Skip to content

Bump the locks group across 1 directory with 46 updates - #245

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/requirements/locks-907ba5716f
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/requirements/locks-907ba5716f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the locks group with 46 updates in the /requirements directory:

Package From To
charset-normalizer 3.5.1 3.5.2
cryptography 50.0.1 50.0.2
idna 3.19 3.20
pyproject-hooks 1.2.0 1.3.3
urllib3 2.7.0 2.8.0
ast-serialize 0.11.2 0.12.1
coverage 7.16.1 7.16.2
googleapis-common-protos 1.75.3 1.75.5
httpcore2 2.13.0 2.13.1
httpx2 2.13.0 2.13.1
hypothesis 6.168.0 6.168.4
langchain 1.4.0 1.4.3
langchain-core 1.6.3 1.6.6
langchain-openai 1.6.2 1.6.7
langgraph 1.2.11 1.2.12
langgraph-sdk 0.4.4 0.4.5
langsmith 0.12.4 0.14.4
librt 0.15.0 0.16.0
mcp 2.2.0 2.3.0
mcp-types 2.2.0 2.3.0
mypy 2.3.1 2.4.0
openai 3.13.0 3.24.0
openai-agents 0.22.2 0.23.1
opentelemetry-api 1.44.0 1.45.0
opentelemetry-exporter-otlp-proto-common 1.44.0 1.45.0
opentelemetry-exporter-otlp-proto-http 1.44.0 1.45.0
opentelemetry-proto 1.44.0 1.45.0
opentelemetry-sdk 1.44.0 1.45.0
opentelemetry-semantic-conventions 0.65b0 0.66b0
protobuf 7.36.1 7.36.2
pydantic-core 2.46.5 2.49.0
pyjwt 2.14.0 2.15.1
regex 2026.9.10 2026.9.29
rpds-py 2026.6.3 2026.9.1
ruff 0.16.7 0.16.10
sse-starlette 3.4.11 3.5.0
starlette 1.6.0 1.7.0
uuid-utils 0.17.1 1.0.0
uvicorn 0.53.0 0.54.0
websockets 16.1.1 17.2
chardet 5.2.0 7.6.0
cyclonedx-bom 7.3.1 7.5.0
fqdn 1.5.1 1.6.0
pyparsing 3.3.2 3.3.3
tzdata 2026.4 2026.5
psycopg 3.3.5 3.3.6

Updates charset-normalizer from 3.5.1 to 3.5.2

Release notes

Sourced from charset-normalizer's releases.

Version 3.5.2

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Changelog

Sourced from charset-normalizer's changelog.

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Commits
  • 935c29a Release 3.5.2 (#805)
  • 9d3238a test: disable traefik in downstream niquests
  • b4c0368 docs: write changelog entry for 3.5.2
  • 717da31 chore: bump version to 3.5.2
  • 264895d chore: update pypa/cibuildwheel and pypa/gh-action-pypi-publish
  • 41e28b6 chore: raise Cython upper bound to 3.3
  • b130b7d Fix valid UTF-8 Chinese JSON misdetected as PTCP154 (#796)
  • f6afd31 Make the IANA_NO_ALIASES encodings resolvable by name (#800)
  • See full diff in compare view

Updates cryptography from 50.0.1 to 50.0.2

Changelog

Sourced from cryptography's changelog.

50.0.2 - 2026-09-30


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.3.
* Added ``abi3.abi3t`` wheels for free-threaded CPython 3.15 and later.
* Updated to PyO3 0.29.2, which fixes building ``cryptography`` on Cygwin and
  MSYS2.

.. _v50-0-1:

Commits

Updates idna from 3.19 to 3.20

Release notes

Sourced from idna's releases.

v3.20

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Changelog

Sourced from idna's changelog.

3.20 (2026-09-17)

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Commits
  • d55e65e Release 3.20
  • 0c0824a Pre-release 3.20rc0
  • bd7c316 Note Python 3.15 support in the 3.20 changelog
  • b6cce85 Merge pull request #276 from kjd/unicode-18
  • 9a4bc59 Update to Unicode 18.0.0
  • dfab5a0 Merge branch 'python-3.15'
  • 417c354 Read the latest Unicode version from the DerivedAge.txt header instead of the...
  • cd17392 Merge pull request #274 from kjd/fix-decode-length-check
  • c5796d7 Skip the decode round-trip check for domains past encode's length limit
  • d6ee690 Update to Python 3.15 release candidate in CI and add trove classifier
  • Additional commits viewable in compare view

Updates pyproject-hooks from 1.2.0 to 1.3.3

Changelog

Sourced from pyproject-hooks's changelog.

v1.3.3

  • No code changes from 1.3. The git tags and the version number got out of sync while fixing an issue with the Github actions workflow to publish the release. 1.3.3 exists only to get them back in sync without reassigning any tags.

v1.3

  • Python 3.8 or above is now required (:pr:214).
  • UserWarnings from the backend are now captured and re-emitted in the frontend process as a new category BuildBackendWarning, so that frontends can control how they are shown to users (:pr:213).
  • Show the traceback from the backend on a BackendUnavailable error (:pr:219).
  • Fix the return type annotation for prepare_metadata_for_build_wheel (:pr:209).
  • Fix removing the internal _in_process directory from sys.path where the install location includes a symlink (:pr:230).
  • Use os.path.commonpath instead of the deprecated commonprefix to validate the location of in-tree backends.
  • Fix in-tree backends in locations containing the path separator character - : on Posix platforms, ; on Windows (:pr:232).
  • Fix finding distribution metadata with importlib.metadata in the backend when an in-tree backend is used (:pr:212).
  • pyproject_hooks can be built from source using flit_core 4.x (:pr:233).
  • Document that the hooks.subprocess_runner context manager API is not thread-safe (:pr:227`)

v1.2

  • Improve interoperability with importlib.metadata, fixing a regression in setuptools compatibility in 1.1 (PR :pr:199).
  • Clean up the _in_process directory inside the package from sys.path before imporing the backend (PR :pr:193).

v1.1

  • Add type annotations to the public API.
  • More careful handling of the backend-path key from pyproject.toml. Previous versions would load the backend and then check that it was loaded from the specified path; the new version only loads it from the specified path. The BackendInvalid exception is now a synonym for :exc:BackendUnavailable, and code should move to using the latter name.

v1.0

... (truncated)

Commits
  • 184c9f5 Merge pull request #239 from pypa/1.3.3
  • a7c2c18 Describe why 1.3.3 in changelog
  • 8cc3947 Update version to 1.3.3
  • 6b92c2b Merge pull request #238 from pypa/gh-action-fix-publish
  • 1b1013d Fix reference to pypi publish action
  • 32cad4e Merge pull request #237 from pypa/update-gh-action-shas
  • 514a241 Latest action versions for lint job as well
  • 91c12fa Add dependabot config to update Github actions automatically
  • 271cf6c Update Github action SHAs to current versions
  • 3f24f34 Merge pull request #235 from pypa/changelog-1.3
  • Additional commits viewable in compare view

Updates urllib3 from 2.7.0 to 2.8.0

Release notes

Sourced from urllib3's releases.

2.8.0

🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)

[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. (#5044)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). (#4945)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). (#5092)

Bugfixes

  • Fixed response header handling to replace obsolete folded header lines (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as Set-Cookie. (#1362)

  • Fixed usage of proxy_ssl_context with ProxyManager when use_forwarding_for_https=True. Passing ssl_context instead of proxy_ssl_context for HTTPS proxies in this configuration now emits a FutureWarning and will raise an error in v3.0. (#2577)

  • Changed behavior of the default ConnectionPool.pool initialization. LifoQueue is now resolved from the queue module after the ConnectionPool is instantiated instead of using the default cached QueueCls class property. This is done because sometimes the queue.LifoQueue is monkey-patched late in the program, such as by gevent. (#3289)

  • Raised UnrewindableBodyError instead of ValueError when retrying a request whose body had tell() but not seek(). (#3779)

  • Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (#3785)

  • Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB chunks (same as the default amt when doing HTTPResponse.stream(...)). (#5019)

  • Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and decimal integers (2130706433), ensuring SSL certificate verification uses the correct mode for these addresses. (#5029)

  • Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError instead of ValueError when called with an invalid timeout argument on a pool created with block=True. (#5059)

  • Fixed port-zero handling to preserve explicit :0 values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, connection_from_url(), and HTTP/2 request authority. (#5071, #5101)

  • Fixed a bug where PoolManager passed the assert_hostname and assert_fingerprint parameters to HTTP connection pools. (#5077)

  • Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (#5079)

  • Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (#5091)

  • Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.

    HTTPSConnection no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its ssl_context as a fallback when an HTTPS proxy forwards an HTTP target. (#5093)

  • Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (#5095)

... (truncated)

Changelog

Sourced from urllib3's changelog.

2.8.0 (2026-09-15)

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)

.. caution::

urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. ([#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044>__)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). ([#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945>__)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). ([#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092>__)

Bugfixes

... (truncated)

Commits
  • b1d30ab Release 2.8.0
  • 9016d7e Skip test_read_chunked_with_trailing_data_does_not_hang for brotlicffi (#5258)
  • 9101f58 Fix nox -s docs warning (#5256)
  • cd770b0 Merge commit from fork
  • ea2ad7b Merge commit from fork
  • 0716e31 Fix loading unencrypted client keys with a password in pyOpenSSL (#5255)
  • 43c68c8 Test pickling of InvalidChunkLength (#5247)
  • 308b279 Share security policy between GitHub and Read the Docs (#5253)
  • 53fa073 Add policy on duplicate pull requests (#5252)
  • 5f2a6a8 Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (#5232)
  • Additional commits viewable in compare view

Updates ast-serialize from 0.11.2 to 0.12.1

Commits

Updates coverage from 7.16.1 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Commits

Updates googleapis-common-protos from 1.75.3 to 1.75.5

Release notes

Sourced from googleapis-common-protos's releases.

google-cloud-compute-v1beta: v0.12.8

0.12.8 (2026-10-08)

Features

Commits
  • d6bed5a chore: release main (#18464)
  • 78ff458 feat(gapic-generator): add schema support for resumable uploads (#18480)
  • af2100a tests: add showcase to golden files (#18479)
  • e1d306a fix: resolve error where google/longrunning/operations.proto is missing (#18477)
  • 7871fa9 fix(gapic-generator): init mock response in version header test (#18488)
  • 0b488a3 feat(bigtable): Reroute Mutations Batcher to use data client (#18200)
  • 30b4f44 fix(google-auth-oauthlib): prevent ipv6 address reuse (#18463)
  • 1d9f468 chore(main): release google-auth 2.59.0 (#18465)
  • c7c133a chore(bigtable): Added an internal batch completed callback to the data clien...
  • 8cb3c6a perf(spanner): optimize query option merging and prevent in-place mutation (#...
  • Additional commits viewable in compare view

Updates httpcore2 from 2.13.0 to 2.13.1

Release notes

Sourced from httpcore2's releases.

v2.13.1

Highlights

📤 Accurate file upload lengths

Passing a file as content= now calculates Content-Length from its remaining bytes, respecting the current file position (#1214).

🔐 Reliable proxy TLS and HTTP/2 negotiation

TLS hostname overrides now apply inside HTTP proxy tunnels without affecting the proxy's own TLS connection (#1223). HTTP/2 is advertised first when enabled, and HTTP/1.1 is omitted when disabled (#1155).

🧹 Clean WebSocket shutdown

The sync WebSocket keepalive thread now exits cleanly when a ping races with connection shutdown (#1228).

httpx2

Fixed

  • Calculate Content-Length from the remaining bytes when a file is passed as content=, respecting its current position (#1214).
  • Stop the sync WebSocket keepalive thread cleanly when a ping races with connection shutdown (#1228).

httpcore2

Fixed

  • Honor the sni_hostname extension for TLS inside HTTP proxy tunnels without applying it to the proxy's TLS connection (#1223).
  • Prefer HTTP/2 during TLS protocol negotiation when enabled, and stop advertising HTTP/1.1 when it is disabled (#1155).

