Skip to content

chore(deps): bump the minor-and-patch group across 1 directory with 17 updates - #975

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python/minor-and-patch-f8e36d2ba1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python/minor-and-patch-f8e36d2ba1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 17 updates in the /python directory:

Package From To
pytest 9.0.3 9.1.1
pytest-rerunfailures 16.2 16.7
litellm 1.85.0 1.102.1
python-dotenv 1.2.2 1.2.3
pydantic 2.13.4 2.13.5
joblib 1.5.3 1.6.0
pytest-asyncio 1.3.0 1.4.0
pydantic-settings 2.14.2 2.15.0
langwatch 1.0.0 1.4.0
twilio 9.10.9 9.11.1
fastapi 0.136.1 0.141.1
uvicorn 0.47.0 0.54.0
google-genai 2.4.0 2.25.0
elevenlabs 2.49.0 2.69.0
pre-commit 4.6.0 4.6.2
pyright 1.1.409 1.1.414
streamlit 1.57.0 1.64.0

Updates pytest from 9.0.3 to 9.1.1

Release notes

Sourced from pytest's releases.

9.1.1

pytest 9.1.1 (2026-06-19)

Bug fixes

  • #14220: Fixed a logic bug in pytest.RaisesGroup which would might cause it to display incorrect "It matches FooError() which was paired with BarError" messages.
  • #14591: Fixed a regression in pytest 9.1.0 which caused overriding a parametrized fixture with an indirect @​pytest.mark.parametrize to fail with "duplicate parametrization of '<fixture name>'".
  • #14606: Fixed list-item typing errors from mypy in @pytest.mark.parametrize <pytest.mark.parametrize ref> argvalues parameter.
  • #14608: Fixed a regression in pytest 9.1.0 where conftest.py files located in <invocation dir>/test* were no longer loaded as initial conftests when invoked without arguments. This could cause certain hooks (like pytest_addoption) in these files to not fire.

9.1.0

pytest 9.1.0 (2026-06-13)

Removals and backward incompatible breaking changes

  • #14533: When using --doctest-modules, autouse fixtures with module, package or session scope that are defined inline in Python test modules (not plugins or conftests) will now possibly execute twice.

    If this is undesirable, move the fixture definition to a conftest.py file if possible.

    Technical explanation for those interested: When using --doctest-modules, pytest possibly collects Python modules twice, once as pytest.Module and once as a DoctestModule (depending on the configuration). Due to improvements in pytest's fixture implementation, if e.g. the DoctestModule collects a fixture, it is now visible to it only, and not to the Module. This means that both need to register the fixtures independently.

Deprecations (removal in next major release)

  • #10819: Added a deprecation warning for class-scoped fixtures defined as instance methods (without @classmethod). Such fixtures set attributes on a different instance than the test methods use, leading to unexpected behavior. Use @classmethod decorator instead -- by yastcher.

    See 10819 and 14011.

  • #12882: Calling request.getfixturevalue() <pytest.FixtureRequest.getfixturevalue> during teardown to request a fixture that was not already requested is now deprecated and will become an error in pytest 10.

    See dynamic-fixture-request-during-teardown for details.

  • #13409: Using non-~collections.abc.Collection iterables (such as generators, iterators, or custom iterable objects) for the argvalues parameter in @pytest.mark.parametrize <pytest.mark.parametrize ref> and metafunc.parametrize <pytest.Metafunc.parametrize> is now deprecated.

    These iterables get exhausted after the first iteration, leading to tests getting unexpectedly skipped in cases such as running pytest.main() multiple times, using class-level parametrize decorators, or collecting tests multiple times.

    See parametrize-iterators for details and suggestions.

  • #13946: The private config.inicfg attribute is now deprecated. Use config.getini() <pytest.Config.getini> to access configuration values instead.

    See config-inicfg for more details.

  • #14004: Passing baseid to ~pytest.FixtureDef or nodeid strings to fixture registration APIs is now deprecated. These are internal pytest APIs that are used by some plugins.

... (truncated)

Commits
  • cf470ec Prepare release version 9.1.1
  • e0c8ce6 Merge pull request #14625 from pytest-dev/patchback/backports/9.1.x/a07c31a97...
  • 1b82d16 Merge pull request #14624 from pytest-dev/patchback/backports/9.1.x/b375b79ec...
  • 501c4bc Merge pull request #14596 from bluetech/doc-classmethod
  • b61f588 Merge pull request #14622 from chrisburr/fix-14608-initial-conftest-test-subdir
  • 9a567e0 [automated] Update plugin list (#14617) (#14618)
  • ef8b299 Merge pull request #14620 from pytest-dev/patchback/backports/9.1.x/680f9f3ed...
  • 66abd07 Merge pull request #14220 from bysiber/fix-stale-iexp-raisesgroup
  • 79fbf93 Merge pull request #14612 from pytest-dev/patchback/backports/9.1.x/974ed48b6...
  • 0d312eb Merge pull request #14611 from bluetech/parametrize-argvalues-typing
  • Additional commits viewable in compare view

Updates pytest-rerunfailures from 16.2 to 16.7

Changelog

Sourced from pytest-rerunfailures's changelog.

16.7 (2026-09-17)

Features ++++++++

  • Allow configuring only_rerun regular expressions in pytest.ini files. ([#165](https://github.com/pytest-dev/pytest-rerunfailures/issues/165) <https://github.com/pytest-dev/pytest-rerunfailures/issues/165>_)
  • Show each rerun attempt and its final outcome in the rerun test summary info section. ([#191](https://github.com/pytest-dev/pytest-rerunfailures/issues/191) <https://github.com/pytest-dev/pytest-rerunfailures/issues/191>_)
  • Allow flaky marker conditions to inspect the exception that caused a failed test phase, including when running with pytest-xdist. ([#230](https://github.com/pytest-dev/pytest-rerunfailures/issues/230) <https://github.com/pytest-dev/pytest-rerunfailures/issues/230>_)

Bug Fixes +++++++++

  • Match only_rerun against the full exception chain (__cause__ and __context__), not only the outermost exception. Match rerun_except against explicit __cause__ links only, so implicit except / finally context does not suppress reruns. ([#353](https://github.com/pytest-dev/pytest-rerunfailures/issues/353) <https://github.com/pytest-dev/pytest-rerunfailures/issues/353>_)
  • Fix INTERNALERROR when only_rerun or rerun_except is given a bare exception class instead of a list. ([#362](https://github.com/pytest-dev/pytest-rerunfailures/issues/362) <https://github.com/pytest-dev/pytest-rerunfailures/issues/362>_)
  • Fix subtest reruns with newer pytest versions that use structured NodeId values internally. ([#363](https://github.com/pytest-dev/pytest-rerunfailures/issues/363) <https://github.com/pytest-dev/pytest-rerunfailures/issues/363>_)
  • Mark teardown failures from an attempt that is rerun as reruns, so a later successful attempt is not reported as an error. ([#366](https://github.com/pytest-dev/pytest-rerunfailures/issues/366) <https://github.com/pytest-dev/pytest-rerunfailures/issues/366>_)

Misc ++++

  • Keep the test suite passing when pytest-randomly is installed, including when the outer pytest is started with -p no:randomly. ([#218](https://github.com/pytest-dev/pytest-rerunfailures/issues/218) <https://github.com/pytest-dev/pytest-rerunfailures/issues/218>_)
  • Test the free-threaded Python 3.14 build in CI, via a new py314t tox environment and a matching workflow job. ([#361](https://github.com/pytest-dev/pytest-rerunfailures/issues/361) <https://github.com/pytest-dev/pytest-rerunfailures/issues/361>_)

16.6.1 (2026-09-03)

Bug Fixes

... (truncated)

Commits
  • fead4c6 Preparing release 16.7
  • ed62cfc Show each rerun attempt outcome in summary (#370)
  • 64687c9 Add pytest.ini support for only_rerun (#369)
  • 1997015 Preserve rerun status for teardown failures (#367)
  • 4220386 Match only_rerun against wrapped exception causes (#364)
  • 87d81b2 Keep nested pytester sessions isolated from pytest-randomly (#368)
  • be14a6b Allow flaky conditions to inspect failure exceptions (#365)
  • 78561a5 ci: test the free-threaded Python 3.14 build (#361)
  • 402afb4 Fix bare exception class in only_rerun / rerun_except causing INTERNALERROR (...
  • 87a8b47 Fix subtest reruns with structured NodeId keys (#363)
  • Additional commits viewable in compare view

Updates litellm from 1.85.0 to 1.102.1

Release notes

Sourced from litellm's releases.

v1.102.1

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.102.1

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.102.1/cosign.pub \
  ghcr.io/berriai/litellm:v1.102.1

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed

Full Changelog: BerriAI/litellm@v1.102.0...v1.102.1

v1.102.0

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

... (truncated)

Commits
  • d09bbae Merge pull request #42618 from BerriAI/litellm_backport_stable_1_102_x_realti...
  • 188c9d1 Merge pull request #42595 from BerriAI/litellm_cherrypick_1_102_x
  • d1cd2dc chore(backport): regenerate the openapi snapshot and dashboard api types for ...
  • 5aa45f1 test(realtime): drop legacy InvalidStatusCode tests and pin websockets imports
  • 4bfac88 fix(ui): adapt the jev dashboard pieces to stable/1.102.x
  • da246e9 chore(deps): bump anyio to 4.14.2 and soupsieve to 2.9.0
  • 9a46f1f Merge pull request #41462 from BerriAI/litellm_otel_promote_nested_request_me...
  • 96e7739 fix(realtime): surface an upstream handshake refusal as an error event and po...
  • d068734 feat(openrouter): price typesafe/jev-1.13 and add an openrouter decisions pas...
  • e20cfbe feat(auto-router): add JEV classifier alongside LLM classifier
  • Additional commits viewable in compare view

Updates python-dotenv from 1.2.2 to 1.2.3

Release notes

Sourced from python-dotenv's releases.

v1.2.3

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638
Changelog

Sourced from python-dotenv's changelog.

[1.2.3] - 2026-08-16

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638
Commits
  • 49515af Bump version: 1.2.2 → 1.2.3
  • 8ac846f chore: add release runbook (RELEASING.md) and make release target
  • bb31c94 docs: add 1.2.3 release notes (#606, #638, #680)
  • f7b18d9 fix: round-trip backslashes through set_key (#680)
  • 751f8c1 ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...
  • f1937b6 chore(deps): update mkdocs-include-markdown-plugin requirement from >=6.0.0 t...
  • 45b9372 chore(deps): update pytest requirement from >=3.9 to >=9.0.3 (#653)
  • 72896e9 docs: fix broken mkdocs link in CONTRIBUTING.md (#636)
  • 72754a1 ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...
  • 078325e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...
  • Additional commits viewable in compare view

Updates pydantic from 2.13.4 to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates joblib from 1.5.3 to 1.6.0

Changelog

Sourced from joblib's changelog.

Release 1.6.0 - 2026/08/31

  • Fix caching of functions whose source cannot be retrieved, such as functions defined in a notebook cell. Their identity fell back to str(hash(func.__code__)), which is salted by PYTHONHASHSEED and so differed between processes. A worker reading the func_code.py written by another one concluded that the function had changed and wiped the whole cache directory for it, discarding results computed by its peers. func_code.py is also no longer rewritten in place, so a reader can no longer catch it half-written and draw the same conclusion. joblib/joblib#1694

  • Drop python 3.9 support. The oldest supported Python version is now Python 3.10. joblib/joblib#1773

  • Fix eval_expr (used to evaluate the pre_dispatch argument of Parallel) to raise a ValueError as documented instead of leaking a ZeroDivisionError for expressions that divide or take a modulo by zero. joblib/joblib#1810

  • MemorizedResult now forwards mmap_mode to its store backend, so a cached array reconstructed from a location is memory-mapped as requested instead of being loaded fully into memory. joblib/joblib#1799

  • Unvendor cloudpickle to more quickly benefit from maintenance releases of cloudpickle joblib/joblib#1775

  • Fix Memory.cache for functions with a keyword-only argument that has a default declared before a keyword-only argument without a default. joblib/joblib#1731

  • Fix behavior of filter_args on some precise cases. joblib/joblib#1800

  • Fix a concurrency error that could happen with unordered generator. joblib/joblib#1789

  • Fix: dump() now accepts any input os.PathLike object to be consistent with load. joblib/joblib#1812

  • The documentation now uses pydata sphinx theme. Furthermore, optional dependencies test and docs have been added to pyproject.toml. joblib/joblib#1774

  • Vendor loky 3.6.0

... (truncated)

Commits
  • cd9a6b0 Release 1.6.0 (#1844)
  • d873f97 MNT vendor loky 3.6.0 (#1843)
  • 4ff61af Bump the github-actions group with 4 updates (#1832)
  • 804f472 FIX make func_code stable across processes when the source is unavailable (#1...
  • 65cc49d TST Restore RNG sequence in hash compatibility test (#1837)
  • c1b6541 CI Use pytest-run-parallel on free-threaded build (#1819)
  • f6b80d3 MNT Simplify isinstance check in hashing (#1835)
  • fa4d5af MNT remove python 3.9 from CI (#1773)
  • 53cea7b DOC Update release docs to reflect usage of trusted publishing (#1826)
  • 26500e9 Bump the github-actions group across 1 directory with 3 updates (#1790)
  • Additional commits viewable in compare view

Updates pytest-asyncio from 1.3.0 to 1.4.0

Release notes

Sourced from pytest-asyncio's releases.

pytest-asyncio v1.4.0

1.4.0 - 2026-05-26

Deprecated

  • Overriding the event_loop_policy fixture is deprecated. Use the pytest_asyncio_loop_factories hook instead. (#1419)

Added

  • Added the pytest_asyncio_loop_factories hook to parametrize asyncio tests with custom event loop factories.

    The hook returns a mapping of factory names to loop factories, and pytest.mark.asyncio(loop_factories=[...]) selects a subset of configured factories per test. When a single factory is configured, test names are unchanged.

    Synchronous @pytest_asyncio.fixture functions now see the correct event loop when custom loop factories are configured, even when test code disrupts the current event loop (e.g., via asyncio.run() or asyncio.set_event_loop(None)). (#1164)

Changed

  • Improved the readability of the warning message that is displayed when asyncio_default_fixture_loop_scope is unset (#1298)
  • Only import asyncio.AbstractEventLoopPolicy for type checking to avoid raising a DeprecationWarning. (#1394)
  • Updated minimum supported pytest version to v8.4.0. (#1397)

Fixed

  • Fixed a ResourceWarning: unclosed event loop warning that could occur when a synchronous test called asyncio.run() or otherwise unset the current event loop after pytest-asyncio had run an async test or fixture. (#724)

Notes for Downstream Packagers

  • Added dependency on sphinx-tabs >= 3.5 to organize documentation examples into tabs. (#1395)

pytest-asyncio v1.4.0a2

1.4.0a2 - 2026-05-02

Deprecated

  • Overriding the event_loop_policy fixture is deprecated. Use the pytest_asyncio_loop_factories hook instead. (#1419)

Added

  • Added the pytest_asyncio_loop_factories hook to parametrize asyncio tests with custom event loop factories.

    The hook returns a mapping of factory names to loop factories, and pytest.mark.asyncio(loop_factories=[...]) selects a subset of configured factories per test. When a single factory is configured, test names are unchanged on pytest 8.4+.

    Synchronous @pytest_asyncio.fixture functions now see the correct event loop when custom loop factories are configured, even when test code disrupts the current event loop (e.g., via asyncio.run() or asyncio.set_event_loop(None)). (#1164)

Changed

  • Improved the readability of the warning message that is displayed when asyncio_default_fixture_loop_scope is unset (#1298)
  • Only import asyncio.AbstractEventLoopPolicy for type checking to avoid raising a DeprecationWarning. (#1394)

... (truncated)

Commits
  • 6e14cd2 chore: Prepare release of v1.4.0.
  • 4b900fb Build(deps): Bump codecov/codecov-action from 6.0.0 to 6.0.1
  • ab9f632 Build(deps): Bump zipp from 3.23.1 to 4.1.0
  • a56fc77 Build(deps): Bump hypothesis from 6.152.6 to 6.152.8
  • e8bae9b Build(deps): Bump requests from 2.34.0 to 2.34.2
  • fc43340 Build(deps): Bump idna from 3.14 to 3.15
  • 762eaf5 Build(deps): Bump jaraco-functools from 4.4.0 to 4.5.0
  • b62e222 Build(deps): Bump click from 8.3.3 to 8.4.0
  • 9190447 Build(deps): Bump pydantic from 2.13.3 to 2.13.4
  • 82a393c ci: Remove unnecessary debug output.
  • Additional commits viewable in compare view

Updates pydantic-settings from 2.14.2 to 2.15.0

Release notes

Sourced from pydantic-settings's releases.

v2.15.0

Highlights

Behavior changes

  • case_sensitive now applies to init kwargs and config-file sources (#900). InitSettingsSource and the JSON/TOML/YAML config sources previously ignored case_sensitive. Since it defaults to False, case-insensitive matching is now the default for these sources — e.g. Settings(TeSt=...) now populates a test field where it previously did not. Nested keys are still matched case-sensitively.
  • Fields with unresolved forward references now emit a warning (#901). Settings sources can silently fail to resolve such fields; they now raise IncompleteFieldDefinitionWarning telling you to call model_rebuild(). If you have filterwarnings = error configured, this may surface as a new failure.
  • Non-JSON env values for strict fields now raise ValidationError (#926) instead of a less specific error.

New features

  • Show environment variable names in CLI help via cli_show_env_vars=True (#860), so generated --help output doubles as configuration documentation.
  • PYDANTIC_SETTINGS_DEBUG for debugging settings resolution (#906, #913). Set it to a truthy value with DEBUG logging enabled to see each source's contribution in priority order, which source won for each value, and which env_file/secret files were probed, loaded, or skipped — the long-standing "why isn't my .env being picked up?" question.
  • toml_table_header for regular TOML files (#882, #886, #887), letting you root settings at a nested table in any TOML file, not just pyproject.toml.
  • Traversable support for JSON/TOML/YAML file sources (#902), so you can load config packaged inside a distribution — including files inside a zip or wheel — via importlib.resources.files(...) without casting to Path.
  • GCP: project_id can come from an earlier settings source (#878), rather than only from the constructor or GOOGLE_CLOUD_PROJECT.

Bug fixes

  • Fix env vars not loading on Windows with case_sensitive=True (#894). Windows upper-cases os.environ keys, so fields raised Field required instead of picking up their values.
  • Read secret files as UTF-8 instead of the platform locale encoding (#917). On Windows code pages such as cp1252 this silently corrupted non-ASCII secrets.
  • Fix AliasPath on nested model fields not JSON-decoding env values (#898).
  • Fix case-insensitive matching for optional nested models (#905).
  • Fix dotenv extras being wrongly claimed by a complex field sharing a name prefix (#912) — e.g. dbx_token being swallowed by a db: dict field.
  • Fix nested_model_default_partial_update=True corrupting discriminated unions (#876).
  • Fix Secret subclasses crashing when loaded from the environment (#920).
  • Fix enum names not parsing through nested annotations such as Optional[Annotated[MyEnum, ...]] with env_parse_enums=True (#910).
  • An empty yaml_config_section now falls back to defaults instead of raising AttributeError: 'NoneType' object has no attribute 'keys' (#914).
  • NestedSecretsSettingsSource no longer follows symlinks pointing outside secrets_dir (#889).
  • GCP: skip the list_secrets call when case_sensitive=True (#862), lowering the required IAM permissions to just roles/secretmanager.secretAccessor.
  • AWS: types-boto3[secretsmanager] is no longer required at runtime (#880).

Documentation

  • Document JSON parsing of complex env values, plus a comma-separated-values recipe (#919).
  • Recommend an async settings loading pattern (#908).
  • Clarify behavior when an unprefixed value is present in a dotenv file (#895).
  • Clarify environment variable helper descriptions (#867) and fix assorted typos (#904).

What's Changed

... (truncated)

Commits
  • f725ca1 Prepare release 2.15.0 (#930)
  • 28f35c2 Bump the python-packages group with 4 updates (#929)
  • 9056db0 test: move function-local imports to the top of test modules (#927)
  • f077e3a fix: raise ValidationError for non-JSON env values on strict fields (#926)
  • ae25d70 fix: treat Secret subclasses as non-complex fields (#716) (#920)
  • 798dcea Bump the python-packages group with 4 updates (#924)
  • a190041 Bump the github-actions group with 4 updates (#925)
  • 5d93332 Bump the python-packages group with 4 updates (#921)
  • d2fdeda fix: read secret files as UTF-8 instead of the locale encoding (#917)
  • 2256a4e Bump the python-packages group with 3 updates (#915)
  • Additional commits viewable in compare view

Updates langwatch from 1.0.0 to 1.4.0

Changelog

Sourced from langwatch's changelog.

1.4.0 (2025-10-31)

Features

Bug Fixes

  • azure ad extra required permission and env var names (#764) (5bfabd3)
  • ci failing (#748) (0b25070)
  • dataset routes (#756) (da736e0)
  • error handling (#747) (732a7ef)
  • ignore 'Function already exist' lambda errors due to race conditions and use existing lambda (c7b7787)
  • integration tests for typescript sdk (#757) (bfd79bb)
  • mermaid sequence diagram sanitization for tricky span names (cae4077)
  • next.js-15: Register NodeTracerProvider globally when ProxyTracerProvider detected (87c1f1f)
  • register NodeTracerProvider globally when ProxyTracerProvider detected (#754) (87c1f1f)
  • rerendering loop issues on component type workflows on the studio (8225238)

Miscellaneous

1.3.1 (2025-10-27)

Bug Fixes

1.3.0 (2025-10-24)

Features

Bug Fixes

... (truncated)

Commits
  • 1108004 chore: release main (#746)
  • 5bfabd3 fix: azure ad extra required permission and env var names (#764)
  • f13366e feat: delete dataset confirmation (#762)
  • da736e0 fix: dataset routes (#756)
  • 21376dc chore: temp disable e2e tests for typescript sdk (#758)
  • bfd79bb fix: integration tests for typescript sdk (#757)
  • 5a003df test: python ci tests
  • 93c9805 ci: fix release please version python file update
  • 697792c chore: bump typescript sdk to v0.7.4 (#755)
  • 87c1f1f fix: register NodeTracerProvider globally when ProxyTracerProvider detected (...
  • Additional commits viewable in compare view

Updates twilio from 9.10.9 to 9.11.1

Release notes

Sourced from twilio's releases.

9.11.1

Release Notes

Library - Fix

Audiences

  • 2026-09-01

  • Backticked brace- and angle-bracket-bearing tokens in descriptions for MDX safety.
  • Updated a prose reference to the renamed FetchCohortSnapshot operation.
  • 2026-08-26

  • Removed 5 path(s):
  • /preview/Audiences (AdminListAudiences)
  • /preview/Audiences/{audienceId} (AdminGetAudience)
  • /preview/Snapshots (AdminListSnapshots)
  • /preview/Snapshots/{snapshotId} (AdminGetSnapshot)
  • /preview/Operations/{operationId} (AdminGetOperation)...

    Description has been truncated

    Note
    Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 6, 2026

@langwatch-agent langwatch-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No actionable findings in this static review.

Reviewed the Python dependency/lockfile changes and existing CI without finding a sufficiently established code defect to report inline. This is NOT a green validation result: the PR's Python job exits 3 with an internal error in pytest_asyncio_concurrent's asyncio.get_event_loop(), after 1470 passes and seven errors. Main also has failures, but the latest main log I inspected showed live-example/budget errors rather than proving this internal error inherited. Isolate the async test-runner combination and obtain a completing run before treating the bump as validated.

Validation boundary: review skill used; external PR code, dependency installation, and package scripts were not executed. This is not an approval or a claim that untested dependency artifacts are safe.

LangWatch-Review: verdict=clean sha=0f23488747a502f3f38b8c446ce889d950285eba p0=0 p1=0 p2=0 p3=0

@dependabot
dependabot Bot force-pushed the dependabot/uv/python/minor-and-patch-f8e36d2ba1 branch from 0f23488 to 2863590 Compare September 7, 2026 21:01

@langwatch-agent langwatch-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No actionable findings established in this static review (P0=0, P1=0, P2=0, P3=0).

Reviewed Python lock package/version/source changes. No concrete security or compatibility defect was established statically. This is NOT ready-on-CI evidence: test (3.12) exits 3 after pytest_asyncio_concurrent calls asyncio.get_event_loop with no current loop (1470 passed, 7 errors in the log). I have not established which dependency change caused that failure or whether it also occurs on base. Resolve or isolate that red job before treating this update as validated.

External-contribution safety: reused the existing worktree; no PR code, dependency installation, package scripts, or live secret-bearing tests were executed. This is a COMMENT review, not approval or a claim that all CI passed.

LangWatch-Review: verdict=clean sha=286359076a0e0a495e4c6ed4e75d81f103074aab p0=0 p1=0 p2=0 p3=0

@dependabot
dependabot Bot force-pushed the dependabot/uv/python/minor-and-patch-f8e36d2ba1 branch from 2863590 to 4bb2306 Compare September 14, 2026 21:02
@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 4d7fa96b-dfdf-4982-a034-b1911040be27

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@langwatch-agent langwatch-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 P2 dependency-migration finding; details inline. Static review of the current head, base consumers and CI logs. No PR code, installs or package scripts executed.

LangWatch-Review: verdict=findings sha=4bb23060f01aff0149690f419deabad56bccc69d p0=0 p1=0 p2=1 p3=0

Comment thread python/uv.lock
]

[[package]]
name = "pytest-asyncio"
version = "1.3.0"
version = "1.4.0"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 · Reconcile the two asyncio test plugins before the bump

  • What you're looking at. This upgrades pytest-asyncio to 1.4.0 while pytest-asyncio-concurrent still relies on a current global event loop.

  • Why it's scary. The 1.4 runner lifecycle no longer restores the previous loop in _temporary_event_loop_policy. Current-head Python 3.12 CI job 104151864356 ends with an INTERNALERROR in pytest_asyncio_concurrent.plugin at asyncio.get_event_loop(), after seven event-structure setup errors. The latest main Python run passed. Keep compatible test-plugin versions or explicitly reconcile loop ownership, and require the complete Python 3.12 job including concurrent groups to finish normally. No local reproduction was executed, so isolate this version change when validating the fix.

@dependabot
dependabot Bot force-pushed the dependabot/uv/python/minor-and-patch-f8e36d2ba1 branch from 4bb2306 to ad585c2 Compare September 21, 2026 21:03

@langwatch-agent langwatch-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One P2 remains on this head; see inline evidence from the current CI run. Static review only, with no contributor code or package scripts executed locally.

LangWatch-Review: verdict=findings sha=ad585c26e21f18dca2ac88ac8a445a66e62b85b8 p0=0 p1=0 p2=1 p3=0

Comment thread python/uv.lock
]

[[package]]
name = "pytest-asyncio"
version = "1.3.0"
version = "1.4.0"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 · Reconcile asyncio test-plugin loop ownership

  • What you're looking at. The lock upgrades pytest-asyncio from 1.3.0 to 1.4.0 while retaining the concurrent test plugin.

  • Why it's scary. The current Python 3.12 job still terminates with INTERNALERROR in pytest_asyncio_concurrent.plugin at asyncio.get_event_loop(): there is no current event loop. This leaves concurrent coverage incomplete despite the many passing tests. Retain compatible plugin versions or reconcile loop ownership and rerun the complete job. The failure is confirmed in CI, but the exact version interaction was not isolated locally. CI evidence.

…7 updates

Bumps the minor-and-patch group with 17 updates in the /python directory:

| Package | From | To |
| --- | --- | --- |
| [pytest](https://github.com/pytest-dev/pytest) | `9.0.3` | `9.1.1` |
| [pytest-rerunfailures](https://github.com/pytest-dev/pytest-rerunfailures) | `16.2` | `16.7` |
| [litellm](https://github.com/BerriAI/litellm) | `1.85.0` | `1.102.1` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |
| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |
| [joblib](https://github.com/joblib/joblib) | `1.5.3` | `1.6.0` |
| [pytest-asyncio](https://github.com/pytest-dev/pytest-asyncio) | `1.3.0` | `1.4.0` |
| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |
| [langwatch](https://github.com/langwatch/langwatch) | `1.0.0` | `1.4.0` |
| [twilio](https://github.com/twilio/twilio-python) | `9.10.9` | `9.11.1` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.136.1` | `0.141.1` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.47.0` | `0.54.0` |
| [google-genai](https://github.com/googleapis/python-genai) | `2.4.0` | `2.25.0` |
| [elevenlabs](https://github.com/elevenlabs/elevenlabs-python) | `2.49.0` | `2.69.0` |
| [pre-commit](https://github.com/pre-commit/pre-commit) | `4.6.0` | `4.6.2` |
| [pyright](https://github.com/RobertCraigie/pyright-python) | `1.1.409` | `1.1.414` |
| [streamlit](https://github.com/streamlit/streamlit) | `1.57.0` | `1.64.0` |



Updates `pytest` from 9.0.3 to 9.1.1
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest@9.0.3...9.1.1)

Updates `pytest-rerunfailures` from 16.2 to 16.7
- [Changelog](https://github.com/pytest-dev/pytest-rerunfailures/blob/master/CHANGES.rst)
- [Commits](pytest-dev/pytest-rerunfailures@16.2...16.7)

Updates `litellm` from 1.85.0 to 1.102.1
- [Release notes](https://github.com/BerriAI/litellm/releases)
- [Commits](BerriAI/litellm@v1.85.0...v1.102.1)

Updates `python-dotenv` from 1.2.2 to 1.2.3
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.2...v1.2.3)

Updates `pydantic` from 2.13.4 to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.13.4...v2.13.5)

Updates `joblib` from 1.5.3 to 1.6.0
- [Release notes](https://github.com/joblib/joblib/releases)
- [Changelog](https://github.com/joblib/joblib/blob/main/CHANGES.rst)
- [Commits](joblib/joblib@1.5.3...1.6.0)

Updates `pytest-asyncio` from 1.3.0 to 1.4.0
- [Release notes](https://github.com/pytest-dev/pytest-asyncio/releases)
- [Commits](pytest-dev/pytest-asyncio@v1.3.0...v1.4.0)

Updates `pydantic-settings` from 2.14.2 to 2.15.0
- [Release notes](https://github.com/pydantic/pydantic-settings/releases)
- [Commits](pydantic/pydantic-settings@v2.14.2...v2.15.0)

Updates `langwatch` from 1.0.0 to 1.4.0
- [Release notes](https://github.com/langwatch/langwatch/releases)
- [Changelog](https://github.com/langwatch/langwatch/blob/main/CHANGELOG.md)
- [Commits](https://github.com/langwatch/langwatch/compare/langwatch@v1.0.0...langwatch@v1.4.0)

Updates `twilio` from 9.10.9 to 9.11.1
- [Release notes](https://github.com/twilio/twilio-python/releases)
- [Changelog](https://github.com/twilio/twilio-python/blob/main/CHANGES.md)
- [Commits](twilio/twilio-python@9.10.9...9.11.1)

Updates `fastapi` from 0.136.1 to 0.141.1
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.136.1...0.141.1)

Updates `uvicorn` from 0.47.0 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.47.0...0.54.0)

Updates `google-genai` from 2.4.0 to 2.25.0
- [Release notes](https://github.com/googleapis/python-genai/releases)
- [Changelog](https://github.com/googleapis/python-genai/blob/main/CHANGELOG.md)
- [Commits](googleapis/python-genai@v2.4.0...v2.25.0)

Updates `elevenlabs` from 2.49.0 to 2.69.0
- [Release notes](https://github.com/elevenlabs/elevenlabs-python/releases)
- [Commits](elevenlabs/elevenlabs-python@v2.49.0...v2.69.0)

Updates `pre-commit` from 4.6.0 to 4.6.2
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md)
- [Commits](pre-commit/pre-commit@v4.6.0...v4.6.2)

Updates `pyright` from 1.1.409 to 1.1.414
- [Release notes](https://github.com/RobertCraigie/pyright-python/releases)
- [Commits](RobertCraigie/pyright-python@v1.1.409...v1.1.414)

Updates `streamlit` from 1.57.0 to 1.64.0
- [Release notes](https://github.com/streamlit/streamlit/releases)
- [Commits](streamlit/streamlit@1.57.0...1.64.0)

---
updated-dependencies:
- dependency-name: elevenlabs
  dependency-version: 2.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: fastapi
  dependency-version: 0.141.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: google-genai
  dependency-version: 2.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: joblib
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langwatch
  dependency-version: 1.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: litellm
  dependency-version: 1.99.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: pre-commit
  dependency-version: 4.6.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: pydantic-settings
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: pyright
  dependency-version: 1.1.411
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: pytest
  dependency-version: 9.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: pytest-asyncio
  dependency-version: 1.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: pytest-rerunfailures
  dependency-version: 16.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: python-dotenv
  dependency-version: 1.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: streamlit
  dependency-version: 1.63.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: twilio
  dependency-version: 9.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: uvicorn
  dependency-version: 0.52.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/python/minor-and-patch-f8e36d2ba1 branch from ad585c2 to 9116ae8 Compare September 29, 2026 09:01
@github-actions

Copy link
Copy Markdown
Contributor

Automated low-risk assessment

This PR was evaluated against the repository's Low-Risk Pull Requests procedure and does not qualify as low risk.

This PR's diff could not be evaluated automatically: Diff too large for automated evaluation (190348 chars exceeds 100000-char limit). Manual review required.

This PR requires a manual review before merging.

@langwatch-agent langwatch-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One P2 remains on this head; details and current CI evidence inline. Static review only; no contributor code, installs or package scripts executed locally.

LangWatch-Review: verdict=findings sha=9116ae839cbb7f54c260ee1ebb8235fbe533ed52 p0=0 p1=0 p2=1 p3=0

Comment thread python/uv.lock
]

[[package]]
name = "pytest-asyncio"
version = "1.3.0"
version = "1.4.0"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 · Resolve the concurrent test-runner incompatibility before upgrading

  • What you're looking at. The lock continues to move pytest-asyncio from 1.3.0 to 1.4.0 alongside pytest and rerun-plugin changes, while retaining pytest_asyncio_concurrent.

  • Why it's scary. Current Python 3.12 CI still exits 3 with INTERNALERROR in pytest_asyncio_concurrent at asyncio.get_event_loop(): no current event loop. It reports 1535 passes but also seven errors and does not complete normally. The earlier finding remains: retain a working plugin combination or reconcile loop ownership, then obtain a completing run. The exact dependency interaction was not isolated locally. Current CI evidence.

@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant