows
  • 7aff911 Update docs for Windows ARM64 build
  • 22e0547 Add Windows ARM64 build
  • Additional commits viewable in compare view

Updates reportlab to 5.0.1

Updates markdown to 3.11

Changelog

Sourced from markdown's changelog.


title: Changelog toc_depth: 2

Python-Markdown Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to the Python Version Specification. See the Contributing Guide for details.

[Unreleased]

  • Update serializer to be non-recursive (#1644).
  • Improve ancestor handling in the inline Treeprocessor (#1646).
  • Fix issue where inline HTML attributes were rejected if they had < or > in the attribute (#1647).
  • Fix issue where an unterminated end tag (</foo) could cause all remaining content to be dropped (#1651).

[3.11.0] - 2026-09-25

Changed

  • Inline processors now resume searching after the previous match, improving performance for repeated inline patterns (#1619).
  • Officially support Python 3.15 and drop support for Python 3.10
  • Walk backtick runs in BacktickInlineProcessor without a regex (#1620).
  • Switch static site generator for documentation from MkDocs to Zensical (#1627, #1635, #1637, and #1638).

Fixed

  • Ensure removing Abbreviations does not raise an error (#1634).
  • Fix an issue with excessive backtracking when matching inline code blocks (#1617).
  • md_in_html now honors tags added to Markdown.block_level_elements after the extension is loaded (#1246).
  • Fix quadratic-time regex backtracking in ReferenceProcessor when a link reference definition has no URL, e.g. a line consisting only of [id]: followed by many trailing spaces (#798).
  • Document attr_list usage for def_list (#1123).

[3.10.3] - 2026-07-30

Fixed

  • Fix SetextHeaderProcessor regex to prevent mixed = and - chars in setext-style headers (#1606).
  • Add AI Policy to Contributing Guide.
  • Officially document all included extensions as being in maintenance mode.

... (truncated)

Commits
  • 0ffbf00 Bump version to 3.11.0
  • 547a934 Show adminitions as rendered examples in contrbuting guide
  • 571f050 Cleanup archived changelog
  • a5176b0 Ensure py-render codeblock title in properly escaped.
  • 819fff9 Document the use of attr_list with def_list.
  • 36cdbd3 Final cleanup for Zensical transition
  • 8a96db5 Add py-render custom code block formater
  • 5d1363c Fix quadratic-time backtracking when a reference link has no URL
  • 0d6afd1 Add Markdown renderer as superfences formatter
  • 175fb5a Ensure removing Abbreviations does not raise an error.
  • Additional commits viewable in compare view

Updates python-dotenv to 1.2.4

Release notes

Sourced from python-dotenv's releases.

v1.2.4

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Changelog

Sourced from python-dotenv's changelog.

[1.2.4] - 2026-10-01

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698

[1.2.3] - 2026-08-16

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638

[1.2.2] - 2026-03-01

Added

  • Support for Python 3.14, including the free-threaded (3.14t) build. (#588)

Changed

  • The dotenv run command now forwards flags directly to the specified command by [@​bbc2] in #607
  • Improved documentation clarity regarding override behavior and the reference page.
  • Updated PyPy support to version 3.11.
  • Documentation for FIFO file support.
  • Dropped Support for Python 3.9.

Fixed

  • Improved set_key and unset_key behavior when interacting with symlinks by [@​bbc2] in [790c5c0]
  • Corrected the license specifier and added missing Python 3.14 classifiers in package metadata by [@​JYOuyang] in #590

Breaking Changes

  • dotenv.set_key and dotenv.unset_key used to follow symlinks in some situations. This is no longer the case. For that behavior to be restored in all cases, follow_symlinks=True should be used.

  • In the CLI, set and unset used to follow symlinks in some situations. This is no longer the case.

  • dotenv.set_key, dotenv.unset_key and the CLI commands set and unset used to reset the file mode of the modified .env file to 0o600 in some situations. This is no longer the case: The original mode of the file is now preserved. Is the file needed to be created or wasn't a regular file, mode 0o600 is used.

... (truncated)

Commits
  • a565c2c Bump version: 1.2.3 → 1.2.4
  • 4a7abd0 docs: add 1.2.4 release notes (#663, #698, #700)
  • f215c02 fix: dotenv get exits 0 for empty string values (#700)
  • 58f2d7c test: make test_run_with_command_flags portable and meaningful (#709)
  • e0310e5 fix: honor --no-override when expanding variables in dotenv run (#698)
  • a00cb2e docs: add CHANGELOG entry for #663 (fix #600)
  • f5485a6 fix: parse empty unquoted value with inline comment as empty string
  • See full diff in compare view

Updates sqlalchemy to 2.1.3

Release notes

Sourced from sqlalchemy's releases.

2.1.3

Released: October 2, 2026

orm

  • [orm] [bug] [regression] Fixed regression where columns delivered to a mapped class from an unmapped _orm.MappedAsDataclass mixin, or from a class decorated with _orm.unmapped_dataclass(), would not be placed in the _schema.Table in the order in which they were declared on the mixin; columns that had no dataclass default, such as a primary key column with no _orm.mapped_column.default, or which made use of _orm.mapped_column.default_factory, would be moved after the remaining columns of the mixin.

    References: #13634

sql

  • [sql] [bug] [regression] Fixed regression caused by the new implementation of ExecutableStatement.params() where parameter values established using this method would not be rendered when compiling the statement with the literal_binds compiler option, instead rendering NULL with a warning.

    References: #13635

Commits

Updates stripe to 16.0.0

Release notes

Sourced from stripe's releases.

v16.0.0

See the changelog for the full release notes.

Changelog

Sourced from stripe's changelog.

16.0.0 - 2026-09-30

This release changes the pinned API version to 2026-09-30.endive.

  • #1904 Support EventNotifications with singleton related objects

  • #1909 Allow suppressing Stripe notices

    Set the STRIPE_SUPPRESS_NOTICES environment variable to true to suppress Stripe notices in test and sandbox environments when not running under a detected AI agent. Notices remain enabled by default and continue to be shown to AI agents.

  • #1911 Fix account scoping for event notification handler callback clients

    • Fix callback clients to use the event's Stripe context and preserve the original client's non-account configuration.
    • Fix API errors when using an event notification handler with a client configured with a Stripe account.
  • ⚠️ #1914 Remove deprecated StripeObject.request() method

    The deprecated StripeObject.request() method has been removed. Use StripeClient.raw_request() to make custom API requests.

  • ⚠️ #1915 Rename stripe.Reversal to stripe.TransferReversal

    • ⚠️ Rename the stripe.Reversal resource class to stripe.TransferReversal. Update references and type annotations to use stripe.TransferReversal.
  • ⚠️ #1920 Make path parameters positional-only in all service methods

    Path parameters must now be passed positionally to service methods. Passing them by keyword is no longer supported. This prevents parameter names derived from the API specification from becoming part of the public interface.

    Resource methods are unaffected by this change.

  • ⚠️ #1924 Make path parameters positional-only in all service methods

    Path parameters must now be passed positionally on resource methods that support both classmethod and instance-method call styles (e.g. Coupon.delete). Passing them by keyword is no longer supported.

  • ⚠️ #1899 Update generated code

    • Add support for new resources apps.Install, product_catalog.TrialOffer, tax.Location, and three_d_secure.Authentication
    • Add support for create, list, modify, retrieve, and uninstall methods on resource apps.Install
    • Add support for create, list, modify, and retrieve methods on resource product_catalog.TrialOffer
    • Add support for createDescription has been truncated

Updates the requirements on [fastapi](https://github.com/fastapi/fastapi), [uvicorn](https://github.com/Kludex/uvicorn), [python-multipart](https://github.com/Kludex/python-multipart), [pydantic](https://github.com/pydantic/pydantic), [pillow](https://github.com/python-pillow/Pillow), [mammoth](https://github.com/mwilliamson/python-mammoth), [pikepdf](https://github.com/pikepdf/pikepdf), [reportlab](https://www.reportlab.com/), [markdown](https://github.com/Python-Markdown/markdown), [python-dotenv](https://github.com/theskumar/python-dotenv), [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy), [stripe](https://github.com/stripe/stripe-python), [httpx](https://github.com/encode/httpx), [ruff](https://github.com/astral-sh/ruff), [uv](https://github.com/astral-sh/uv) and [cyclonedx-bom](https://github.com/CycloneDX/cyclonedx-python) to permit the latest version.

Updates `fastapi` to 0.142.2
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.141.1...0.142.2)

Updates `uvicorn` to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.52.4...0.54.0)

Updates `python-multipart` to 0.0.32
- [Release notes](https://github.com/Kludex/python-multipart/releases)
- [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md)
- [Commits](Kludex/python-multipart@0.0.18...0.0.32)

Updates `pydantic` to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.13.4...v2.13.5)

Updates `pillow` to 12.3.0
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@10.3.0...12.3.0)

Updates `mammoth` to 1.13.0
- [Changelog](https://github.com/mwilliamson/python-mammoth/blob/master/NEWS)
- [Commits](mwilliamson/python-mammoth@1.12.1...1.13.0)

Updates `pikepdf` to 10.16.0
- [Release notes](https://github.com/pikepdf/pikepdf/releases)
- [Commits](pikepdf/pikepdf@v10.13.0.post1...v10.16.0)

Updates `reportlab` to 5.0.1

Updates `markdown` to 3.11
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](Python-Markdown/markdown@3.10.3...3.11.0)

Updates `python-dotenv` to 1.2.4
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.3...v1.2.4)

Updates `sqlalchemy` to 2.1.3
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

Updates `stripe` to 16.0.0
- [Release notes](https://github.com/stripe/stripe-python/releases)
- [Changelog](https://github.com/stripe/stripe-python/blob/master/CHANGELOG.md)
- [Commits](stripe/stripe-python@v15.6.1...v16.0.0)

Updates `httpx` to 0.28.1
- [Release notes](https://github.com/encode/httpx/releases)
- [Changelog](https://github.com/encode/httpx/blob/master/CHANGELOG.md)
- [Commits](encode/httpx@0.27.0...0.28.1)

Updates `ruff` from 0.16.9 to 0.16.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.9...0.16.10)

Updates `uv` from 0.12.19 to 0.12.22
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.19...0.12.22)

Updates `cyclonedx-bom` to 5.5.0
- [Release notes](https://github.com/CycloneDX/cyclonedx-python/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-python/blob/main/CHANGELOG.md)
- [Commits](CycloneDX/cyclonedx-python@v5.0.0...v5.5.0)

---
updated-dependencies:
- dependency-name: fastapi
  dependency-version: 0.142.2
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: python-multipart
  dependency-version: 0.0.32
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: pillow
  dependency-version: 12.3.0
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: mammoth
  dependency-version: 1.13.0
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: pikepdf
  dependency-version: 10.16.0
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: reportlab
  dependency-version: 5.0.1
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: markdown
  dependency-version: '3.11'
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: python-dotenv
  dependency-version: 1.2.4
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: sqlalchemy
  dependency-version: 2.1.3
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: stripe
  dependency-version: 16.0.0
  dependency-type: direct:production
  dependency-group: python-all
- dependency-name: httpx
  dependency-version: 0.28.1
  dependency-type: direct:development
  dependency-group: python-all
- dependency-name: ruff
  dependency-version: 0.16.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-all
- dependency-name: uv
  dependency-version: 0.12.22
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-all
- dependency-name: cyclonedx-bom
  dependency-version: 5.5.0
  dependency-type: direct:production
  dependency-group: python-all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

…w 16

Dependabot's python-all group raised 16 floors in requirements*.txt; the
lockfiles were not recompiled, so lint-and-test (constrained install) and
lockfile-drift were red by design. requirements.lock and requirements-uv.lock
are recompiled with uv 0.12.22 (requirements-sbom.lock needed no change).

Moves in the image: SQLAlchemy 2.0.52 -> 2.1.4, FastAPI 0.141.1 -> 0.142.2
(adds opentelemetry-api 1.45.0, dormant without an SDK), uvicorn 0.54.0,
pikepdf 10.16.0, mammoth 1.13.0, Markdown 3.11, python-dotenv 1.2.4. FastAPI
and opentelemetry-api are held to the versions Dependabot proposed via
--upgrade-package, because the newest ones were younger than the three-day
cooldown; the drift gate's plain recompile reproduces the file byte for byte.
SQLAlchemy stays on 2.1.4 despite its age: it fixes a connection leak and a
masked error on the asyncio/asyncpg path.

Stripe is capped at >=15.6.1,<16 and excluded from the Dependabot group:
stripe 16 pins API version 2026-09-30.endive, which no longer accepts
payment_method_types on Checkout session creation, so every checkout would be
rejected once keys are set. The tests mock that call; a new assertion in
tests/test_billing_consent.py compares the sent kwargs with the installed
SDK's SessionCreateParams, and it fails with stripe 16 (checked) until the
call is ported in its own PR.

Reviewed by security-auditor (hashes equal PyPI's for every moved package,
provenance unchanged or better, opentelemetry-api inert) and code-reviewer.
Verified: full suite 1664 passed / 80 skipped against exactly these versions
(local venv; Postgres and Linux-only tests run in CI); ruff clean; gitleaks
and the pre-commit scope guard clean. pip-audit: no new finding from this
batch.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@MrChengLen MrChengLen changed the title deps: Bump the python-all group with 16 updates deps: python-all batch — SQLAlchemy 2.1, FastAPI 0.142 and 13 more; Stripe 16 held back Oct 8, 2026
@MrChengLen
MrChengLen merged commit 8836232 into main Oct 8, 2026
6 checks passed
@MrChengLen
MrChengLen deleted the dependabot/pip/python-all-8ae3af6e5e branch October 8, 2026 08:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant