Update Python dependencies - #371
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/python-dependencies
branch
from
September 28, 2026 01:38
bd133e1 to
3dff0e6
Compare
renovate
Bot
force-pushed
the
renovate/python-dependencies
branch
from
September 28, 2026 03:26
3dff0e6 to
217e3c3
Compare
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
anuraaga
reviewed
Sep 28, 2026
| else () | ||
| ) | ||
| self._details = [ | ||
| m if isinstance(m, ErrorDetail) else ErrorDetail(m) for m in details |
Collaborator
There was a problem hiding this comment.
Figured avoiding the empty list allocation is an overoptimization not worth having to explain a lint suppression (if details is true for generators, which is fine here, but lint catches it since it is often not fine)
anuraaga
approved these changes
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==2.0.8→==2.0.9==1.1.0→==1.2.0==0.16.8→==0.16.9==1.6.0→==1.7.0==1.5.5→==1.5.7==0.0.82→==0.0.84==0.53.0→==0.54.0==0.0.63→==0.0.65Release Notes
mkdocstrings/python (mkdocstrings-python)
v2.0.9Compare Source
Compare with 2.0.8
Bug Fixes
Performance Improvements
curioswitch/pyvoy (pyvoy)
v1.2.0Compare Source
This release adds support for trio - you can use pass
--loop trioto the CLI to configure pyvoy to use it instead of asyncio with uvloop. We have also taken this opportunity to add support for--loop zuvloop, and up and coming event loop implementation. As it matures, we likely will switch to it as the default in the future.Full Changelog: curioswitch/pyvoy@v1.1.0...v1.2.0
astral-sh/ruff (ruff)
v0.16.9Compare Source
Released on 2026-09-24.
Preview features
ruff] Avoid false positives for overloaded division (RUF069) (#28309)Bug fixes
flake8-bugbear] Avoid false positives for calls with keyword arguments (B009,B010,B043) (#28776)flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)Rule changes
flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)Documentation
flake8-annotations] Clarify thatANN401checks return types in addition to arguments (#28334)flake8-bugbear] Document type-checker interaction (B010) (#28509)flake8-comprehensions] Documentmap/generator exception behavior (C417) (#27794)ruff] Mention related isort settings (RUF022) (#28719)Contributors
Kludex/starlette (starlette)
v1.7.0: Version 1.7.0Compare Source
This release adds experimental OpenTelemetry tracing, HTTP
QUERYsupport, and response trailers inTestClient. Starlette now requires AnyIO 4.Added
OpenTelemetryMiddlewarefor HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.scope["route"]#3438.QUERYHTTP method inHTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.TestClientand expose them throughresponse.extensions["http.response.trailers"]#3563.SessionMiddleware#3510.partitionedtoResponse.delete_cookie()on Python 3.14 and later #3376.TrustedHostMiddlewareandTestClient#3471.Changed
anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.WebSocketDisconnected, aRuntimeErrorsubclass, for disconnected WebSocket operations #2767.Collection[str]inCORSMiddlewareconfiguration annotations, including sets and frozensets #3518.Fixed
BaseHTTPMiddleware#3476.400for invalid multipart parser input #3492.Vary: Originon all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.Hostheaders and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.Rangeheaders whenFileResponsehas a status other than200, preserving its status and full body #3568.If-None-Match: *inStaticFiles#3201.StaticFileswithout raising an assertion error #3532.popitem()and|=#3436.WebSocketEndpoint.decode()#3372.identityonSimpleUserandUnauthenticatedUser#3271.HTTPExceptionto use non-standard status codes without an explicitdetail#3545.TestClientand add explicit imports inWSGIMiddlewarefor AnyIO 4.15 compatibility #3498 and #3501.ServerErrorMiddleware#2858.Full changelog: 1.6.0...1.7.0
tombi-toml/tombi (tombi)
v1.5.7Compare Source
What's Changed
🛠️ Other Changes
Full Changelog: tombi-toml/tombi@v1.5.6...v1.5.7
v1.5.6Compare Source
What's Changed
🦅 New Features
🐝 Bug Fixes
🛠️ Other Changes
Full Changelog: tombi-toml/tombi@v1.5.5...v1.5.6
astral-sh/ty (ty)
v0.0.84Compare Source
Released on 2026-09-24.
This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.
Bug fixes
showSyntaxErrors(#28759)LSP server
Performance
Core type checking
TypeIsmaterializations (#28817)"foo" in ["foo"]is now inferred asLiteral[True]) (#28676)Configuration
invalid-legacy-positional-parameterby default (#28834)Other changes
redundant-condition(-strict)due to the condition being defined relative tosys.version_info,sys.platform,os.nameortyping.TYPE_CHECKING(#28788)Contributors
v0.0.83Compare Source
Released on 2026-09-21.
Bug fixes
LSP server
Diagnostic improvements
redundant-condition(-strict)diagnostics (#28666)Other changes
Callable,Iterable,IteratororGeneratortypes in a boolean context (#28554)Unknownfrom unconstrained collection use-sites (#28659)Selfreceivers (#28662)Contributors
Kludex/uvicorn (uvicorn)
v0.54.0: Version 0.54.0Compare Source
📨 Send metadata after the response body
uvicorn0.54.0 adds response trailers and103 Early Hintsto its experimental HTTP/2 implementation throughzttp.uv add uvicorn==0.54.0 "zttp>=0.0.34"http.response.trailersextension lets applications send metadata, such as checksums, after the response body. Clients must sendTE: trailersto receive them. Multiple trailer messages are combined before completing the response.--http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.💡 Hint at resources before the final response
103 Early Hintsover HTTP/2 (#3137). Applications can use the ASGIhttp.response.early_hintextension to send resource hints before the final response. Each supplied link becomes a separateLinkheader.Full changelog: 0.53.0...0.54.0
zensical/zensical (zensical)
v0.0.65: 0.0.65Compare Source
Summary
This version expands MkDocs compatibility with a native replacement for the
rssplugin and support for mkdocstrings backlinks. Zensical can now generate RSS 2.0 and JSON Feed 1.1 feeds for created and updated pages. Python API documentation can also show which pages reference a documented object, with backlinks kept current across cached builds.Changelog
Features
e7876abzensical, compat – support mike'sversion_selectorsetting25b95e9zensical, compat – support mkdocstrings'enable_inventorysetting0223fc9compat – support more macros settingsacee89azensical, compat – support autorefs settings0291923zensical, compat – support mkdocstrings backlinksc214988zensical, compat – addrssplugin replacement (#443)Bug fixes
cf68f6dzensical, compat – resolve source links to published post URLs (#966)v0.0.64: 0.0.64Compare Source
Summary
Many of you have been waiting for this one: Zensical now includes native blog support. As a direct port of the Material for MkDocs blog plugin, it preserves the familiar configuration, metadata, URLs, archives, categories, authors, pagination, and more. We're happy to finally put it into your hands, with more flexible blogging functionality planned for the future.
Changelog
Features
5825381zensical, compat, ui – addblogplugin replacementBug fixes
a85875eui – update ui to v0.0.32Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.