Full Changelog: pydantic/httpx2@v2.13.0...v2.13.1

Commits

Updates httpx2 from 2.13.0 to 2.13.1

Release notes

Sourced from httpx2's releases.

v2.13.1

Highlights

📤 Accurate file upload lengths

Passing a file as content= now calculates Content-Length from its remaining bytes, respecting the current file position (#1214).

🔐 Reliable proxy TLS and HTTP/2 negotiation

TLS hostname overrides now apply inside HTTP proxy tunnels without affecting the proxy's own TLS connection (#1223). HTTP/2 is advertised first when enabled, and HTTP/1.1 is omitted when disabled (#1155).

🧹 Clean WebSocket shutdown

The sync WebSocket keepalive thread now exits cleanly when a ping races with connection shutdown (#1228).

httpx2

Fixed

  • Calculate Content-Length from the remaining bytes when a file is passed as content=, respecting its current position (#1214).
  • Stop the sync WebSocket keepalive thread cleanly when a ping races with connection shutdown (#1228).

httpcore2

Fixed

  • Honor the sni_hostname extension for TLS inside HTTP proxy tunnels without applying it to the proxy's TLS connection (#1223).
  • Prefer HTTP/2 during TLS protocol negotiation when enabled, and stop advertising HTTP/1.1 when it is disabled (#1155).

Full Changelog: pydantic/httpx2@v2.13.0...v2.13.1

Changelog

Sourced from httpx2's changelog.

2.13.1 (September 23rd, 2026)

Fixed

  • Calculate Content-Length from the remaining bytes when a file is passed as content=, respecting its current position. (#1214)
  • Stop the sync WebSocket keepalive thread cleanly when a ping races with connection shutdown. (#1228)
Commits

Updates hypothesis from 6.168.0 to 6.168.4

Commits
  • d862501 Bump hypothesis version to 6.168.4 and update changelog
  • de4ec1c Merge pull request #4887 from HypothesisWorks/create-pull-request/patch
  • 8a80889 add pypy312 support
  • 9ee265d Update pinned dependencies
  • 44b82b2 Bump hypothesis version to 6.168.3 and update changelog
  • aeaafb5 Merge pull request #4888 from gpacix/fix-quadratic-statistics
  • f3f4a29 wording, remove hardcoded test
  • 7fabb94 Add RELEASE.rst and AUTHORS.rst changes
  • 0ab4e38 Summarize statistics events in linear time
  • 32ebeb2 Bump hypothesis version to 6.168.2 and update changelog
  • Additional commits viewable in compare view

Updates langchain from 1.4.0 to 1.4.3

Release notes

Sourced from langchain's releases.

langchain-fireworks==1.4.3

Changes since langchain-fireworks==1.4.2

release(fireworks): 1.4.3 chore: bump vcrpy from 8.1.1 to 8.2.1 in /libs/partners/fireworks (#38314) chore: bump langsmith from 0.8.16 to 0.8.18 in /libs/partners/fireworks (#38313) chore: bump langsmith from 0.8.14 to 0.8.16 in /libs/partners/fireworks (#38235) chore: bump pytest from 9.0.3 to 9.1.0 in /libs/partners/fireworks (#38233) chore(model-profiles): refresh model profile data (#38210) chore(model-profiles): refresh model profile data (#38191) chore(model-profiles): refresh model profile data (#38133) docs: refresh README installation and resources (#38119) release(core): 1.4.7 (#38111) fix(core,partners): rename package version trace metadata (#38110) style(core,langchain,langchain-classic,partners): replace double backticks in docstrings (#38095) chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/fireworks (#38093) release(core): 1.4.6 (#38061) feat(core,partners): add package version tracking to tracing metadata (#35295) chore(infra): bump mypy to 2.1 and unify type-check config across the monorepo (#36470) feat(standard-tests): validate tool call chunks during streaming (#34707) chore(partners): bump locks (#38052) hotfix(openai): min core dep (#37990) chore(model-profiles): refresh model profile data (#37973) chore(model-profiles): refresh model profile data (#37936) test(langchain,partners): disable pytest-benchmark under xdist to silence PytestBenchmarkWarning (#37901) fix(partners): cap aiohttp below 3.14 for vcrpy compat (#37898) chore(model-profiles): refresh model profile data (#37895) chore: bump aiohttp from 3.13.5 to 3.14.0 in /libs/partners/fireworks (#37882) chore: bump langsmith from 0.8.7 to 0.8.9 in /libs/partners/fireworks (#37883) chore: bump langsmith from 0.8.0 to 0.8.7 in /libs/partners/fireworks (#37781) chore: bump requests from 2.34.0 to 2.34.2 in /libs/partners/fireworks (#37782)

langchain-openai==1.4.3

Changes since langchain-openai==1.4.2

release(openai): 1.4.3 (#39485) fix(openai): filter invalid tool calls from content (#39366) chore(openai): update guidance for responses API for OpenAI-compatible providers (#39327) chore(openai): update docstring for include_response_headers (#39326)

langchain==1.4.3

Changes since langchain==1.4.2

release(langchain): 1.4.3 (#40888) fix(langchain): sanitize cache settings for fallback models (#40886) feat(langchain): support Bedrock Mantle chat models in init_chat_model (#40837) fix(langchain): recognize GPT-6 structured output without profiles (#40844) docs(infra): fix AGENTS.md root setup guidance and package doc accuracy (#40794) fix(langchain): repair invalid tool calls in create_agent (#40530) chore(langchain): remove commented-out cohere extra (#40713)

... (truncated)

Commits
  • be854a1 release(langchain): 1.4.3 (#40888)
  • 2ade674 fix(langchain): sanitize cache settings for fallback models (#40886)
  • 88b9727 feat(fireworks): add prompt caching middleware (#38823)
  • 60e57f5 fix(fireworks): classify mid-stream read timeouts (#40874)
  • 42f04f4 docs: update OpenWiki (#40781)
  • 213f230 chore(model-profiles): refresh model profile data (#40869)
  • d750819 chore(model-profiles): refresh model profile data (#40833)
  • 1ef23d6 fix(anthropic): serialize invalid tool calls as tool use on replay (#40864)
  • 80b7409 feat(langchain): support Bedrock Mantle chat models in init_chat_model (#40...
  • 40fe8d6 docs(core): fix docstring examples that don't run as copied (#40815)
  • Additional commits viewable in compare view

Updates langchain-core from 1.6.3 to 1.6.6

Release notes

Sourced from langchain-core's releases.

langchain-core==1.6.6

Changes since langchain-core==1.6.5

release(core): 1.6.6 (#40906) fix(anthropic): support Claude Sonnet 5.5 compatibility (#40882) docs(core): fix docstring examples that don't run as copied (#40815)

langchain-core==1.6.5

Changes since langchain-core==1.6.4

release(core): 1.6.5 (#40816) fix(core): abbreviate long tool IDs in XML buffer strings (#40792)

langchain-core==1.6.4

Changes since langchain-core==1.6.3

release(core): 1.6.4 (#40718) chore(core): deprecate chat message history (#40711) chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (#40634) chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (#40574)

Commits

Updates langchain-openai from 1.6.2 to 1.6.7

Release notes

Sourced from langchain-openai's releases.

langchain-openai==1.6.7

Changes since langchain-openai==1.6.6

release(openai): 1.6.7 (#40933) chore(model-profiles): refresh model profile data (#40924) test(openai): drop retired completions live tests (#40910) chore(model-profiles): refresh model profile data (#40869) feat(openai): discover Azure workload identity (#40532)

langchain-openai==1.6.6

Changes since langchain-openai==1.6.5

release(openai): 1.6.6 (#40800) fix(openai): raise on error events in stream path (

Bumps the locks group with 46 updates in the /requirements directory:

| Package | From | To |
| --- | --- | --- |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.5.1` | `3.5.2` |
| [cryptography](https://github.com/pyca/cryptography) | `50.0.1` | `50.0.2` |
| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |
| [pyproject-hooks](https://github.com/pypa/pyproject-hooks) | `1.2.0` | `1.3.3` |
| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |
| [ast-serialize](https://github.com/mypyc/ast_serialize) | `0.11.2` | `0.12.1` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.16.1` | `7.16.2` |
| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.75.3` | `1.75.5` |
| [httpcore2](https://github.com/pydantic/httpx2) | `2.13.0` | `2.13.1` |
| [httpx2](https://github.com/pydantic/httpx2) | `2.13.0` | `2.13.1` |
| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.168.0` | `6.168.4` |
| [langchain](https://github.com/langchain-ai/langchain) | `1.4.0` | `1.4.3` |
| [langchain-core](https://github.com/langchain-ai/langchain) | `1.6.3` | `1.6.6` |
| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.6.2` | `1.6.7` |
| [langgraph](https://github.com/langchain-ai/langgraph) | `1.2.11` | `1.2.12` |
| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.4.4` | `0.4.5` |
| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.12.4` | `0.14.4` |
| [librt](https://github.com/mypyc/librt) | `0.15.0` | `0.16.0` |
| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `2.2.0` | `2.3.0` |
| [mcp-types](https://github.com/modelcontextprotocol/python-sdk) | `2.2.0` | `2.3.0` |
| [mypy](https://github.com/python/mypy) | `2.3.1` | `2.4.0` |
| [openai](https://github.com/openai/openai-python) | `3.13.0` | `3.24.0` |
| [openai-agents](https://github.com/openai/openai-agents-python) | `0.22.2` | `0.23.1` |
| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [opentelemetry-exporter-otlp-proto-common](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.65b0` | `0.66b0` |
| [protobuf](https://developers.google.com/protocol-buffers/) | `7.36.1` | `7.36.2` |
| [pydantic-core](https://github.com/pydantic/pydantic) | `2.46.5` | `2.49.0` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.14.0` | `2.15.1` |
| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.9.10` | `2026.9.29` |
| [rpds-py](https://github.com/crate-py/rpds) | `2026.6.3` | `2026.9.1` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.7` | `0.16.10` |
| [sse-starlette](https://github.com/sysid/sse-starlette) | `3.4.11` | `3.5.0` |
| [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` |
| [uuid-utils](https://github.com/aminalaee/uuid-utils) | `0.17.1` | `1.0.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.53.0` | `0.54.0` |
| [websockets](https://github.com/python-websockets/websockets) | `16.1.1` | `17.2` |
| [chardet](https://github.com/chardet/chardet) | `5.2.0` | `7.6.0` |
| [cyclonedx-bom](https://github.com/CycloneDX/cyclonedx-python) | `7.3.1` | `7.5.0` |
| [fqdn](https://github.com/ypcrts/fqdn) | `1.5.1` | `1.6.0` |
| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.3.2` | `3.3.3` |
| [tzdata](https://github.com/python/tzdata) | `2026.4` | `2026.5` |
| [psycopg](https://github.com/psycopg/psycopg) | `3.3.5` | `3.3.6` |



Updates `charset-normalizer` from 3.5.1 to 3.5.2
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](jawah/charset_normalizer@3.5.1...3.5.2)

Updates `cryptography` from 50.0.1 to 50.0.2
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@50.0.1...50.0.2)

Updates `idna` from 3.19 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.19...v3.20)

Updates `pyproject-hooks` from 1.2.0 to 1.3.3
- [Changelog](https://github.com/pypa/pyproject-hooks/blob/main/docs/changelog.rst)
- [Commits](pypa/pyproject-hooks@v1.2.0...v1.3.3)

Updates `urllib3` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

Updates `ast-serialize` from 0.11.2 to 0.12.1
- [Commits](mypyc/ast_serialize@v0.11.2...v0.12.1)

Updates `coverage` from 7.16.1 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.1...7.16.2)

Updates `googleapis-common-protos` from 1.75.3 to 1.75.5
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](googleapis/google-cloud-python@googleapis-common-protos-v1.75.3...googleapis-common-protos-v1.75.5)

Updates `httpcore2` from 2.13.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Commits](pydantic/httpx2@v2.13.0...v2.13.1)

Updates `httpx2` from 2.13.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](pydantic/httpx2@v2.13.0...v2.13.1)

Updates `hypothesis` from 6.168.0 to 6.168.4
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.168.0...v6.168.4)

Updates `langchain` from 1.4.0 to 1.4.3
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain==1.4.0...langchain==1.4.3)

Updates `langchain-core` from 1.6.3 to 1.6.6
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-core==1.6.3...langchain-core==1.6.6)

Updates `langchain-openai` from 1.6.2 to 1.6.7
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-openai==1.6.2...langchain-openai==1.6.7)

Updates `langgraph` from 1.2.11 to 1.2.12
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](langchain-ai/langgraph@1.2.11...1.2.12)

Updates `langgraph-sdk` from 0.4.4 to 0.4.5
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](langchain-ai/langgraph@0.4.4...0.4.5)

Updates `langsmith` from 0.12.4 to 0.14.4
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases)
- [Commits](langchain-ai/langsmith-sdk@v0.12.4...v0.14.4)

Updates `librt` from 0.15.0 to 0.16.0
- [Commits](mypyc/librt@v0.15.0...v0.16.0)

Updates `mcp` from 2.2.0 to 2.3.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v2.2.0...v2.3.0)

Updates `mcp-types` from 2.2.0 to 2.3.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v2.2.0...v2.3.0)

Updates `mypy` from 2.3.1 to 2.4.0
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v2.3.1...v2.4.0)

Updates `openai` from 3.13.0 to 3.24.0
- [Release notes](https://github.com/openai/openai-python/releases)
- [Changelog](https://github.com/openai/openai-python/blob/main/CHANGELOG.md)
- [Commits](openai/openai-python@v3.13.0...v3.24.0)

Updates `openai-agents` from 0.22.2 to 0.23.1
- [Release notes](https://github.com/openai/openai-agents-python/releases)
- [Changelog](https://github.com/openai/openai-agents-python/blob/main/CHANGELOG.md)
- [Commits](openai/openai-agents-python@v0.22.2...v0.23.1)

Updates `opentelemetry-api` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-exporter-otlp-proto-common` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-exporter-otlp-proto-http` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-proto` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-sdk` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `opentelemetry-semantic-conventions` from 0.65b0 to 0.66b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python/commits)

Updates `protobuf` from 7.36.1 to 7.36.2

Updates `pydantic-core` from 2.46.5 to 2.49.0
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/main/HISTORY.md)
- [Commits](pydantic/pydantic@core-v2.46.5...core-v2.49.0)

Updates `pyjwt` from 2.14.0 to 2.15.1
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.14.0...2.15.1)

Updates `regex` from 2026.9.10 to 2026.9.29
- [Changelog](https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt)
- [Commits](mrabarnett/mrab-regex@2026.9.10...2026.9.29)

Updates `rpds-py` from 2026.6.3 to 2026.9.1
- [Release notes](https://github.com/crate-py/rpds/releases)
- [Changelog](https://github.com/crate-py/rpds/blob/main/release.toml)
- [Commits](crate-py/rpds@v2026.6.3...v2026.9.1)

Updates `ruff` from 0.16.7 to 0.16.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.7...0.16.10)

Updates `sse-starlette` from 3.4.11 to 3.5.0
- [Release notes](https://github.com/sysid/sse-starlette/releases)
- [Commits](sysid/sse-starlette@v3.4.11...v3.5.0)

Updates `starlette` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.6.0...1.7.0)

Updates `uuid-utils` from 0.17.1 to 1.0.0
- [Release notes](https://github.com/aminalaee/uuid-utils/releases)
- [Commits](aminalaee/uuid-utils@0.17.1...1.0.0)

Updates `uvicorn` from 0.53.0 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.53.0...0.54.0)

Updates `websockets` from 16.1.1 to 17.2
- [Release notes](https://github.com/python-websockets/websockets/releases)
- [Commits](python-websockets/websockets@16.1.1...17.2)

Updates `chardet` from 5.2.0 to 7.6.0
- [Release notes](https://github.com/chardet/chardet/releases)
- [Changelog](https://github.com/chardet/chardet/blob/main/docs/changelog.rst)
- [Commits](chardet/chardet@5.2.0...7.6.0)

Updates `cyclonedx-bom` from 7.3.1 to 7.5.0
- [Release notes](https://github.com/CycloneDX/cyclonedx-python/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-python/blob/main/CHANGELOG.md)
- [Commits](CycloneDX/cyclonedx-python@v7.3.1...v7.5.0)

Updates `fqdn` from 1.5.1 to 1.6.0
- [Release notes](https://github.com/ypcrts/fqdn/releases)
- [Changelog](https://github.com/ypcrts/fqdn/blob/develop/CHANGELOG.md)
- [Commits](ypcrts/fqdn@v1.5.1...v1.6.0)

Updates `pyparsing` from 3.3.2 to 3.3.3
- [Release notes](https://github.com/pyparsing/pyparsing/releases)
- [Changelog](https://github.com/pyparsing/pyparsing/blob/master/CHANGES)
- [Commits](pyparsing/pyparsing@3.3.2...3.3.3)

Updates `tzdata` from 2026.4 to 2026.5
- [Release notes](https://github.com/python/tzdata/releases)
- [Changelog](https://github.com/python/tzdata/blob/master/NEWS.md)
- [Commits](python/tzdata@2026.4...2026.5)

Updates `psycopg` from 3.3.5 to 3.3.6
- [Changelog](https://github.com/psycopg/psycopg/blob/master/docs/news.rst)
- [Commits](psycopg/psycopg@3.3.5...3.3.6)

---
updated-dependencies:
- dependency-name: charset-normalizer
  dependency-version: 3.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: cryptography
  dependency-version: 50.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: pyproject-hooks
  dependency-version: 1.3.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: ast-serialize
  dependency-version: 0.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: googleapis-common-protos
  dependency-version: 1.75.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: httpcore2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: httpx2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: hypothesis
  dependency-version: 6.168.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: langchain
  dependency-version: 1.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: langchain-core
  dependency-version: 1.6.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: langchain-openai
  dependency-version: 1.6.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: langgraph
  dependency-version: 1.2.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: langgraph-sdk
  dependency-version: 0.4.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: langsmith
  dependency-version: 0.14.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: librt
  dependency-version: 0.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: mcp
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: mcp-types
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: mypy
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: openai
  dependency-version: 3.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: openai-agents
  dependency-version: 0.23.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: opentelemetry-api
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: opentelemetry-exporter-otlp-proto-common
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: opentelemetry-exporter-otlp-proto-http
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: opentelemetry-proto
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: opentelemetry-sdk
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: opentelemetry-semantic-conventions
  dependency-version: 0.66b0
  dependency-type: direct:production
  dependency-group: locks
- dependency-name: protobuf
  dependency-version: 7.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: pydantic-core
  dependency-version: 2.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: pyjwt
  dependency-version: 2.15.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: regex
  dependency-version: 2026.9.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: rpds-py
  dependency-version: 2026.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: ruff
  dependency-version: 0.16.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: sse-starlette
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: uuid-utils
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: locks
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: websockets
  dependency-version: '17.2'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: locks
- dependency-name: chardet
  dependency-version: 7.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: locks
- dependency-name: cyclonedx-bom
  dependency-version: 7.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: fqdn
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: pyparsing
  dependency-version: 3.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
- dependency-name: tzdata
  dependency-version: '2026.5'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: locks
- dependency-name: psycopg
  dependency-version: 3.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: locks
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 8, 2026
@dependabot
dependabot Bot requested a review from arpanghoshal as a code owner October 8, 2026 17:33
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 8, 2026
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 224f9b33-1fd0-4e1c-b2dc-ea2a3be370bb

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants