Skip to content

build(deps): bump the backend-deps group in /backend with 12 updates - #51

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend/backend-deps-83ff511091
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend/backend-deps-83ff511091

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the backend-deps group in /backend with 12 updates:

Package From To
fastapi 0.141.1 0.142.2
uvicorn 0.53.0 0.54.0
sqlalchemy 2.0.54 2.1.3
sse-starlette 3.4.11 3.5.0
charset-normalizer 3.5.1 3.5.2
markdown 3.10.3 3.11
pydantic-core 2.46.5 2.49.0
python-dotenv 1.2.3 1.2.4
soupsieve 2.9.2 2.10
starlette 1.6.0 1.7.0
tzdata 2026.4 2026.5
wrapt 2.4.1 2.5.0

Updates fastapi from 0.141.1 to 0.142.2

Release notes

Sourced from fastapi's releases.

0.142.2

Fixes

  • 🐛 Allow startup when automatic OpenTelemetry configuration fails. PR #16418 by @​tiangolo.

0.142.1

Fixes

0.142.0

Features

Refactors

Docs

Translations

Internal

... (truncated)

Commits

Updates uvicorn from 0.53.0 to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)
Commits

Updates sqlalchemy from 2.0.54 to 2.1.3

Release notes

Sourced from sqlalchemy's releases.

2.1.3

Released: October 2, 2026

orm

  • [orm] [bug] [regression] Fixed regression where columns delivered to a mapped class from an unmapped _orm.MappedAsDataclass mixin, or from a class decorated with _orm.unmapped_dataclass(), would not be placed in the _schema.Table in the order in which they were declared on the mixin; columns that had no dataclass default, such as a primary key column with no _orm.mapped_column.default, or which made use of _orm.mapped_column.default_factory, would be moved after the remaining columns of the mixin.

    References: #13634

sql

  • [sql] [bug] [regression] Fixed regression caused by the new implementation of ExecutableStatement.params() where parameter values established using this method would not be rendered when compiling the statement with the literal_binds compiler option, instead rendering NULL with a warning.

    References: #13635

2.1.2

Released: October 2, 2026

orm

  • [orm] [bug] [regression] Fixed regression caused by #5987 where the selectinload() loader strategy would ignore additional criteria present in the _orm.relationship.primaryjoin of a many-to-many relationship, such as a comparison against a column on the association table or on the parent table, loading related rows that should have been excluded. The omit_join optimization for many-to-many relationships is now only used when the primaryjoin consists solely of comparisons between the parent's primary key columns and the association table.

    References: #13626

engine

... (truncated)

Commits

Updates sse-starlette from 3.4.11 to 3.5.0

Release notes

Sourced from sse-starlette's releases.

v3.5.0

Fixed

  • A stopped uvicorn server no longer cancels SSE streams of later servers in the same process (#211, regression since 3.1.1). Typical trigger: test suites starting a real server per test.

Behaviour change

  • AppStatus.should_exit is no longer set when sse-starlette detects uvicorn's own Server.should_exit (fallback path, e.g. uvicorn "module:app"). Streams still close on shutdown. If you read AppStatus.should_exit to detect shutdown, use shutdown_event instead.
  • A real SIGTERM/SIGINT still sets AppStatus.should_exit process-wide; see README "Testing" if your tests send real signals to an in-process server.

Upgrade note

  • If you called AppStatus.disable_automatic_graceful_drain() only to work around #211, remove it to get automatic stream draining back.

What's Changed

Full Changelog: sysid/sse-starlette@v3.4.11...v3.5.0

Commits
  • 1705b2d Bump version to 3.5.0
  • 16179fd Merge pull request #212 from sysid/fix/issue211
  • 3821353 fix(shutdown): re-resolve uvicorn server on every watcher poll
  • 6925c68 fix(tests): import httpx2 instead of removed httpx dependency
  • aa3b89e build(deps): bump starlette to 1.7.0 for anyio BlockingPortal deprecation
  • 329a72c build(deps): bump anyio, autobahn, setuptools for security advisories
  • d43a29f test(experimentation): assert consumer line counts in main thread
  • 96afe01 fix(shutdown): stop latching AppStatus.should_exit from uvicorn state
  • See full diff in compare view

Updates charset-normalizer from 3.5.1 to 3.5.2

Release notes

Sourced from charset-normalizer's releases.

Version 3.5.2

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Changelog

Sourced from charset-normalizer's changelog.

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Commits
  • 935c29a Release 3.5.2 (#805)
  • 9d3238a test: disable traefik in downstream niquests
  • b4c0368 docs: write changelog entry for 3.5.2
  • 717da31 chore: bump version to 3.5.2
  • 264895d chore: update pypa/cibuildwheel and pypa/gh-action-pypi-publish
  • 41e28b6 chore: raise Cython upper bound to 3.3
  • b130b7d Fix valid UTF-8 Chinese JSON misdetected as PTCP154 (#796)
  • f6afd31 Make the IANA_NO_ALIASES encodings resolvable by name (#800)
  • See full diff in compare view

Updates markdown from 3.10.3 to 3.11

Release notes

Sourced from markdown's releases.

Release 3.11.0

Changed

  • Inline processors now resume searching after the previous match, improving performance for repeated inline patterns (#1619).
  • Officially support Python 3.15 and drop support for Python 3.10
  • Walk backtick runs in BacktickInlineProcessor without a regex (#1620).
  • Switch static site generator for documentation from MkDocs to Zensical (#1627, #1635, #1637, and #1638).

Fixed

  • Ensure removing Abbreviations does not raise an error (#1634).
  • Fix an issue with excessive backtracking when matching inline code blocks (#1617).
  • md_in_html now honors tags added to Markdown.block_level_elements after the extension is loaded (#1246).
  • Fix quadratic-time regex backtracking in ReferenceProcessor when a link reference definition has no URL, e.g. a line consisting only of [id]: followed by many trailing spaces (#798).
  • Document attr_list usage for def_list (#1123).
Changelog

Sourced from markdown's changelog.


title: Changelog toc_depth: 2

Python-Markdown Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to the Python Version Specification. See the Contributing Guide for details.

[Unreleased]

  • Update serializer to be non-recursive (#1644).
  • Improve ancestor handling in the inline Treeprocessor (#1646).
  • Keep a raw HTML comment inside an inline HTML element that closes in the same paragraph, instead of splitting the paragraph around it (#1643).
  • Fix issue where inline HTML attributes were rejected if they had < or > in the attribute (#1647).
  • Fix issue where an unterminated end tag (</foo) could cause all remaining content to be dropped (#1651).

[3.11.0] - 2026-09-25

Changed

  • Inline processors now resume searching after the previous match, improving performance for repeated inline patterns (#1619).
  • Officially support Python 3.15 and drop support for Python 3.10
  • Walk backtick runs in BacktickInlineProcessor without a regex (#1620).
  • Switch static site generator for documentation from MkDocs to Zensical (#1627, #1635, #1637, and #1638).

Fixed

  • Ensure removing Abbreviations does not raise an error (#1634).
  • Fix an issue with excessive backtracking when matching inline code blocks (#1617).
  • md_in_html now honors tags added to Markdown.block_level_elements after the extension is loaded (#1246).
  • Fix quadratic-time regex backtracking in ReferenceProcessor when a link reference definition has no URL, e.g. a line consisting only of [id]: followed by many trailing spaces (#798).
  • Document attr_list usage for def_list (#1123).
Commits
  • 0ffbf00 Bump version to 3.11.0
  • 547a934 Show adminitions as rendered examples in contrbuting guide
  • 571f050 Cleanup archived changelog
  • a5176b0 Ensure py-render codeblock title in properly escaped.
  • 819fff9 Document the use of attr_list with def_list.
  • 36cdbd3 Final cleanup for Zensical transition
  • 8a96db5 Add py-render custom code block formater
  • 5d1363c Fix quadratic-time backtracking when a reference link has no URL
  • 0d6afd1 Add Markdown renderer as superfences formatter
  • 175fb5a Ensure removing Abbreviations does not raise an error.
  • Additional commits viewable in compare view

Updates pydantic-core from 2.46.5 to 2.49.0

Commits

Updates python-dotenv from 1.2.3 to 1.2.4

Release notes

Sourced from python-dotenv's releases.

v1.2.4

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Changelog

Sourced from python-dotenv's changelog.

[1.2.4] - 2026-10-01

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Commits
  • a565c2c Bump version: 1.2.3 → 1.2.4
  • 4a7abd0 docs: add 1.2.4 release notes (#663, #698, #700)
  • f215c02 fix: dotenv get exits 0 for empty string values (#700)
  • 58f2d7c test: make test_run_with_command_flags portable and meaningful (#709)
  • e0310e5 fix: honor --no-override when expanding variables in dotenv run (#698)
  • a00cb2e docs: add CHANGELOG entry for #663 (fix #600)
  • f5485a6 fix: parse empty unquoted value with inline comment as empty string
  • See full diff in compare view

Updates soupsieve from 2.9.2 to 2.10

Release notes

Sourced from soupsieve's releases.

2.10

  • NEW: Support Python 3.15.
  • NEW: Add new ignore option to API methods that allows the specification of specific pseudo-classes to be ignored.
  • NEW: Tighten restrictions such that namespaces and custom objects must always be a Mapping, previously lists of tuples were also allowed.
  • NEW: Use a singleton for null selectors internally via called Null of type SelectorNull.
  • NEW: For performance, Soup Sieve will no longer try and coerce bad attribute values to useable strings.
  • NEW: Add NOCACHE flag that can be used to disable caching optimizations selectors and possibly other future caching optimizations. Provided for disabling and also disabling if issues are found with the new caching approach.
  • FIX: Improve performance of ~ for various cases by employing caching.
  • FIX: Improve performance of nth-* family of selectors in certain scenarios by employing caching.
  • FIX: Ensure custom is properly passed down from API functions to compilation.
Commits
  • fc195cd Add official support for Python 3.15 (#305)
  • 04af8c7 Update changelog
  • edf9a5e Include tools in sdist
  • 71c662b Fix example and update doc configuration
  • 0928124 Rework patterns
  • 56c9655 Update documentation
  • ffb88cc Employ caching to speed up various cases of general sibling combinator (#304)
  • 537d072 Use caching to increase performance of nth-* family of selectors (#301)
  • 8df4abf Don't coerce bad attributes to strings
  • 7975507 Improve performance for tag and namespace checking
  • Additional commits viewable in compare view

Updates starlette from 1.6.0 to 1.7.0

Release notes

Sourced from starlette's releases.

Version 1.7.0

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING] OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

Full changelog: 1.6.0...1.7.0

Changelog

Sourced from starlette's changelog.

1.7.0 (September 23, 2026)

This release adds experimental OpenTelemetry tracing and requires AnyIO 4.

!!! warning "OpenTelemetryMiddleware is experimental" Its API and emitted telemetry may change in minor releases without a deprecation period #3574.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.
Commits
  • 2269e9a Version 1.7.0 (#3575)
  • 4fe55eb Preserve FileResponse status for range requests (#3568)
  • 1f08daf Mark OpenTelemetryMiddleware as experimental (#3574)
  • 57de5fa Support HTTP response trailers in TestClient (#3563)
  • 03f12b7 Allow HTTPException to use non-standard status codes (#3545)
  • 76fd00f Reject WebSocket requests to StaticFiles (#3532)
  • f03f65c docs: fix 'its not available' and 'This ensure' wording (#3526)
  • 485aca4 docs: the test client is built on httpx2, not httpx (#3525)
  • fd662b1 Implement identity on SimpleUser and UnauthenticatedUser (#3271)
  • 41db6a7 Stabilize CodSpeed upload buffer allocations (#3524)
  • Additional commits viewable in compare view

Updates tzdata from 2026.4 to 2026.5

Release notes

Sourced from tzdata's releases.

2026.5: Release of upstream tzdata 2026e

Version 2026.5

Upstream version 2026e released 2026-09-30T00:14:38+00:00.

Briefly:

Manitoba moves to permanent -05 on 2026-10-31.

Changes to future timestamps

Manitoba’s 2026-03-08 spring forward was its last foreseeable clock change, as it moved to permanent -05 thereafter. Model this with its traditional abbreviation EST. Although the change to permanent -05 legally takes place on 2026-10-31, temporarily model the change to occur on 2026-11-01 at 02:00 for the same reason as other recent temporary hacks. (Caution: see “NOTE FOR 2026b TEMPORARY HACK FOR CLDR AND CANADA” below.)

As the change affects both America/Winnipeg and its backward compatibility link, the obsolescent setting TZ="Canada/Central" will now use the abbreviation EST for affected timestamps, akin to TZ="Canada/Pacific" behavior introduced in 2026b.

Another TZDB release may be needed soon if any of the portions of northwestern Ontario historically aligned with America/Winnipeg do not follow. For now, given the short leadtime with Manitoba’s announcement, assume that they will, to avoid creating new zones that may not be needed if no divergence occurs.

Changes to past timestamps

In 1925 Ireland fell back on 09-20 not 10-04 (thanks to Stan Ulbrych).

Changes to commentary

Discussion on timekeeping practices in northwestern Ontario has been expanded in light of Manitoba’s recent announcement. It is not yet known whether or to what extent these areas may adapt their own timekeeping practices in response.

Changelog

Sourced from tzdata's changelog.

Version 2026.5

Upstream version 2026e released 2026-09-30T00:14:38+00:00

Briefly:

Manitoba moves to permanent -05 on 2026-10-31.

Changes to future timestamps

Manitoba’s 2026-03-08 spring forward was its last foreseeable clock change, as it moved to permanent -05 thereafter. Model this with its traditional abbreviation EST. Although the change to permanent -05 legally takes place on 2026-10-31, temporarily model the change to occur on 2026-11-01 at 02:00 for the same reason as other recent temporary hacks. (Caution: see “NOTE FOR 2026b TEMPORARY HACK FOR CLDR AND CANADA” below.)

As the change affects both America/Winnipeg and its backward compatibility link, the obsolescent setting TZ="Canada/Central" will now use the abbreviation EST for affected timestamps, akin to TZ="Canada/Pacific" behavior introduced in 2026b.

Another TZDB release may be needed soon if any of the portions of northwestern Ontario historically aligned with America/Winnipeg do not follow. For now, given the short leadtime with Manitoba’s announcement, assume that they will, to avoid creating new zones that may not be needed if no divergence occurs.

Changes to past timestamps

In 1925 Ireland fell back on 09-20 not 10-04 (thanks to Stan Ulbrych).

Changes to commentary

Discussion on timekeeping practices in northwestern Ontario has been expanded in light of Manitoba’s recent announcement. It is not yet known whether or to what extent these areas may adapt their own timekeeping practices in response.


Commits

Updates wrapt from 2.4.1 to 2.5.0

Release notes

Sourced from wrapt's releases.

wrapt 2.5.0

Full release notes: https://wrapt.readthedocs.io/en/latest/changes.html#version-2-5-0

Install from PyPi (recommended):

pip install wrapt==2.5.0

PyPi uploads follow each GitHub release; if pip reports the version is unavailable, the matching PyPi upload may not have happened yet.

Pre-built wheels are provided for a range of Python versions and platforms (Linux x86_64/aarch64/riscv64, macOS x86_64 and arm64, Windows x86_64 and arm64, plus PyPy and free-threaded builds). The source distribution is also attached together with SHA256SUMS for verification.

wrapt 2.5.0rc1

Release candidate. Release notes for the upcoming 2.5.0 final (work in progress): https://wrapt.readthedocs.io/en/latest/changes.html#version-2-5-0

May be installable from PyPi:

pip install wrapt==2.5.0rc1

If pip reports the version is unavailable, this candidate either has not been uploaded yet or is not being published to PyPi. Use the attached wheels or build from the source distribution instead:

tar xf wrapt-2.5.0rc1.tar.gz
cd wrapt-2.5.0rc1
pip install .

SHA256SUMS is attached for verification of the archives.

wrapt 2.4.2rc1

Release candidate. Release notes for the upcoming 2.4.2 final (work in progress): https://wrapt.readthedocs.io/en/latest/changes.html#version-2-4-2

May be installable from PyPi:

pip install wrapt==2.4.2rc1

If pip reports the version is unavailable, this candidate either has not been uploaded yet or is not being published to PyPi. Use the attached wheels or build from the source distribution instead:

tar xf wrapt-2.4.2rc1.tar.gz

... (truncated)

Changelog

Sourced from wrapt's changelog.

Version 2.5.0

New Features

  • Added with_doc, a decorator for overriding the docstring that help(), pydoc and other introspection tools see for a wrapped callable without mutating the wrapped function itself. It is the companion of with_signature. The docstring can be supplied directly, or as a factory callable that derives it from the wrapped function at decoration time. When stacked above with_signature the factory sees the overridden signature and can embed it in the docstring. Assigning to __doc__ on the resulting wrapper replaces the override, and deleting it restores delegation to the wrapped function. Previously the only option was to assign to __doc__ on a wrapper, which writes through to the wrapped function since __doc__ on every proxy delegates to the wrapped object, and so changed what was reported for the wrapped function everywhere. The override is handled for instance methods, class methods and static methods, and propagates through outer wrapt decorators stacked on top. See the "Docstring Override" section of :doc:bundled for details.

  • with_signature now accepts a doc argument for overriding the docstring at the same time as the signature, and the factory callable may return a tuple of (signature_or_prototype, docstring) so that a single factory can derive both from the wrapped function in one pass. When doc is supplied, the docstring from the tuple is ignored. When neither is given, __doc__ continues to delegate to the wrapped function as before, including for assignment and deletion.

  • A class derived from wrapt.BaseObjectProxy may now define __doc__ as a property, or other descriptor, in its class body, and that is used for instances of the class in place of the default delegation of __doc__ to the wrapped object. This works with both the pure Python implementation and the C extension, and the descriptor is inherited by further derived classes. Previously the pure Python metaclass overwrote such a descriptor wi...

    Description has been truncated

Bumps the backend-deps group in /backend with 12 updates:

| Package | From | To |
| --- | --- | --- |
| [fastapi](https://github.com/fastapi/fastapi) | `0.141.1` | `0.142.2` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.53.0` | `0.54.0` |
| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.54` | `2.1.3` |
| [sse-starlette](https://github.com/sysid/sse-starlette) | `3.4.11` | `3.5.0` |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.5.1` | `3.5.2` |
| [markdown](https://github.com/Python-Markdown/markdown) | `3.10.3` | `3.11` |
| [pydantic-core](https://github.com/pydantic/pydantic) | `2.46.5` | `2.49.0` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.3` | `1.2.4` |
| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.9.2` | `2.10` |
| [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` |
| [tzdata](https://github.com/python/tzdata) | `2026.4` | `2026.5` |
| [wrapt](https://github.com/GrahamDumpleton/wrapt) | `2.4.1` | `2.5.0` |


Updates `fastapi` from 0.141.1 to 0.142.2
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.141.1...0.142.2)

Updates `uvicorn` from 0.53.0 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.53.0...0.54.0)

Updates `sqlalchemy` from 2.0.54 to 2.1.3
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

Updates `sse-starlette` from 3.4.11 to 3.5.0
- [Release notes](https://github.com/sysid/sse-starlette/releases)
- [Commits](sysid/sse-starlette@v3.4.11...v3.5.0)

Updates `charset-normalizer` from 3.5.1 to 3.5.2
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](jawah/charset_normalizer@3.5.1...3.5.2)

Updates `markdown` from 3.10.3 to 3.11
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](Python-Markdown/markdown@3.10.3...3.11.0)

Updates `pydantic-core` from 2.46.5 to 2.49.0
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/main/HISTORY.md)
- [Commits](pydantic/pydantic@core-v2.46.5...core-v2.49.0)

Updates `python-dotenv` from 1.2.3 to 1.2.4
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.3...v1.2.4)

Updates `soupsieve` from 2.9.2 to 2.10
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](facelessuser/soupsieve@2.9.2...2.10)

Updates `starlette` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.6.0...1.7.0)

Updates `tzdata` from 2026.4 to 2026.5
- [Release notes](https://github.com/python/tzdata/releases)
- [Changelog](https://github.com/python/tzdata/blob/master/NEWS.md)
- [Commits](python/tzdata@2026.4...2026.5)

Updates `wrapt` from 2.4.1 to 2.5.0
- [Release notes](https://github.com/GrahamDumpleton/wrapt/releases)
- [Changelog](https://github.com/GrahamDumpleton/wrapt/blob/develop/docs/changes.rst)
- [Commits](GrahamDumpleton/wrapt@2.4.1...2.5.0)

---
updated-dependencies:
- dependency-name: fastapi
  dependency-version: 0.142.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-deps
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-deps
- dependency-name: sqlalchemy
  dependency-version: 2.1.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-deps
- dependency-name: sse-starlette
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-deps
- dependency-name: charset-normalizer
  dependency-version: 3.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-deps
- dependency-name: markdown
  dependency-version: '3.11'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-deps
- dependency-name: pydantic-core
  dependency-version: 2.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-deps
- dependency-name: python-dotenv
  dependency-version: 1.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-deps
- dependency-name: soupsieve
  dependency-version: '2.10'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-deps
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-deps
- dependency-name: tzdata
  dependency-version: '2026.5'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-deps
- dependency-name: wrapt
  dependency-version: 2.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants