Repository navigation
test: update all test dependencies - #1669
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/tests-all-test-dependencies
branch
6 times, most recently
from
August 30, 2026 18:26
d3d0674 to
7df4afa
Compare
renovate
Bot
force-pushed
the
renovate/tests-all-test-dependencies
branch
from
August 30, 2026 22:00
7df4afa to
336078c
Compare
renovate
Bot
force-pushed
the
renovate/tests-all-test-dependencies
branch
4 times, most recently
from
September 7, 2026 01:08
02fcc5a to
698da99
Compare
renovate
Bot
force-pushed
the
renovate/tests-all-test-dependencies
branch
5 times, most recently
from
September 17, 2026 23:32
44af5b3 to
472a8e9
Compare
renovate
Bot
force-pushed
the
renovate/tests-all-test-dependencies
branch
5 times, most recently
from
September 25, 2026 16:17
cc2c612 to
d267042
Compare
renovate
Bot
force-pushed
the
renovate/tests-all-test-dependencies
branch
4 times, most recently
from
September 27, 2026 08:56
0cbbcfb to
7b315ec
Compare
renovate
Bot
force-pushed
the
renovate/tests-all-test-dependencies
branch
from
October 3, 2026 15:39
7b315ec to
29497cf
Compare
renovate
Bot
force-pushed
the
renovate/tests-all-test-dependencies
branch
from
October 4, 2026 00:51
29497cf to
02eec99
Compare
renovate
Bot
force-pushed
the
renovate/tests-all-test-dependencies
branch
from
October 7, 2026 01:42
02eec99 to
aaed965
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==26.5.1→==26.10.0==3.5.1→==3.5.2==8.4.2→==8.5.0==8.4.2→==8.5.0==7.3.0→==7.4.1==3.19→==3.20==3.19→==3.20==8.0.1→==9.0.2==2.3.1→==2.4.0==1.12.1.2→==1.13==1.12.1.2→==1.13==2.9.2→==2.10==2.7.0→==2.8.0==2.7.0→==2.8.0==0.52.4→==0.54.0Release Notes
psf/black (black)
v26.10.0Compare Source
Stable style
--line-rangesno longer inserts an empty line after a docstring when the rangecovers only the docstring itself (#5312)
# fmt: skipon a bracketed ternary turning the surrounding tuple into a call(#5464)
# fmt: skipis placed on a one-line function or class with PEP 695type parameters (#5429)
inside the parentheses when the parenthesized expression contains own-line comments
(#5395)
# fmt: skipis placed on a bracket of anif,while,for, orwithheader (#5401, #5405)# fmt: skip(#5414)earlier on the line (#5381)
# fmt: oncomment (#5300)(x): int = 5), which prevent CPython from including the name in__annotations__(#5321)
t" spam "asthe first statement of a module, class or function) (#5287)
t'\'{a["b"]}\'') (#5265)already-escaped double quote (e.g.
'''\'''\"''') (#5262)--skip-magic-trailing-commadropping the trailing comma from a splitsingle-element tuple used as a lambda parameter default (#5246)
parenthesized assert message) (#5241)
--skip-magic-trailing-commadropping the trailing comma of a one-elementsubscript (
a[x,]) when the line is long enough to be split and contains a poweroperator (#5272)
(#5144)
*TypeVarTupleor**ParamSpec(#5244)# fmt: off/# fmt: onblock is followed by awithstatement after another standalone comment (#5189)
case case if ...match patterns at very small linelengths (#5147)
docstrings (#5148)
# fmt: skipon a line that opens a bracket (e.g.from x import ( # fmt: skip) when a standalone comment is among the bracket'scontents (#5161)
# type: ignorecomments in a parenthesizedattribute chain were merged onto one physical line (#5297)
--line-ranges(#5175)# fmt: skipis used on one-lineasync def,async with, andasync forstatements containing a semicolon (#5311)(#5461)
--skip-source-first-lineturning the skipped line's CRLF ending into\r\r\nwhen reformatting a file with CRLF line endings (#5438)
Preview style
New preview features
(e.g. stop splitting inside the
[2]of[1,][2](3)) (#5448)wrapped onto a new line instead (#5435)
for (x), (y) in points:becomesfor x, y in points:) (#5416)Tprefixes on t-strings to lowercase (#5425)# fmt: offblockafter an import (#5238)
(e.g.
x[key] = expr) (#5095)yieldstatements for consistency with functioncalls and returns (#5170)
not in,==,is, ...) whenthe right-hand side is a bracketed expression, and instead split inside the brackets
(#5135)
.pyistub files, enforce a blank line after a function or method that has adocstring-only body when another comment or statement follows it (#5158)
Updates to existing preview features
# fmt: skipis placed on a function in a group ofsame-name decorated functions (e.g.
@overloads or a property setter) (#5430)[x for x in (lambda: 0) if x]) (#5176, #5200)Updates to existing unstable features
# type: ignorecomments as single-line unsplittable expressions (#5466)
merging a backslash-continued string on the same line (#5449)
(#5427)
# type: ignorecomments onto oneline (#5271)
# type: ignoreis lost during formatting of a long parenthesizedstring (#5329)
r"..." r"...") being wrapped in parentheses (#5434)Configuration
NO_COLORenvironment variable to disable ANSI output (#5129)--target-versionflag (#5167)--force-excludenot excluding files whose path contains..(e.g.black ../generated/file.pyrun from a subdirectory) (#5471)no common project root (e.g. they are on different drives on Windows) instead of
crashing (#5386)
pyproject.tomlpath when--codeis used from differentworking directories in the same process (#5152)
--line-rangesvalues (#5107)EOFError(#5192)includeandforce-excludevalues inpyproject.toml(#5193)BLACK_NUM_WORKERSvalues and report invalid values as usage errors insteadof crashing (#5211)
Packaging
PyInstaller release build (#5223)
Immutable Releases
(#5296)
Performance
# fmt: skip/# fmt: off/# fmt: oncomments(#5169, #5190, #5232)
with triple-quoted strings as values) (#5188)
match/caseblocks)(#5186)
large dict literals (in
--preview) (#5184)--line-rangeson files with many sibling blocks (a longif/elifchain, amatchwith many cases, or many top-level definitions) (#5213)operators (e.g. a long run of implicitly concatenated strings inside
[]) (#5239)a ** b ** c ** ...chain) (#5235)
if/elifchains and other compound statements with manyclauses (#5322)
string_processing:(#5165)
"%s ..." % (a, b, c, ...)) (#5178, #5199, #5220)Output
path:line:columnlocations (#5237)sys.stdoutthat has nobufferattribute (e.g. in Jupyter notebooks) (#5411)
Blackd
X-Python-Variantheader is empty or has anempty entry (e.g. a trailing comma) (#5428)
pyiin theX-Python-Variantheader (#5441)Integrations
migrate-blackscript (#5319)tool.black.required-versionfor the GitHubAction (#5399)
is_formatted,change_count,same_count,failure_count) to GitHubAction runs (#5408)
Documentation
vim-python-pep8-indent, which provides anindentexprfor Black-styleinsert-mode indentation (#5288)
jawah/charset_normalizer (charset-normalizer)
v3.5.2Compare Source
Changed
<3.4for native builds. The bound remains<3.3forabi3builds to preserve compatibility with the Python 3.7 Limited API.Fixed
for uncommon CJK characters. (#796)
declarations. (#800)
pallets/click (click)
v8.5.0Compare Source
Released 2026-08-24
5.1+ and pwsh 7+) alongside the existing
bash,zsh, andfishcompleters. Use
_FOO_BAR_COMPLETE=powershell_source foo-barto generatethe completion script. {issue}
2672{pr}3637Colorama is no longer a dependency and is not used. {issue}
2986{pr}3505Argumentaccepts ahelpparameter, and help output includesa
Positional argumentssection when argument help is available. {issue}2983{pr}3473confirm()andprompt()strip ANSI color and style codes from theprompt when the output stream does not support them, matching
echo().This stripping was lost in
8.4.0when {pr}2969began writing theprompt with
input()directly. {issue}3572{pr}36533656Pathwithallow_dash=Trueno longer triggers aBytesWarning,an error under
python -bb, when checking a value against the-convention. {issue}
2877{pr}3642custom_version_option, a--versionoption whose output isproduced by a callback, covering cases {func}
version_optionintentionallydoes not. The feature set of {func}
version_optionis now frozen; seediscussion #3527. {pr}
3581style()andsecho()no longer silently drop the 256-color index0(black) passed as
fgorbg, and now validate color arguments. Invalidcolors raise a
ValueErrorinstead of aTypeError. {pr}3677_click_default_helpinstead ofhelp, so a parameter namedhelpnolonger breaks parsing. The new name is visible in
{meth}
Command.to_info_dictoutput. Parameters that overwrite each other'svalue trigger a warning: an argument sharing its name with another
parameter, or any parameter claiming the reserved name. Options may still
share a name to compete for the same value (feature switches).
{issue}
2819{pr}3678unstyleand the ANSI handling behind help-text wrapping now strip the fullCSI escape-sequence grammar. {pr}
3681Optionflag handling: the flag-kind, type, lazy-default andvalidation steps in
Option.__init__move into focused helpers, andflag_valueanddefaultkeep their unset sentinel at construction(resolved lazily on read) so
is UNSETreliably tells a user-supplied valuefrom an auto-derived one. Runtime behavior is unchanged, but
{meth}
Parameter.to_info_dictnow resolvesdefault=Trueon a featureswitch to its
flag_value, matching what the function receives at calltime. {pr}
3641get_binary_streamand {func}get_text_streamare deprecated andwill be removed in Click 9.0. {issue}
3481{pr}3695click.utilsnames were never intentionally public and arenow private (
_-prefixed). The old names remain available with aDeprecationWarninguntil Click 9.0:LazyFile,KeepOpenFile,make_default_short_help,PacifyFlushWrapper, andsafecall.{issue}
3099{pr}3695CliRunner.isolated_filesystem. It relies on{func}
os.chdir, which mutates process-global state and is notthread-safe. The helper predates Python 3 and modern pytest: use a
temporary directory ({class}
tempfile.TemporaryDirectoryor pytest'stmp_pathfixture) with absolute paths instead. For running tests inparallel, use process-based isolation (such as
pytest-xdist) ratherthan threads, since {meth}
CliRunner.invokealso redirects theprocess-global standard streams. {issue}
3501{issue}3700{pr}3704prompt()is now generically typed and returns the type produced bytype,value_proc, or a matchingdefaultinstead ofAny.{class}
ParamTypetakes a second optional type parameter describing theinput value it accepts (
ParamType[int, str]for a type convertingstrings to integers), defaulting to
Any. {pr}3407Command.get_help_option_namesreturns the help option names in theorder they were declared. {pr}
3728get_pager_fileyields a text stream on Windows again. The temporaryfile backend opened its file in binary mode, so writing a
strto the pagerraised
TypeError: a bytes-like object is required, not 'str', and thecolorargument was ignored on that path. Regression introduced in8.4.0by {pr}
1572. {issue}3731{issue}3732{issue}3740{pr}3739progressbarsettles on its final position whenupdate_min_stepsdoes not divide the total. Steps below that threshold are applied when the
bar finishes, so
show_posrenders20/20rather than the last multipleit reached. {issue}
3571{pr}3769PermissionError: [WinError 32]on Windows. The temporary file backendunlinked its file without closing it first, and Windows refuses to remove a
file the process still holds open, so the cleanup failure masked the real
exception. {issue}
3731{pr}3764{func}
get_pager_filepicked for the output stream, and witherrors="replace"to match the pipe backend. Any text stdout can encodereaches the pager.
PAGERto the pager command instead of silently dropping them. On Windows,PAGER="less -R"now invokesless -Ron the temporary file rather thanbare
less. {pr}37773416{pr}
3777editacceptsos.PathLikevalues forfilename, in addition tostrings. {issue}
2869{pr}3781pycqa/flake8 (flake8)
v7.4.1Compare Source
v7.4.0Compare Source
kjd/idna (idna)
v3.20Compare Source
codec.
PyCQA/isort (isort)
v9.0.2Compare Source
🪲 Fixes
Other changes
processby @DanielNoord in #2677Full Changelog: PyCQA/isort@9.0.1...9.0.2
v9.0.1Compare Source
🪲 Fixes
python -m isortby excluding__main__from mypyc compilation by @DanielNoord with @Copilot in #2643Other changes
Full Changelog: PyCQA/isort@9.0.0...9.0.1
v9.0.0Compare Source
mypycby @DanielNoord in #2586posixpath.abspathby @DanielNoord in #2606stdlibmodules to bestdlib(#2295) @devdanzinfrom X importlines (#2499) @copilot-swe-agentcheck_codewhen usingfloat_to_top+add_imports(#2492) @copilot-swe-agent#inline comments on imports (#2488) @copilot-swe-agent# isort: off/on/splitduringfloat_to_toppreprocessing with CRLF input by @DanielNoord with @Copilot in #2553# isort: skipwhen a__future__import is present (#2092) by @apoorvdarshan in #2574__all__and literals black-compatible (#2280) by @lord-haffi in #2576*imports by @DanielNoord in #2619Anyfromparse.py(#2516) @DanielNoordgit_ignoreconfig by @sparrowt in #2531tomliby @DanielNoord in #2579cruftby @DanielNoord in #2610mypyccompiled wheels by @DanielNoord in #2623mypycby @DanielNoord in #2625test_importablefor local dev by @DanielNoord in #2635python/mypy (mypy)
v2.4.0Compare Source
facelessuser/soupsieve (soupsieve)
v2.10Compare Source
2.10
ignoreoption to API methods that allows the specification of specific pseudo-classes to beignored.
namespacesandcustomobjects must always be a Mapping, previously listsof tuples were also allowed.
Nullof typeSelectorNull.NOCACHEflag that can be used to disable caching optimizations selectors and possibly other futurecaching optimizations. Provided for disabling and also disabling if issues are found with the new caching approach.
~for various cases by employing caching.nth-*family of selectors in certain scenarios by employing caching.customis properly passed down from API functions to compilation.urllib3/urllib3 (urllib3)
v2.8.0Compare Source
==================
Security
Fixed the following security issues:
(High severity,
GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)HTTPResponse.stream()andread_chunked()could buffer a chunk-sizeline of unbounded length in memory. (High severity,
GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__).. caution::
Deprecations & Removals
Retryoptionallowed_methodsto retry any verb.(
#​5044 <https://github.com/urllib3/urllib3/issues/5044>__)Features
Url.auth_decodedandUrl.auth_decoded_joinedconvenienceproperties to the result of
parse_url().(
#​4945 <https://github.com/urllib3/urllib3/issues/4945>__)basic_auth_encodingandproxy_basic_auth_encodingparameters tourllib3.util.make_headers().(
#​5092 <https://github.com/urllib3/urllib3/issues/5092>__)Bugfixes
Fixed response header handling to replace obsolete folded header lines
(
obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLFsequences from appearing in header values such as
Set-Cookie.(
#​1362 <https://github.com/urllib3/urllib3/issues/1362>__)Fixed usage of
proxy_ssl_contextwithProxyManagerwhenuse_forwarding_for_https=True. Passingssl_contextinstead ofproxy_ssl_contextfor HTTPS proxies in this configuration now emits aFutureWarningand will raise an error in v3.0.(
#​2577 <https://github.com/urllib3/urllib3/issues/2577>__)Changed behavior of the default
ConnectionPool.poolinitialization.LifoQueueis now resolved from thequeuemodule after theConnectionPoolis instantiated instead of using the default cachedQueueClsclass property. This is done because sometimes thequeue.LifoQueueis monkey-patched late in the program, such as by gevent.(
#​3289 <https://github.com/urllib3/urllib3/issues/3289>__)Raised
UnrewindableBodyErrorinstead ofValueErrorwhen retrying arequest whose body had
tell()but notseek().(
#​3779 <https://github.com/urllib3/urllib3/issues/3779>__)Decoded percent-encoded SOCKS proxy credentials before authenticating with
the proxy server.
(
#​3785 <https://github.com/urllib3/urllib3/issues/3785>__)Fixed
HTTPResponse.drain_conn()to discard unread response data in 64 KiBchunks (same as the default
amtwhen doingHTTPResponse.stream(...)).(
#​5019 <https://github.com/urllib3/urllib3/issues/5019>__)Fixed
is_ipaddress()to detect non-standard IPv4 forms accepted bysocket.connect, such as hex (0x7f000001), octal (0177.0.0.1), anddecimal integers (
2130706433), ensuring SSL certificate verification usesthe correct mode for these addresses.
(
#​5029 <https://github.com/urllib3/urllib3/issues/5029>__)Fixed
HTTPConnectionPool.urlopenraising a misleadingFullPoolErrorinstead of
ValueErrorwhen called with an invalidtimeoutargument ona pool created with
block=True.(
#​5059 <https://github.com/urllib3/urllib3/issues/5059>__)Fixed port-zero handling to preserve explicit
:0values instead ofsubstituting the default ports 80 or 443 in URL parsing, pool selection,
proxy configuration,
connection_from_url(), and HTTP/2 request authority.(
#​5071 <https://github.com/urllib3/urllib3/issues/5071>,#​5101 <https://github.com/urllib3/urllib3/issues/5101>)Fixed a bug where
PoolManagerpassed theassert_hostnameandassert_fingerprintparameters to HTTP connection pools.(
#​5077 <https://github.com/urllib3/urllib3/issues/5077>__)Fixed
HTTPConnectionPool.urlopen()and HTTP proxy forwarding to strip URLfragments from absolute request targets before sending requests.
(
#​5079 <https://github.com/urllib3/urllib3/issues/5079>__)Added safeguards to the proxy tunneling code to prevent potential security
issues when handling invalid characters in the proxy host and HTTP headers.
This change affects users of Python 3.10, Python 3.11, and Python 3.12 when
the standard library does not contain the fix; those on newer Python versions
should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes.
(
#​5091 <https://github.com/urllib3/urllib3/issues/5091>__)Fixed
HTTPSConnection.connect()overridingProxyConfig.ssl_context'scertificate policy and proxy identity checks with the target connection's TLS
settings when forwarding through an HTTPS proxy.
HTTPSConnectionno longer applies target SNI, assertions, or clientcredentials to forwarding proxy handshakes and continues to use its
ssl_contextas a fallback when an HTTPS proxy forwards an HTTP target.(
#​5093 <https://github.com/urllib3/urllib3/issues/5093>__)Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting
invalid host input such as raw spaces and control characters, malformed
percent-encodings, and percent-encoded control characters in HTTP(S) hosts
and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host
normalization now also follows RFC 3986 normalization rules for
percent-encoded octets by decoding percent-encoded unreserved characters and
uppercasing the hexadecimal digits of retained percent-encoded octets.
(
#​5095 <https://github.com/urllib3/urllib3/issues/5095>__)Fixed an
AttributeErroron Python built with OpenSSL 4+, wheressl.PROTOCOL_TLSv1no longer exists.(
#​5097 <https://github.com/urllib3/urllib3/issues/5097>__)Fixed
urllib3.contrib.pyopensslto use cryptography APIs when reading acertificate subject and loading encrypted private keys, avoiding
DeprecationWarningraised by pyOpenSSL 26.3.0+.(
#​5103 <https://github.com/urllib3/urllib3/issues/5103>__)Fixed handling of HTTP 303 redirects for requests with chunked or file-like
bodies.
(
#​5161 <https://github.com/urllib3/urllib3/issues/5161>__)Fixed
assert_fingerprint()to raiseSSLErrorinstead ofbinascii.Errorwhen a fingerprint has a supported length but containsnon-hexadecimal characters.
(
#​5211 <https://github.com/urllib3/urllib3/issues/5211>__)Misc
testdependency group containing the minimum dependencies neededto run the test suite, intended for downstream packagers. The
dev-baseand
mypygroups now include this new group viainclude-group,removing duplication.
(
#​3594 <https://github.com/urllib3/urllib3/issues/3594>__)(
#​5094 <https://github.com/urllib3/urllib3/issues/5094>__)(
#​5166 <https://github.com/urllib3/urllib3/issues/5166>__)(
#​5209 <https://github.com/urllib3/urllib3/issues/5209>__)(
#​5232 <https://github.com/urllib3/urllib3/issues/5232>,#​5234 <https://github.com/urllib3/urllib3/issues/5234>,#​5239 <https://github.com/urllib3/urllib3/issues/5239>__)Kludex/uvicorn (uvicorn)
v0.54.0: Version 0.54.0Compare Source
📨 Send metadata after the response body
uvicorn0.54.0 adds response trailers and103 Early Hintsto its experimental HTTP/2 implementation throughzttp.uv add uvicorn==0.54.0 "zttp>=0.0.34"http.response.trailersextension lets applications send metadata, such as checksums, after the response body. Clients must sendTE: trailersto receive them. Multiple trailer messages are combined before completing the response.--http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.💡 Hint at resources before the final response
103 Early Hintsover HTTP/2 (#3137). Applications can use the ASGIhttp.response.early_hintextension to send resource hints before the final response. Each supplied link becomes a separateLinkheader.Full changelog: 0.53.0...0.54.0
v0.53.0: Version 0.53.0Compare Source
🌐 Opt-in HTTP/2 support
uvicorn0.53.0 adds experimental HTTP/2 throughzttp, alongside a newzuvloopintegration and connection-handling improvements.uv add uvicorn==0.53.0zttp(#2982, #3101). Installzttp, then enable HTTP/2 with--http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.⚙️ More event loop choice
zuvloop(#3104). Installzuvloopseparately and select it explicitly with--loop zuvloopon CPython 3.14 or newer.🛡️ More reliable connections and proxies
Connection: closetoken lists (#3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.FORWARDED_ALLOW_IPSvalue now includes::1.Full changelog: 0.52.4...0.53.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.