Skip to content

chore(deps): bump the backend-dependencies group across 1 directory with 7 updates - #75

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend/backend-dependencies-712ec6bd7a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend/backend-dependencies-712ec6bd7a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the backend-dependencies group with 7 updates in the /backend directory:

Package From To
uvicorn 0.53.0 0.54.0
sqlalchemy 2.0.53 2.1.0
psycopg 3.3.5 3.3.6
pillow-heif 1.7.0 1.8.0
sentry-sdk 2.69.1 2.70.0
google-auth 2.58.0 2.58.1
ruff 0.16.7 0.16.9

Updates uvicorn from 0.53.0 to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)
Commits

Updates sqlalchemy from 2.0.53 to 2.1.0

Release notes

Sourced from sqlalchemy's releases.

2.1.0

Released: September 24, 2026

orm

  • [orm] [feature] Added _orm.composite.column_template parameter to _orm.composite(). When the composite class is a dataclass, this parameter accepts a string template such as "person_%s", containing exactly one %s placeholder, that's used to generate column names for dataclass fields that don't otherwise have an explicit name, rather than using the bare field name. This removes the need to hand-write a _orm.mapped_column() for each field when the same composite dataclass is mapped multiple times on the same class with different column-name prefixes. Pull request courtesy Leonardo Rosa.

    References: #12575

  • [orm] [bug] Fixed issue where pickling an ORM object that had an instance level lazy loader established, such as when the _orm.raiseload() option is used, would emit a spurious warning regarding the loader containing additional criteria, if the object had itself been unpickled from a previous serialization. This would occur for objects that cross more than one serialization boundary, such as when using multiprocessing.

    This change is also backported to: 2.0.53

    References: #13574

  • [orm] [bug] Fixed issue where calling _orm.aliased() against an existing _orm.aliased() construct, without passing an explicit selectable, would disregard the selectable of the existing construct and produce an alias of the mapped table instead, if that selectable were anything other than a table or a plain subquery, leading to incorrect results and/or non-working queries.

    This includes _orm.aliased() against a _orm.with_polymorphic() construct, which would previously produce an alias of the base mapped class only, discarding the polymorphic selectable and additional mappers. The new construct now retains these, so that criteria against subclass attributes and the innerjoin and selectable parameters of _orm.with_polymorphic() take effect, and subclass columns are loaded up front. The SQL rendered for these constructs now includes the polymorphic selectable.

    This change is also backported to: 2.0.53

    References: #13583, #13584

... (truncated)

Commits

Updates psycopg from 3.3.5 to 3.3.6

Changelog

Sourced from psycopg's changelog.

.. currentmodule:: psycopg

.. index:: single: Release notes single: News

psycopg release notes

Current release

Psycopg 3.3.6 ^^^^^^^^^^^^^

  • Add support for Python 3.15 (:ticket:[#1245](https://github.com/psycopg/psycopg/issues/1245)).
  • Don't wait forever for a query to terminate after interrupting it, for instance if the server is unresponsive. The fix requires libpq 17 or newer (:ticket:[#1371](https://github.com/psycopg/psycopg/issues/1371)).
  • Cancel a running query upon receiving !SystemExit (:ticket:[#1384](https://github.com/psycopg/psycopg/issues/1384)).
  • Report !None instead of 65535 as the Column.precision of an :sql:interval column declared with a fields restriction and no explicit precision, such as e.g. :sql:interval day to second (:ticket:[#1397](https://github.com/psycopg/psycopg/issues/1397)).
  • Fix dumping of nested subclasses of lists as arrays (:ticket:[#1398](https://github.com/psycopg/psycopg/issues/1398)).
  • Discard prepared statements upon :sql:DEALLOCATE ALL (:ticket:[#1408](https://github.com/psycopg/psycopg/issues/1408)).
  • Better guards dumping large Python !int to binary numeric (:ticket:[#1414](https://github.com/psycopg/psycopg/issues/1414)).
  • Improve performance of async queries by reducing the overhead of the !wait_async() function (:ticket:[#1331](https://github.com/psycopg/psycopg/issues/1331)).

Psycopg 3.3.5 ^^^^^^^^^^^^^

  • Discard prepared statements upon :sql:ALTER * or DISCARD * (:ticket:[#1307](https://github.com/psycopg/psycopg/issues/1307)).
  • Fix !ProgrammingError when dumping non-!None values with no !NoneType dumper registered in python implementation (:ticket:[#1325](https://github.com/psycopg/psycopg/issues/1325)).
  • Fix !wait_selector wait function to not raise !KeyError (:ticket:[#1327](https://github.com/psycopg/psycopg/issues/1327)).
  • Fix !DataError messages leaking the literal {...} placeholder instead of the offending value when loading a pre-year-1 :sql:timestamp or a malformed binary :sql:jsonb value (:ticket:[#1372](https://github.com/psycopg/psycopg/issues/1372)).
  • Raise !DataError instead of !ValueError when ~psycopg.rows.namedtuple_row receives duplicate column names (:ticket:[#1348](https://github.com/psycopg/psycopg/issues/1348)).
  • Raise !DataError on inconsistent copy data (:tickets:[#1359](https://github.com/psycopg/psycopg/issues/1359), [#1360](https://github.com/psycopg/psycopg/issues/1360)).
  • Handle client encodings aliases (:ticket:[#1363](https://github.com/psycopg/psycopg/issues/1363)).
  • Fix building C extension with Cython 3.3.

Psycopg 3.3.4

... (truncated)

Commits
  • a67654d chore: bump psycopg package version to 3.3.6
  • 443814b Merge pull request #1416 from dvarrazzo/wait-async-perf
  • 42966e9 test: add helpful comments to some tests
  • 5e8797f test: add reasonable connect_timeout to most tests
  • c81ba62 perf: reduce the overhead of wait_async()
  • d2bbfe4 refactor: use get_running_loop() in the async wait functions
  • 2b1484a test: add a script to measure the async wait functions
  • 573cf4a test: fix incorrect wait timing test
  • 2b68990 refactor: drop leftovers of waiting with inf interval in wait_conn_async
  • 60765dd Merge pull request #1414 from dvarrazzo/fix-decimal-overflow
  • Additional commits viewable in compare view

Updates pillow-heif from 1.7.0 to 1.8.0

Release notes

Sourced from pillow-heif's releases.

v1.8.0

Added

  • Reading of entity groups: entity_groups key in info dictionary, tells which images form a stereo pair in spatial photos. #476
  • Decoding of embedded thumbnails: HeifImage.get_thumbnail method and draft in the Pillow plugin, Image.thumbnail() uses them instead of decoding the full image. #477

Changed

  • Minimum required libheif version is 1.23.4. #480
  • libheif was updated from the 1.23.3 to 1.23.4 version. #479
  • libde265 was updated from the 1.1.2 to 1.1.3 version. #483

Fixed

  • Segmentation fault when opening a file whose metadata item type is not valid UTF-8. #478
  • Pillow plugin: load() of a multi-frame image reloaded the frame data on every call, discarding in-place changes and failing after thumbnail(). #477
  • A depth image of an item type that libheif cannot decode made the whole file unreadable with libheif 1.23.4, such depth images are now skipped. #480
  • Type checkers treated the names imported from pillow_heif as private since the py.typed marker was added in 1.7.0: Pyright/Pylance and mypy --strict reported them as not exported, Pyright/Pylance autocompletion did not offer them. #490 Thanks to @​BetoFernandez123
Changelog

Sourced from pillow-heif's changelog.

[1.8.0 - 2026-09-22]

Added

  • Reading of entity groups: entity_groups key in info dictionary, tells which images form a stereo pair in spatial photos. #476
  • Decoding of embedded thumbnails: HeifImage.get_thumbnail method and draft in the Pillow plugin, Image.thumbnail() uses them instead of decoding the full image. #477

Changed

  • Minimum required libheif version is 1.23.4. #480
  • libheif was updated from the 1.23.3 to 1.23.4 version. #479
  • libde265 was updated from the 1.1.2 to 1.1.3 version. #483

Fixed

  • Segmentation fault when opening a file whose metadata item type is not valid UTF-8. #478
  • Pillow plugin: load() of a multi-frame image reloaded the frame data on every call, discarding in-place changes and failing after thumbnail(). #477
  • A depth image of an item type that libheif cannot decode made the whole file unreadable with libheif 1.23.4, such depth images are now skipped. #480
  • Type checkers treated the names imported from pillow_heif as private since the py.typed marker was added in 1.7.0: Pyright/Pylance and mypy --strict reported them as not exported, Pyright/Pylance autocompletion did not offer them. #490 Thanks to @​BetoFernandez123
Commits
  • 1486e9f v1.8.0
  • 1ffdd5d fix: names imported from pillow_heif were private for type checkers (#490)
  • c775daf [pre-commit.ci] pre-commit autoupdate (#484)
  • 8f2c0f6 fix(tests): Pillow 13 resize order changes one hash bit (#489)
  • abcfd35 chore(deps): update dependency strukturag/libde265 to v1.1.3 (#483)
  • fa18f51 fix: a depth image of an unsupported item type made the file unreadable (#480)
  • efdbf03 [pre-commit.ci] pre-commit autoupdate (#481)
  • 07f7203 feat: decode embedded thumbnails, draft() in the Pillow plugin (#477)
  • d60dcd2 chore(deps): update dependency strukturag/libheif to v1.23.4 (#479)
  • 07334a0 fix: segfault on a metadata item type that is not valid UTF-8 (#478)
  • Additional commits viewable in compare view

Updates sentry-sdk from 2.69.1 to 2.70.0

Release notes

Sourced from sentry-sdk's releases.

2.70.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.mistral import MistralIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
MistralIntegration(),
]
)

import sentry_sdk
sentry_sdk.init(
data_collection={
"user_info": False,
"gen_ai": {"inputs": False, "outputs": False},
"graphql": {"document": False, "variables": False},
"database_query_data": False,
"queues": False,
"http_bodies": [],
"cookies": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
"http_headers": {
"request": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
},
</tr></table>

... (truncated)

Changelog

Sourced from sentry-sdk's changelog.

2.70.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.mistral import MistralIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
MistralIntegration(),
]
)

import sentry_sdk
sentry_sdk.init(
data_collection={
"user_info": False,
"gen_ai": {"inputs": False, "outputs": False},
"graphql": {"document": False, "variables": False},
"database_query_data": False,
"queues": False,
"http_bodies": [],
"cookies": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
"http_headers": {
"request": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
</tr></table>

... (truncated)

Commits
  • 1eb7df5 Update CHANGELOG.md
  • 92fd42b release: 2.70.0
  • d99edef ref(data-collection): Promote data_collection from _experiments o top-lev...
  • 045d2c1 test: Close client on teardown (#7562)
  • b454d7d feat(mistral): Record gen_ai.output.messages (#7549)
  • bdfd68c feat(mistral): Record gen_ai.input.messages (#7548)
  • ea08f64 feat(mistral): Record gen_ai.system_instructions (#7547)
  • dbddd0e feat(mistral): Record request parameters (#7531)
  • 9342968 feat(mistral): Record token usage (#7529)
  • 988fd0e feat(mistral): Add integration with Chat.complete and Chat.complete_async...
  • Additional commits viewable in compare view

Updates google-auth from 2.58.0 to 2.58.1

Release notes

Sourced from google-auth's releases.

google-auth: v2.58.1

2.58.1 (2026-09-24)

Bug Fixes

  • auth: allow mTLS retry when credentials raise NotImplementedError on refresh (#18349) (1665e68)
Commits
  • e654dc2 chore(main): release google-auth 2.58.1 (#18462)
  • 1665e68 fix(auth): allow mTLS retry when credentials raise NotImplementedError on ref...
  • 89310be chore(main): release google-crc32c 1.9.0 (#18459)
  • 9cb21d0 fix: regenerate gencode with protobuf 6.33.5 (#18461)
  • 54f1019 feat: update API sources and regenerate (#18446)
  • a04c831 feat(firestore): add BSONDecimal128 support (#18395)
  • 1bf979a fix(crc32c): remove stale pypy reference from README (#18458)
  • fdaa618 chore(crc32c): run manylinux wheel validation and upload in isolated Python 3...
  • 5fe1ef3 feat: add 3.15 support to gapic library classifiers (#18450)
  • 322c9bc feat(firestore): add BSONRegex support (#18394)
  • Additional commits viewable in compare view

Updates ruff from 0.16.7 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ith 7 updates

Bumps the backend-dependencies group with 7 updates in the /backend directory:

| Package | From | To |
| --- | --- | --- |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.53.0` | `0.54.0` |
| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.53` | `2.1.0` |
| [psycopg](https://github.com/psycopg/psycopg) | `3.3.5` | `3.3.6` |
| [pillow-heif](https://github.com/bigcat88/pillow_heif) | `1.7.0` | `1.8.0` |
| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.69.1` | `2.70.0` |
| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.58.0` | `2.58.1` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.7` | `0.16.9` |



Updates `uvicorn` from 0.53.0 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.53.0...0.54.0)

Updates `sqlalchemy` from 2.0.53 to 2.1.0
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

Updates `psycopg` from 3.3.5 to 3.3.6
- [Changelog](https://github.com/psycopg/psycopg/blob/master/docs/news.rst)
- [Commits](psycopg/psycopg@3.3.5...3.3.6)

Updates `pillow-heif` from 1.7.0 to 1.8.0
- [Release notes](https://github.com/bigcat88/pillow_heif/releases)
- [Changelog](https://github.com/bigcat88/pillow_heif/blob/master/CHANGELOG.md)
- [Commits](bigcat88/pillow_heif@v1.7.0...v1.8.0)

Updates `sentry-sdk` from 2.69.1 to 2.70.0
- [Release notes](https://github.com/getsentry/sentry-python/releases)
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-python@2.69.1...2.70.0)

Updates `google-auth` from 2.58.0 to 2.58.1
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](googleapis/google-cloud-python@google-auth-v2.58.0...google-auth-v2.58.1)

Updates `ruff` from 0.16.7 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.7...0.16.9)

---
updated-dependencies:
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-dependencies
- dependency-name: sqlalchemy
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-dependencies
- dependency-name: psycopg
  dependency-version: 3.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-dependencies
- dependency-name: pillow-heif
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-dependencies
- dependency-name: sentry-sdk
  dependency-version: 2.70.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-dependencies
- dependency-name: google-auth
  dependency-version: 2.58.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-dependencies
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: backend-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants