Skip to content

chore(deps): bump multidict from 6.9.1 to 7.0.0 in the aiohttp group - #139

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/aiohttp-c141bcaca4
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/aiohttp-c141bcaca4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the aiohttp group with 1 update: multidict.

Updates multidict from 6.9.1 to 7.0.0

Release notes

Sourced from multidict's releases.

7.0.0 is a major release. It makes istr final, adds a public C API for third-party extensions, and makes the C extension substantially faster across the board.

Breaking change. istr can no longer be subclassed, on either backend. Code that subclassed it has to wrap or convert instead. The C extension also started rejecting an argument passed both positionally and by name with TypeError, where it used to silently misbehave.

Public C and Cython API. Other C extensions and Cython modules can now create, read and mutate multidicts through a capsule, without going through the Python-level API. The capsule comes with multidict_capi.h, a cimport-able multidict/__init__.pxd and multidict.get_include(). The API includes MultiDict_ForEach() and a watchers API modeled on CPython's dict watchers. See the C API and Cython API references.

Performance. On CodSpeed's GIL-build benchmarks against 6.9.1, 82 C-extension benchmarks got faster and none got slower. Rough figures:

  • CIMultiDict keyed by plain str: construction, add(), extend(), update() and item assignment got 2 to 3.8 times faster, and lookups about 2 times faster.
  • CIMultiDict keyed by istr, and case-sensitive MultiDict: lookups, insertion and deletion got 10% to 70% faster.
  • getall() and iterating items() got about 35% faster, and the view set operations 10% to 85% faster.
  • popitem() on a whole mapping went from quadratic to linear time.
  • On the free-threaded build, measured in instructions against 6.9.1, lookups got 24% to 33% cheaper on MultiDict and 4 to 5 times cheaper on CIMultiDict with lowercase str keys, and item assignment 15% to 19% cheaper. Construction and deletion on MultiDict cost 2% to 7% more. With several threads mutating at once, a d[key] = value got about four times faster.

The pure-Python backend is unchanged in speed.

Robustness. This release fixed several crashes and leaks in the C extension, including use-after-free bugs when a key's lower() or a value's __eq__ mutated a multidict, a crash at interpreter shutdown, and table and reference leaks on the free-threaded build.

Bug fixes

... (truncated)

Changelog

Sourced from multidict's changelog.

7.0.0

(2026-09-26)

7.0.0 is a major release. It makes :class:~multidict.istr final, adds a public C API for third-party extensions, and makes the C extension substantially faster across the board.

Breaking change. :class:~multidict.istr can no longer be subclassed, on either backend. Code that subclassed it has to wrap or convert instead. The C extension also started rejecting an argument passed both positionally and by name with :exc:TypeError, where it used to silently misbehave.

Public C and Cython API. Other C extensions and Cython modules can now create, read and mutate multidicts through a capsule, without going through the Python-level API. The capsule comes with multidict_capi.h, a cimport-able multidict/__init__.pxd and :func:multidict.get_include. The API includes MultiDict_ForEach() and a watchers API modeled on CPython's dict watchers. See the :doc:C API <capi> and :doc:Cython API <cyapi> references.

Performance. On CodSpeed's GIL-build benchmarks against 6.9.1, 82 C-extension benchmarks got faster and none got slower. Rough figures:

  • :class:~multidict.CIMultiDict keyed by plain :class:str: construction, add(), extend(), update() and item assignment got 2 to 3.8 times faster, and lookups about 2 times faster.
  • :class:~multidict.CIMultiDict keyed by :class:~multidict.istr, and case-sensitive :class:~multidict.MultiDict: lookups, insertion and deletion got 10% to 70% faster.
  • :meth:~multidict.MultiDict.getall and iterating :meth:~multidict.MultiDict.items got about 35% faster, and the view set operations 10% to 85% faster.
  • :meth:~multidict.MultiDict.popitem on a whole mapping went from quadratic to linear time.
  • On the free-threaded build, measured in instructions against 6.9.1, lookups got 24% to 33% cheaper on :class:~multidict.MultiDict and 4 to 5 times cheaper on :class:~multidict.CIMultiDict with lowercase :class:str keys, and item assignment 15% to 19% cheaper. Construction and deletion on :class:~multidict.MultiDict cost 2% to 7% more. With several threads mutating at once, a d[key] = value got about four times faster.

The pure-Python backend is unchanged in speed.

Robustness. This release fixed several crashes and leaks in the C extension, including use-after-free bugs when a key's lower() or a value's __eq__ mutated a multidict, a crash at interpreter shutdown, and table and reference leaks on the free-threaded build.

... (truncated)

Commits
  • 72f7c3c Release 7.0.0 (#1603)
  • 2f84475 Fold new fragments and refresh benchmark tables for 7.0.0 (#1602)
  • d66879b Keep slot-level operations out of line (#1600)
  • 8708f36 Keep the insert-path resize out of line (#1601)
  • 39ac5df Take references in update() from a dict only when lower() can run code (#1598)
  • b5d4053 Keep one thread-local version counter on free-threaded builds (#1599)
  • 602dedc Render changelog roles as Markdown in GitHub Release notes (#1596)
  • d02502a Tidy news fragments for 7.0.0 (#1597)
  • 91d5329 Forbid instantiating views and iterators with Py_TPFLAGS_DISALLOW_INSTANTIATI...
  • 27fec2d Name slot-only C functions after the slot they fill (#1594)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the aiohttp group with 1 update: [multidict](https://github.com/aio-libs/multidict).


Updates `multidict` from 6.9.1 to 7.0.0
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v6.9.1...v7.0.0)

---
updated-dependencies:
- dependency-name: multidict
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: aiohttp
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants