Skip to content

Update Python dependencies - #371

Merged
anuraaga merged 2 commits into
mainfrom
renovate/python-dependencies
Sep 28, 2026
Merged

anuraaga merged 2 commits into
mainfrom
renovate/python-dependencies

Conversation

@renovate

@renovate renovate Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
mkdocstrings-python (changelog) ==2.0.8 → ==2.0.9 age adoption passing confidence
pyvoy (changelog) ==1.1.0 → ==1.2.0 age adoption passing confidence
ruff (source, changelog) ==0.16.8 → ==0.16.9 age adoption passing confidence
starlette (changelog) ==1.6.0 → ==1.7.0 age adoption passing confidence
tombi ==1.5.5 → ==1.5.7 age adoption passing confidence
ty (changelog) ==0.0.82 → ==0.0.84 age adoption passing confidence
uvicorn (changelog) ==0.53.0 → ==0.54.0 age adoption passing confidence
zensical (changelog) ==0.0.63 → ==0.0.65 age adoption passing confidence

Release Notes

mkdocstrings/python (mkdocstrings-python)

v2.0.9

Compare Source

Compare with 2.0.8

Bug Fixes
  • Improve inventory object types (incorrectly called roles in mkdocstrings) (d754326 by Timothée Mazzucotelli). Issue-339, PR-340
  • Expand relative cross-references against the object the docstring was written on (a9a4ca3 by Dev M). Issue-341, PR-342
Performance Improvements
  • Small performance improvement when getting aliases and formatting/highlighting signatures (2263163 by Timothée Mazzucotelli).
curioswitch/pyvoy (pyvoy)

v1.2.0

Compare Source

This release adds support for trio - you can use pass --loop trio to the CLI to configure pyvoy to use it instead of asyncio with uvloop. We have also taken this opportunity to add support for --loop zuvloop, and up and coming event loop implementation. As it matures, we likely will switch to it as the default in the future.

Full Changelog: curioswitch/pyvoy@v1.1.0...v1.2.0

astral-sh/ruff (ruff)

v0.16.9

Compare Source

Released on 2026-09-24.

Preview features
  • [ruff] Avoid false positives for overloaded division (RUF069) (#​28309)
Bug fixes
  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#​28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#​28767)
Rule changes
  • Update LibCST-based fixes for Python 3.15 (#​28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#​28542)
Documentation
  • Fix horizontal overflow on the rules documentation page (#​28699)
  • Update rules table with category information (#​28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#​28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#​28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#​27794)
  • [ruff] Mention related isort settings (RUF022) (#​28719)
Contributors
Kludex/starlette (starlette)

v1.7.0: Version 1.7.0

Compare Source

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING]
OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added
  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #​3438, #​3463, and #​3520.
  • Expose the matched route through scope["route"] #​3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #​3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #​3563.
  • Support partitioned cookies in SessionMiddleware #​3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #​3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #​3471.
  • Support Python 3.15 #​3508.
Changed
  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #​3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #​2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #​3518.
Fixed
  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #​3476.
  • Return 400 for invalid multipart parser input #​3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #​3516 and #​3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #​3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #​3568.
  • Handle standalone If-None-Match: * in StaticFiles #​3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #​3532.
  • Persist session mutations made with popitem() and |= #​3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #​3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #​3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #​3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #​3498 and #​3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #​2858.

Full changelog: 1.6.0...1.7.0

tombi-toml/tombi (tombi)

v1.5.7

Compare Source

What's Changed

🛠️ Other Changes

Full Changelog: tombi-toml/tombi@v1.5.6...v1.5.7

v1.5.6

Compare Source

What's Changed

🦅 New Features
🐝 Bug Fixes
🛠️ Other Changes

Full Changelog: tombi-toml/tombi@v1.5.5...v1.5.6

astral-sh/ty (ty)

v0.0.84

Compare Source

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes
  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#​28759)
LSP server
  • Complete string keys from dictionary initializers (#​28820)
  • Support LSP requests against closed documents (#​28595)
  • Select projects for external files using import search paths (#​28594)
  • Use workspace editor settings for external files (#​28639)
Performance
  • Avoid repeated subtyping checks for materialized recursive protocols (#​28774)
  • Skip reading notebooks when discovering scripts (#​28781)
Core type checking
  • Avoid incorrect simplification of TypeIs materializations (#​28817)
  • Fix disjointness of generic class types (#​28787)
  • Fix staticmethod shadowing through generic receivers and unions (#​28766)
  • Infer callable signatures from bounded type variables (#​28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#​28676)
  • Infer through optional generic containers in the legacy solver (#​28791)
  • Preserve call narrowing during cyclic inference (#​28708)
  • Preserve intersections of type guard return types (#​28796)
  • Use subtyping for constraint-set implication (#​28657)
Configuration
  • Disable invalid-legacy-positional-parameter by default (#​28834)
Other changes
  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#​28788)
Contributors

v0.0.83

Compare Source

Released on 2026-09-21.

Bug fixes
  • Fix hangs from repeated partial application (#​28754)
  • Preserve PEP 695 bindings across nested classes (#​28723)
LSP server
  • Include required imports in every inlay hint (#​28724)
  • Preserve fast name filtering for normalized Unicode source (#​28701)
  • Refresh diagnostics after workspace configuration changes (#​28755)
Diagnostic improvements
  • Expand unreachable-code annotations for redundant conditions (#​28674)
  • Improve diagnostics for async generator stubs (#​28692)
  • Improve primary diagnostic annotations for redundant-condition(-strict) diagnostics (#​28666)
  • Point misplaced tuple ellipsis diagnostics at each ellipsis (#​28709)
Other changes
  • Add rules that detect suspicious uses of Callable, Iterable, Iterator or Generator types in a boolean context (#​28554)
  • Allow slots to override abstract properties (#​28698)
  • Avoid leaking Unknown from unconstrained collection use-sites (#​28659)
  • Diagnose unguarded cycles in implicit and PEP 613 aliases (#​28704)
  • Eagerly bind unused Self receivers (#​28662)
  • Generalize receiver binding for wrapped callables (#​28725)
  • More faithful representation of bound methods (#​28410)
  • Only classify evidence bounds for constrained type variables (#​28700)
  • Preserve inferred bindings during annotation cycles (#​28717)
  • Preserve quoted aliases during cycle recovery (#​28710)
  • Reject class-scoped type variables in init receivers (#​28706)
  • Reject unsafe TypedDict updates from hidden fields (#​28711)
  • Respect fixed caller type variables when selecting constraints (#​28652)
  • Reuse cached type alias inference for diagnostics (#​28696)
  • Simplify unions of disjoint exclusions (#​28684)
  • Update typing conformance suite (#​28718)
Contributors
Kludex/uvicorn (uvicorn)

v0.54.0: Version 0.54.0

Compare Source

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#​3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#​3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

zensical/zensical (zensical)

v0.0.65: 0.0.65

Compare Source

Summary

This version expands MkDocs compatibility with a native replacement for the rss plugin and support for mkdocstrings backlinks. Zensical can now generate RSS 2.0 and JSON Feed 1.1 feeds for created and updated pages. Python API documentation can also show which pages reference a documented object, with backlinks kept current across cached builds.

Changelog

Features
  • e7876ab zensical, compat – support mike's version_selector setting
  • 25b95e9 zensical, compat – support mkdocstrings' enable_inventory setting
  • 0223fc9 compat – support more macros settings
  • acee89a zensical, compat – support autorefs settings
  • 0291923 zensical, compat – support mkdocstrings backlinks
  • c214988 zensical, compat – add rss plugin replacement (#​443)
Bug fixes
  • cf68f6d zensical, compat – resolve source links to published post URLs (#​966)

v0.0.64: 0.0.64

Compare Source

Summary

Many of you have been waiting for this one: Zensical now includes native blog support. As a direct port of the Material for MkDocs blog plugin, it preserves the familiar configuration, metadata, URLs, archives, categories, authors, pagination, and more. We're happy to finally put it into your hands, with more flexible blogging functionality planned for the future.

Changelog
Features
  • 5825381 zensical, compat, ui – add blog plugin replacement
Bug fixes
  • a85875e ui – update ui to v0.0.32

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/python-dependencies branch from bd133e1 to 3dff0e6 Compare September 28, 2026 01:38
@renovate
renovate Bot force-pushed the renovate/python-dependencies branch from 3dff0e6 to 217e3c3 Compare September 28, 2026 03:26
Signed-off-by: Anuraag Agrawal <anuraaga@gmail.com>
@renovate

renovate Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Comment thread src/connectrpc/errors.py
else ()
)
self._details = [
m if isinstance(m, ErrorDetail) else ErrorDetail(m) for m in details

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Figured avoiding the empty list allocation is an overoptimization not worth having to explain a lint suppression (if details is true for generators, which is fine here, but lint catches it since it is often not fine)

@anuraaga
anuraaga merged commit 03a3270 into main Sep 28, 2026
37 of 40 checks passed
@anuraaga
anuraaga deleted the renovate/python-dependencies branch September 28, 2026 07:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant