Skip to content

test: update all test dependencies - #1669

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/tests-all-test-dependencies
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/tests-all-test-dependencies

Conversation

@renovate

@renovate renovate Bot commented Aug 29, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
black (changelog) ==26.5.1 → ==26.10.0 age confidence
charset-normalizer (changelog) ==3.5.1 → ==3.5.2 age confidence
click (changelog) ==8.4.2 → ==8.5.0 age confidence
click (changelog) ==8.4.2 → ==8.5.0 age confidence
flake8 (changelog) ==7.3.0 → ==7.4.1 age confidence
idna (changelog) ==3.19 → ==3.20 age confidence
idna (changelog) ==3.19 → ==3.20 age confidence
isort (changelog) ==8.0.1 → ==9.0.2 age confidence
mypy (changelog) ==2.3.1 → ==2.4.0 age confidence
pkginfo ==1.12.1.2 → ==1.13 age confidence
pkginfo ==1.12.1.2 → ==1.13 age confidence
soupsieve ==2.9.2 → ==2.10 age confidence
urllib3 (changelog) ==2.7.0 → ==2.8.0 age confidence
urllib3 (changelog) ==2.7.0 → ==2.8.0 age confidence
uvicorn (changelog) ==0.52.4 → ==0.54.0 age confidence

Release Notes

psf/black (black)

v26.10.0

Compare Source

Stable style
  • --line-ranges no longer inserts an empty line after a docstring when the range
    covers only the docstring itself (#​5312)
  • Fix # fmt: skip on a bracketed ternary turning the surrounding tuple into a call
    (#​5464)
  • Fix crash when # fmt: skip is placed on a one-line function or class with PEP 695
    type parameters (#​5429)
  • Fix an inline comment after the closing bracket of optional parentheses being moved
    inside the parentheses when the parenthesized expression contains own-line comments
    (#​5395)
  • Fix unparseable output when # fmt: skip is placed on a bracket of an if, while,
    for, or with header (#​5401, #​5405)
  • Fix crash when formatting parenthesized expressions with multiple inline comments and
    # fmt: skip (#​5414)
  • Fix parsing Jupyter notebook assignment magics when non-ASCII characters appear
    earlier on the line (#​5381)
  • Preserve blank lines that come immediately before a # fmt: on comment (#​5300)
  • Keep the parentheses around the target of an annotated assignment (e.g.
    (x): int = 5), which prevent CPython from including the name in __annotations__
    (#​5321)
  • Stop treating a t-string in docstring position as a docstring (e.g. t" spam " as
    the first statement of a module, class or function) (#​5287)
  • Fix unparseable output for a t-string whose replacement field contains a quote (e.g.
    t'\'{a["b"]}\'') (#​5265)
  • Fix unparseable output for a triple-quoted string whose body ends in an
    already-escaped double quote (e.g. '''\'''\"''') (#​5262)
  • Fix --skip-magic-trailing-comma dropping the trailing comma from a split
    single-element tuple used as a lambda parameter default (#​5246)
  • Fix unstable formatting when an inline comment sits on optional parentheses (e.g. a
    parenthesized assert message) (#​5241)
  • Fix --skip-magic-trailing-comma dropping the trailing comma of a one-element
    subscript (a[x,]) when the line is long enough to be split and contains a power
    operator (#​5272)
  • Fix crash when a standalone comment sits between tokens of a comprehension or lambda
    (#​5144)
  • Fix inline comments on a bracket inside a comprehension being dropped (#​5330)
  • Respect the magic trailing comma in a PEP 695 type parameter list containing a
    *TypeVarTuple or **ParamSpec (#​5244)
  • Fix crash when a comment-only # fmt: off/# fmt: on block is followed by a with
    statement after another standalone comment (#​5189)
  • Fix a crash when splitting case case if ... match patterns at very small line
    lengths (#​5147)
  • Fix multiline docstring indentation when leading tabs are used inside indented
    docstrings (#​5148)
  • Respect # fmt: skip on a line that opens a bracket (e.g.
    from x import ( # fmt: skip) when a standalone comment is among the bracket's
    contents (#​5161)
  • Fix an AST safety error when separate # type: ignore comments in a parenthesized
    attribute chain were merged onto one physical line (#​5297)
  • Preserve comments and blank lines outside requested ranges when formatting with
    --line-ranges (#​5175)
  • Fix crash when # fmt: skip is used on one-line async def, async with, and
    async for statements containing a semicolon (#​5311)
  • Stop converting form feeds or other similar characters in docstrings into newlines
    (#​5461)
  • Fix --skip-source-first-line turning the skipped line's CRLF ending into \r\r\n
    when reformatting a file with CRLF line endings (#​5438)
Preview style
New preview features
  • Add missing blank lines after classes whose last method has an ellipsis body (#​5439)
  • Split only the brackets holding a magic trailing comma when more trailers follow them
    (e.g. stop splitting inside the [2] of [1,][2](3)) (#​5448)
  • Keep dictionary keys containing operators together on one line when the value can be
    wrapped onto a new line instead (#​5435)
  • Remove redundant parentheses around individual variables in unpacking targets (e.g.
    for (x), (y) in points: becomes for x, y in points:) (#​5416)
  • Normalize uppercase T prefixes on t-strings to lowercase (#​5425)
  • Remove redundant parentheses around generator expressions (#​5304, #​5369)
  • Preserve two blank lines before a top-level class starting inside a # fmt: off block
    after an import (#​5238)
  • Fix unnecessary parentheses around short right-hand expressions in indexed assignments
    (e.g. x[key] = expr) (#​5095)
  • Parenthesize tuple expressions in yield statements for consistency with function
    calls and returns (#​5170)
  • Stop splitting between a variable and its operator (not in, ==, is, ...) when
    the right-hand side is a bracketed expression, and instead split inside the brackets
    (#​5135)
  • In .pyi stub files, enforce a blank line after a function or method that has a
    docstring-only body when another comment or statement follows it (#​5158)
Updates to existing preview features
  • Fix crash in stub files when # fmt: skip is placed on a function in a group of
    same-name decorated functions (e.g. @overloads or a property setter) (#​5430)
  • Keep the parentheses around a lambda used as the iterable of a comprehension (e.g.
    [x for x in (lambda: 0) if x]) (#​5176, #​5200)
Updates to existing unstable features
  • Do not treat multi-line expressions with merged strings and trailing # type: ignore
    comments as single-line unsplittable expressions (#​5466)
  • Fix duplicated inline comment when stripping the parentheses around a string or
    merging a backslash-continued string on the same line (#​5449)
  • Split long stringified return annotations even when the function has parameters
    (#​5427)
  • Don't hug brackets when doing so would join two # type: ignore comments onto one
    line (#​5271)
  • Fix a crash when # type: ignore is lost during formatting of a long parenthesized
    string (#​5329)
  • Fix only the first part of an implicitly concatenated unmergeable string (e.g.
    r"..." r"...") being wrapped in parentheses (#​5434)
Configuration
  • Add support for NO_COLOR environment variable to disable ANSI output (#​5129)
  • Remove spurious target version warning when runtime version is included in a
    --target-version flag (#​5167)
  • Fix --force-exclude not excluding files whose path contains .. (e.g.
    black ../generated/file.py run from a subdirectory) (#​5471)
  • Fall back to the default configuration, with a warning, when the given sources share
    no common project root (e.g. they are on different drives on Windows) instead of
    crashing (#​5386)
  • Fix loading a stale cached pyproject.toml path when --code is used from different
    working directories in the same process (#​5152)
  • Add validation for --line-ranges values (#​5107)
  • Ignore empty cache files instead of raising an EOFError (#​5192)
  • Reject non-string include and force-exclude values in pyproject.toml (#​5193)
  • Validate BLACK_NUM_WORKERS values and report invalid values as usage errors instead
    of crashing (#​5211)
  • Ignore permission errors when reading cache (#​5258)
Packaging
  • Reduce the size of Linux standalone binaries by stripping debug symbols during the
    PyInstaller release build (#​5223)
  • Black is now released using GitHub
    Immutable Releases
    (#​5296)
Performance
  • Fix superlinear runtime growth with the number of input files (#​5450)
  • Improve performance on strings containing many consecutive backslashes (#​5163)
  • Improve performance on files with many # fmt: skip/# fmt: off/# fmt: on comments
    (#​5169, #​5190, #​5232)
  • Improve performance on long calls and collections (#​5177)
  • Improve performance on multiline strings inside large collections (e.g. a dict literal
    with triple-quoted strings as values) (#​5188)
  • Improve performance on files with many soft keywords (e.g. match/case blocks)
    (#​5186)
  • Improve performance on long semicolon-separated statements (in the stable style) and
    large dict literals (in --preview) (#​5184)
  • Improve performance of --line-ranges on files with many sibling blocks (a long
    if/elif chain, a match with many cases, or many top-level definitions) (#​5213)
  • Improve performance on deeply nested bracketed expressions (#​5171, #​5242)
  • Improve performance on lists and subscripts holding one long expression without
    operators (e.g. a long run of implicitly concatenated strings inside []) (#​5239)
  • Improve performance on deeply chained operations (e.g. a long a ** b ** c ** ...
    chain) (#​5235)
  • Improve performance on long if/elif chains and other compound statements with many
    clauses (#​5322)
  • Improve performance of string_processing:
    • when merging implicitly concatenated f-strings containing long string literals
      (#​5165)
    • when merging long implicitly concatenated strings (#​5173, #​5194)
    • when rewriting large nodes (e.g. "%s ..." % (a, b, c, ...)) (#​5178, #​5199, #​5220)
    • when splitting long string literals (#​5183)
Output
  • Report parser failures using editor-friendly path:line:column locations (#​5237)
  • Fix crash when writing formatted code or diffs to a sys.stdout that has no buffer
    attribute (e.g. in Jupyter notebooks) (#​5411)
  • Report parse failures on Black's own output as internal errors (#​5383)
Blackd
  • Return HTTP 400 instead of 500 when the X-Python-Variant header is empty or has an
    empty entry (e.g. a trailing comma) (#​5428)
  • Allow optional whitespace around comma-separated versions and pyi in the
    X-Python-Variant header (#​5441)
Integrations
  • Remove unused migrate-black script (#​5319)
  • Support PEP 440 version specifiers in tool.black.required-version for the GitHub
    Action (#​5399)
  • Add outputs (is_formatted, change_count, same_count, failure_count) to GitHub
    Action runs (#​5408)
Documentation
  • Document vim-python-pep8-indent, which provides an indentexpr for Black-style
    insert-mode indentation (#​5288)
jawah/charset_normalizer (charset-normalizer)

v3.5.2

Compare Source

Changed
  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for
    abi3 builds to preserve compatibility with the Python 3.7 Limited API.
Fixed
  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties
    for uncommon CJK characters. (#​796)
  • Supported encodings without aliases failing name resolution or being ignored in charset
    declarations. (#​800)
pallets/click (click)

v8.5.0

Compare Source

Released 2026-08-24

  • Add built-in shell completion support for PowerShell (Windows PowerShell
    5.1+ and pwsh 7+) alongside the existing bash, zsh, and fish
    completers. Use _FOO_BAR_COMPLETE=powershell_source foo-bar to generate
    the completion script. {issue}2672 {pr}3637
  • Supported versions of Windows enable ANSI terminal styles by default.
    Colorama is no longer a dependency and is not used. {issue}2986 {pr}3505
  • {class}Argument accepts a help parameter, and help output includes
    a Positional arguments section when argument help is available. {issue}2983 {pr}3473
  • confirm() and prompt() strip ANSI color and style codes from the
    prompt when the output stream does not support them, matching echo().
    This stripping was lost in 8.4.0 when {pr}2969 began writing the
    prompt with input() directly. {issue}3572 {pr}3653
  • Fix test failures when using pytest >= 9.1. {pr}3656
  • {class}Path with allow_dash=True no longer triggers a BytesWarning,
    an error under python -bb, when checking a value against the -
    convention. {issue}2877 {pr}3642
  • Add {func}custom_version_option, a --version option whose output is
    produced by a callback, covering cases {func}version_option intentionally
    does not. The feature set of {func}version_option is now frozen; see
    discussion #​3527. {pr}3581
  • style() and secho() no longer silently drop the 256-color index 0
    (black) passed as fg or bg, and now validate color arguments. Invalid
    colors raise a ValueError instead of a TypeError. {pr}3677
  • The automatic help option stores its value under the reserved name
    _click_default_help instead of help, so a parameter named help no
    longer breaks parsing. The new name is visible in
    {meth}Command.to_info_dict output. Parameters that overwrite each other's
    value trigger a warning: an argument sharing its name with another
    parameter, or any parameter claiming the reserved name. Options may still
    share a name to compete for the same value (feature switches).
    {issue}2819 {pr}3678
  • unstyle and the ANSI handling behind help-text wrapping now strip the full
    CSI escape-sequence grammar. {pr}3681
  • Streamline Option flag handling: the flag-kind, type, lazy-default and
    validation steps in Option.__init__ move into focused helpers, and
    flag_value and default keep their unset sentinel at construction
    (resolved lazily on read) so is UNSET reliably tells a user-supplied value
    from an auto-derived one. Runtime behavior is unchanged, but
    {meth}Parameter.to_info_dict now resolves default=True on a feature
    switch to its flag_value, matching what the function receives at call
    time. {pr}3641
  • {func}get_binary_stream and {func}get_text_stream are deprecated and
    will be removed in Click 9.0. {issue}3481 {pr}3695
  • The following click.utils names were never intentionally public and are
    now private (_-prefixed). The old names remain available with a
    DeprecationWarning until Click 9.0: LazyFile, KeepOpenFile,
    make_default_short_help, PacifyFlushWrapper, and safecall.
    {issue}3099 {pr}3695
  • Deprecate {meth}CliRunner.isolated_filesystem. It relies on
    {func}os.chdir, which mutates process-global state and is not
    thread-safe. The helper predates Python 3 and modern pytest: use a
    temporary directory ({class}tempfile.TemporaryDirectory or pytest's
    tmp_path fixture) with absolute paths instead. For running tests in
    parallel, use process-based isolation (such as pytest-xdist) rather
    than threads, since {meth}CliRunner.invoke also redirects the
    process-global standard streams. {issue}3501 {issue}3700 {pr}3704
  • prompt() is now generically typed and returns the type produced by
    type, value_proc, or a matching default instead of Any.
    {class}ParamType takes a second optional type parameter describing the
    input value it accepts (ParamType[int, str] for a type converting
    strings to integers), defaulting to Any. {pr}3407
  • {meth}Command.get_help_option_names returns the help option names in the
    order they were declared. {pr}3728
  • {func}get_pager_file yields a text stream on Windows again. The temporary
    file backend opened its file in binary mode, so writing a str to the pager
    raised TypeError: a bytes-like object is required, not 'str', and the
    color argument was ignored on that path. Regression introduced in 8.4.0
    by {pr}1572. {issue}3731 {issue}3732 {issue}3740 {pr}3739
  • {func}progressbar settles on its final position when update_min_steps
    does not divide the total. Steps below that threshold are applied when the
    bar finishes, so show_pos renders 20/20 rather than the last multiple
    it reached. {issue}3571 {pr}3769
  • An error raised while writing to the pager no longer gets replaced by
    PermissionError: [WinError 32] on Windows. The temporary file backend
    unlinked its file without closing it first, and Windows refuses to remove a
    file the process still holds open, so the cleanup failure masked the real
    exception. {issue}3731 {pr}3764
  • The temporary file the pager writes to on Windows is opened with the encoding
    {func}get_pager_file picked for the output stream, and with
    errors="replace" to match the pipe backend. Any text stdout can encode
    reaches the pager.
  • The temporary file pager backend forwards any parameters the user set in
    PAGER to the pager command instead of silently dropping them. On Windows,
    PAGER="less -R" now invokes less -R on the temporary file rather than
    bare less. {pr}3777
  • Improve raw mode detection by parsing the option tokens. {issue}3416
    {pr}3777
  • {func}edit accepts os.PathLike values for filename, in addition to
    strings. {issue}2869 {pr}3781
pycqa/flake8 (flake8)

v7.4.1

Compare Source

v7.4.0

Compare Source

kjd/idna (idna)

v3.20

Compare Source

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental
    codec.
  • Add support for Python 3.15.
PyCQA/isort (isort)

v9.0.2

Compare Source

🪲 Fixes

Other changes

Full Changelog: PyCQA/isort@9.0.1...9.0.2

v9.0.1

Compare Source

🪲 Fixes

Other changes

Full Changelog: PyCQA/isort@9.0.0...9.0.1

v9.0.0

Compare Source

python/mypy (mypy)

v2.4.0

Compare Source

facelessuser/soupsieve (soupsieve)

v2.10

Compare Source

2.10

  • NEW: Support Python 3.15.
  • NEW: Add new ignore option to API methods that allows the specification of specific pseudo-classes to be
    ignored.
  • NEW: Tighten restrictions such that namespaces and custom objects must always be a Mapping, previously lists
    of tuples were also allowed.
  • NEW: Use a singleton for null selectors internally via called Null of type SelectorNull.
  • NEW: For performance, Soup Sieve will no longer try and coerce bad attribute values to useable strings.
  • NEW: Add NOCACHE flag that can be used to disable caching optimizations selectors and possibly other future
    caching optimizations. Provided for disabling and also disabling if issues are found with the new caching approach.
  • FIX: Improve performance of ~ for various cases by employing caching.
  • FIX: Improve performance of nth-* family of selectors in certain scenarios by employing caching.
  • FIX: Ensure custom is properly passed down from API functions to compilation.
urllib3/urllib3 (urllib3)

v2.8.0

Compare Source

==================

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden.
    (High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size
    line of unbounded length in memory. (High severity,
    GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity,
    GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)

.. caution::

urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.

Configure proxy CA certificates and client certificates in
``proxy_ssl_context``, and proxy identity checks with
``proxy_assert_hostname`` or ``proxy_assert_fingerprint``.
Destination client certificates and identity overrides no longer
apply to HTTPS forwarding proxy connections.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option
    allowed_methods to retry any verb.
    (#&#8203;5044 <https://github.com/urllib3/urllib3/issues/5044>__)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience
    properties to the result of parse_url().
    (#&#8203;4945 <https://github.com/urllib3/urllib3/issues/4945>__)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to
    urllib3.util.make_headers().
    (#&#8203;5092 <https://github.com/urllib3/urllib3/issues/5092>__)

Bugfixes

  • Fixed response header handling to replace obsolete folded header lines
    (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF
    sequences from appearing in header values such as Set-Cookie.
    (#&#8203;1362 <https://github.com/urllib3/urllib3/issues/1362>__)

  • Fixed usage of proxy_ssl_context with ProxyManager when
    use_forwarding_for_https=True. Passing ssl_context instead of
    proxy_ssl_context for HTTPS proxies in this configuration now emits a
    FutureWarning and will raise an error in v3.0.
    (#&#8203;2577 <https://github.com/urllib3/urllib3/issues/2577>__)

  • Changed behavior of the default ConnectionPool.pool initialization.
    LifoQueue is now resolved from the queue module after the
    ConnectionPool is instantiated instead of using the default cached
    QueueCls class property. This is done because sometimes the
    queue.LifoQueue is monkey-patched late in the program, such as by gevent.
    (#&#8203;3289 <https://github.com/urllib3/urllib3/issues/3289>__)

  • Raised UnrewindableBodyError instead of ValueError when retrying a
    request whose body had tell() but not seek().
    (#&#8203;3779 <https://github.com/urllib3/urllib3/issues/3779>__)

  • Decoded percent-encoded SOCKS proxy credentials before authenticating with
    the proxy server.
    (#&#8203;3785 <https://github.com/urllib3/urllib3/issues/3785>__)

  • Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB
    chunks (same as the default amt when doing HTTPResponse.stream(...)).
    (#&#8203;5019 <https://github.com/urllib3/urllib3/issues/5019>__)

  • Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by
    socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and
    decimal integers (2130706433), ensuring SSL certificate verification uses
    the correct mode for these addresses.
    (#&#8203;5029 <https://github.com/urllib3/urllib3/issues/5029>__)

  • Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError
    instead of ValueError when called with an invalid timeout argument on
    a pool created with block=True.
    (#&#8203;5059 <https://github.com/urllib3/urllib3/issues/5059>__)

  • Fixed port-zero handling to preserve explicit :0 values instead of
    substituting the default ports 80 or 443 in URL parsing, pool selection,
    proxy configuration, connection_from_url(), and HTTP/2 request authority.
    (#&#8203;5071 <https://github.com/urllib3/urllib3/issues/5071>,
    #&#8203;5101 <https://github.com/urllib3/urllib3/issues/5101>
    )

  • Fixed a bug where PoolManager passed the assert_hostname and
    assert_fingerprint parameters to HTTP connection pools.
    (#&#8203;5077 <https://github.com/urllib3/urllib3/issues/5077>__)

  • Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL
    fragments from absolute request targets before sending requests.
    (#&#8203;5079 <https://github.com/urllib3/urllib3/issues/5079>__)

  • Added safeguards to the proxy tunneling code to prevent potential security
    issues when handling invalid characters in the proxy host and HTTP headers.
    This change affects users of Python 3.10, Python 3.11, and Python 3.12 when
    the standard library does not contain the fix; those on newer Python versions
    should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
    (#&#8203;5091 <https://github.com/urllib3/urllib3/issues/5091>__)

  • Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's
    certificate policy and proxy identity checks with the target connection's TLS
    settings when forwarding through an HTTPS proxy.

    HTTPSConnection no longer applies target SNI, assertions, or client
    credentials to forwarding proxy handshakes and continues to use its
    ssl_context as a fallback when an HTTPS proxy forwards an HTTP target.
    (#&#8203;5093 <https://github.com/urllib3/urllib3/issues/5093>__)

  • Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting
    invalid host input such as raw spaces and control characters, malformed
    percent-encodings, and percent-encoded control characters in HTTP(S) hosts
    and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host
    normalization now also follows RFC 3986 normalization rules for
    percent-encoded octets by decoding percent-encoded unreserved characters and
    uppercasing the hexadecimal digits of retained percent-encoded octets.
    (#&#8203;5095 <https://github.com/urllib3/urllib3/issues/5095>__)

  • Fixed an AttributeError on Python built with OpenSSL 4+, where
    ssl.PROTOCOL_TLSv1 no longer exists.
    (#&#8203;5097 <https://github.com/urllib3/urllib3/issues/5097>__)

  • Fixed urllib3.contrib.pyopenssl to use cryptography APIs when reading a
    certificate subject and loading encrypted private keys, avoiding
    DeprecationWarning raised by pyOpenSSL 26.3.0+.
    (#&#8203;5103 <https://github.com/urllib3/urllib3/issues/5103>__)

  • Fixed handling of HTTP 303 redirects for requests with chunked or file-like
    bodies.
    (#&#8203;5161 <https://github.com/urllib3/urllib3/issues/5161>__)

  • Fixed assert_fingerprint() to raise SSLError instead of
    binascii.Error when a fingerprint has a supported length but contains
    non-hexadecimal characters.
    (#&#8203;5211 <https://github.com/urllib3/urllib3/issues/5211>__)

Misc

  • Added a test dependency group containing the minimum dependencies needed
    to run the test suite, intended for downstream packagers. The dev-base
    and mypy groups now include this new group via include-group,
    removing duplication.
    (#&#8203;3594 <https://github.com/urllib3/urllib3/issues/3594>__)
  • Fixed test failures with pytest >= 9.1.
    (#&#8203;5094 <https://github.com/urllib3/urllib3/issues/5094>__)
  • Enabled JSPI tests with Firefox in the Emscripten test suite.
    (#&#8203;5166 <https://github.com/urllib3/urllib3/issues/5166>__)
  • Improved streamed response decoding performance.
    (#&#8203;5209 <https://github.com/urllib3/urllib3/issues/5209>__)
  • Fixed flaky tests.
    (#&#8203;5232 <https://github.com/urllib3/urllib3/issues/5232>,
    #&#8203;5234 <https://github.com/urllib3/urllib3/issues/5234>
    ,
    #&#8203;5239 <https://github.com/urllib3/urllib3/issues/5239>__)
Kludex/uvicorn (uvicorn)

v0.54.0: Version 0.54.0

Compare Source

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#​3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#​3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

v0.53.0: Version 0.53.0

Compare Source

🌐 Opt-in HTTP/2 support

uvicorn 0.53.0 adds experimental HTTP/2 through zttp, alongside a new zuvloop integration and connection-handling improvements.

uv add uvicorn==0.53.0
  • Serve HTTP/1.1 and HTTP/2 with zttp (#​2982, #​3101). Install zttp, then enable HTTP/2 with --http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.
  • HTTP/2 remains experimental. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

⚙️ More event loop choice

  • Run Uvicorn with zuvloop (#​3104). Install zuvloop separately and select it explicitly with --loop zuvloop on CPython 3.14 or newer.

🛡️ More reliable connections and proxies

  • Honor Connection: close token lists (#​3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.
  • Trust IPv6 loopback proxies by default (#​3119). The default FORWARDED_ALLOW_IPS value now includes ::1.
  • Keep upgraded WebSockets alive (#​3107). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.

Full changelog: 0.52.4...0.53.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 5am on saturday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) August 29, 2026 01:29
@renovate
renovate Bot force-pushed the renovate/tests-all-test-dependencies branch 6 times, most recently from d3d0674 to 7df4afa Compare August 30, 2026 18:26
@renovate renovate Bot changed the title test: update all test dependencies test: update dependencies in tests to v9 Aug 30, 2026
@renovate
renovate Bot force-pushed the renovate/tests-all-test-dependencies branch from 7df4afa to 336078c Compare August 30, 2026 22:00
@renovate renovate Bot changed the title test: update dependencies in tests to v9 test: update all test dependencies Aug 30, 2026
@renovate
renovate Bot force-pushed the renovate/tests-all-test-dependencies branch 4 times, most recently from 02fcc5a to 698da99 Compare September 7, 2026 01:08
@renovate
renovate Bot force-pushed the renovate/tests-all-test-dependencies branch 5 times, most recently from 44af5b3 to 472a8e9 Compare September 17, 2026 23:32
@renovate
renovate Bot force-pushed the renovate/tests-all-test-dependencies branch 5 times, most recently from cc2c612 to d267042 Compare September 25, 2026 16:17
@renovate
renovate Bot force-pushed the renovate/tests-all-test-dependencies branch 4 times, most recently from 0cbbcfb to 7b315ec Compare September 27, 2026 08:56
@renovate
renovate Bot force-pushed the renovate/tests-all-test-dependencies branch from 7b315ec to 29497cf Compare October 3, 2026 15:39
@renovate
renovate Bot force-pushed the renovate/tests-all-test-dependencies branch from 29497cf to 02eec99 Compare October 4, 2026 00:51
@renovate
renovate Bot force-pushed the renovate/tests-all-test-dependencies branch from 02eec99 to aaed965 Compare October 7, 2026 01:42

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants