Skip to content

chore(deps): bump the ci-toolchain group across 1 directory with 8 updates - #399

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/pip/requirements/dev/ci-toolchain-29a0c5ef11
Open

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/pip/requirements/dev/ci-toolchain-29a0c5ef11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Bumps the ci-toolchain group with 8 updates in the /requirements directory:

Package From To
hatchling 1.32.0 1.32.4
idna 3.19 3.20
httpcore2 2.12.0 2.13.1
httpx2 2.12.0 2.13.1
pyjwt 2.14.0 2.15.0
starlette 1.6.0 1.7.0
watchfiles 1.2.0 1.3.0
cyclonedx-bom 7.3.0 7.4.0

Updates hatchling from 1.32.0 to 1.32.4

Release notes

Sourced from hatchling's releases.

Hatchling v1.32.4

Fixed:

  • Revert the extra type parameter added to BuildHookInterface in 1.32.3, which broke plugins that subscripted the interface with a single argument (e.g. BuildHookInterface[MyConfig]) by raising TypeError at import time. BuilderConfig is likewise no longer generic, restoring the pre-1.32.3 plugin interface.
  • Strip spaces around version metadata when using original input for CalVer to keep leading zeroes.

Hatchling v1.32.3

Fixed:

  • Preserve the version string exactly as written in core metadata, so stylized versions such as CalVer 2026.08.10 are no longer stripped of leading zeros. Distribution file names and .dist-info directories continue to use the PEP 440 normalized form.
Commits

Updates idna from 3.19 to 3.20

Release notes

Sourced from idna's releases.

v3.20

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Changelog

Sourced from idna's changelog.

3.20 (2026-09-17)

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Commits
  • d55e65e Release 3.20
  • 0c0824a Pre-release 3.20rc0
  • bd7c316 Note Python 3.15 support in the 3.20 changelog
  • b6cce85 Merge pull request #276 from kjd/unicode-18
  • 9a4bc59 Update to Unicode 18.0.0
  • dfab5a0 Merge branch 'python-3.15'
  • 417c354 Read the latest Unicode version from the DerivedAge.txt header instead of the...
  • cd17392 Merge pull request #274 from kjd/fix-decode-length-check
  • c5796d7 Skip the decode round-trip check for domains past encode's length limit
  • d6ee690 Update to Python 3.15 release candidate in CI and add trove classifier
  • Additional commits viewable in compare view

Updates httpcore2 from 2.12.0 to 2.13.1

Release notes

Sourced from httpcore2's releases.

v2.13.1

Highlights

📤 Accurate file upload lengths

Passing a file as content= now calculates Content-Length from its remaining bytes, respecting the current file position (#1214).

🔐 Reliable proxy TLS and HTTP/2 negotiation

TLS hostname overrides now apply inside HTTP proxy tunnels without affecting the proxy's own TLS connection (#1223). HTTP/2 is advertised first when enabled, and HTTP/1.1 is omitted when disabled (#1155).

🧹 Clean WebSocket shutdown

The sync WebSocket keepalive thread now exits cleanly when a ping races with connection shutdown (#1228).

httpx2

Fixed

  • Calculate Content-Length from the remaining bytes when a file is passed as content=, respecting its current position (#1214).
  • Stop the sync WebSocket keepalive thread cleanly when a ping races with connection shutdown (#1228).

httpcore2

Fixed

  • Honor the sni_hostname extension for TLS inside HTTP proxy tunnels without applying it to the proxy's TLS connection (#1223).
  • Prefer HTTP/2 during TLS protocol negotiation when enabled, and stop advertising HTTP/1.1 when it is disabled (#1155).

Full Changelog: pydantic/httpx2@v2.13.0...v2.13.1

v2.13.0

Highlights

🔐 Reliable TLS verification controls

The CLI --no-verify flag now disables TLS certificate verification as intended, and --verify provides an explicit counterpart (pydantic/httpx2#1140, pydantic/httpx2#1186).

🧹 Safer async stream cleanup

Stopping a streamed response early no longer risks a nested async generator finalization error (pydantic/httpx2#1204).

httpx2

Changed

  • Require brotlicffi 1.2.0.2 or later for the brotli extra on non-CPython implementations in pydantic/httpx2#1179

Fixed

... (truncated)

Commits
  • d91c9f4 Correct the upcoming release version to 2.13.1 (#1228)
  • 62a607d Prepare version 2.14.0 (#1227)
  • 392bbed Honor the TLS hostname override in proxy tunnels (#1223)
  • df9783d Respect file cursor positions when calculating raw content length (#1214)
  • 36c4009 httpcore2: prefer h2 for ALPN protocol if requesting HTTP/2 (#1155)
  • 04d152b docs: correct stale URL.query example (#1222)
  • f295185 Prepare version 2.13.0 (#1208)
  • c518f71 Avoid nested async generator finalization errors (#1204)
  • 8f215b5 Use portable links in API docstrings (#1202)
  • 81c523f Revert "Maintain connection reservations incrementally in the pool" (#1197)
  • Additional commits viewable in compare view

Updates httpx2 from 2.12.0 to 2.13.1

Release notes

Sourced from httpx2's releases.

v2.13.1

Highlights

📤 Accurate file upload lengths

Passing a file as content= now calculates Content-Length from its remaining bytes, respecting the current file position (#1214).

🔐 Reliable proxy TLS and HTTP/2 negotiation

TLS hostname overrides now apply inside HTTP proxy tunnels without affecting the proxy's own TLS connection (#1223). HTTP/2 is advertised first when enabled, and HTTP/1.1 is omitted when disabled (#1155).

🧹 Clean WebSocket shutdown

The sync WebSocket keepalive thread now exits cleanly when a ping races with connection shutdown (#1228).

httpx2

Fixed

  • Calculate Content-Length from the remaining bytes when a file is passed as content=, respecting its current position (#1214).
  • Stop the sync WebSocket keepalive thread cleanly when a ping races with connection shutdown (#1228).

httpcore2

Fixed

  • Honor the sni_hostname extension for TLS inside HTTP proxy tunnels without applying it to the proxy's TLS connection (#1223).
  • Prefer HTTP/2 during TLS protocol negotiation when enabled, and stop advertising HTTP/1.1 when it is disabled (#1155).

Full Changelog: pydantic/httpx2@v2.13.0...v2.13.1

v2.13.0

Highlights

🔐 Reliable TLS verification controls

The CLI --no-verify flag now disables TLS certificate verification as intended, and --verify provides an explicit counterpart (pydantic/httpx2#1140, pydantic/httpx2#1186).

🧹 Safer async stream cleanup

Stopping a streamed response early no longer risks a nested async generator finalization error (pydantic/httpx2#1204).

httpx2

Changed

  • Require brotlicffi 1.2.0.2 or later for the brotli extra on non-CPython implementations in pydantic/httpx2#1179

Fixed

... (truncated)

Changelog

Sourced from httpx2's changelog.

2.13.1 (September 23rd, 2026)

Fixed

  • Calculate Content-Length from the remaining bytes when a file is passed as content=, respecting its current position. (#1214)
  • Stop the sync WebSocket keepalive thread cleanly when a ping races with connection shutdown. (#1228)

2.13.0 (September 14th, 2026)

Changed

  • Require brotlicffi 1.2.0.2 or later for the brotli extra on non-CPython implementations. (#1179)

Fixed

  • Make the --no-verify CLI flag disable TLS certificate verification and add an explicit --verify counterpart. (#1140, #1186)
  • Avoid nested async generator finalization errors when streamed responses are abandoned early. (#1204)
Commits

Updates pyjwt from 2.14.0 to 2.15.0

Release notes

Sourced from pyjwt's releases.

2.15.0

See the 2.15.0 changelog for complete release details.

Changelog

Sourced from pyjwt's changelog.

v2.15.0 <https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0>__

Security


- Wrap recursion errors from deeply nested JWT payloads in ``DecodeError``
  instead of exposing a raw ``RecursionError``.

Added


- Support Python 3.15 by @kytta in `[#1202](https://github.com/jpadilla/pyjwt/issues/1202) &lt;https://github.com/jpadilla/pyjwt/pull/1202&gt;`__

Changed

  • JWKSetCache now stores the parsed PyJWKSet rather than the raw JWKS payload, so a cache hit no longer re-parses every key. JWKSetCache.put() accepts either form and raises PyJWKSetError for anything else. As a result, PyJWKClient.get_jwk_set() returns the same PyJWKSet instance for as long as it stays cached, rather than a freshly built one per call in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__
  • PyJWKClient.fetch_data() now raises PyJWKClientError(&quot;The JWKS endpoint did not return a JSON object&quot;) when the endpoint response is not a JSON object, instead of returning it for get_jwk_set() to reject. Callers reaching the JWKS through get_jwk_set() see the same error as before in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__

Fixed


- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead
  of raising ``PyJWKClientError(&quot;The JWKS endpoint did not return a JSON
  object&quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value,
  so callers pre-populating the cache to avoid a network round-trip could not
  read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) &lt;https://github.com/jpadilla/pyjwt/issues/914&gt;`__ and
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
  ``fetch_data()`` override that filters or transforms the JWKS is no longer
  undone by the next cache hit in
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- Raise the documented ``PyJWTError`` subclass instead of leaking a
  ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
  non-numeric, non-string value such as a list, dict, or ``null``.
- Reject OKP JWK private keys when their public ``x`` component does not
  match the private ``d`` component.
- Treat malformed JWK Set members as unusable keys rather than letting
  ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is not
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>

<ul>
<li><a href="https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68&quot;&gt;&lt;code&gt;1d41a64&lt;/code&gt;&lt;/a> chore: prepare 2.15.0 release</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3&quot;&gt;&lt;code&gt;9bc0665&lt;/code&gt;&lt;/a> fix: make recursive payload tests deterministic</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b&quot;&gt;&lt;code&gt;5fde08a&lt;/code&gt;&lt;/a> fix: normalize recursive JWT payload errors</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19&quot;&gt;&lt;code&gt;171062d&lt;/code&gt;&lt;/a> utils: mention bytes in force_bytes type error (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1173&quot;&gt;#1173&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6&quot;&gt;&lt;code&gt;c9d4d53&lt;/code&gt;&lt;/a> docs/conf: drop duplicate 'and' from read() docstring (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1174&quot;&gt;#1174&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53&quot;&gt;&lt;code&gt;2763752&lt;/code&gt;&lt;/a> Add support for Python 3.15 (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1202&quot;&gt;#1202&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5&quot;&gt;&lt;code&gt;4adcd02&lt;/code&gt;&lt;/a> Catch http.client.HTTPException in PyJWKClient.fetch_data (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1201&quot;&gt;#1201&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097&quot;&gt;&lt;code&gt;9e501d9&lt;/code&gt;&lt;/a> fix: correct docstring typo in _validate_jti (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1179&quot;&gt;#1179&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2&quot;&gt;&lt;code&gt;4047c44&lt;/code&gt;&lt;/a> docs: clarify JWK certificate member handling (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1212&quot;&gt;#1212&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9&quot;&gt;&lt;code&gt;f4e2b59&lt;/code&gt;&lt;/a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1210&quot;&gt;#1210&lt;/a&gt;)&lt;/li>
<li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&quot;&gt;compare view</a></li>
</ul>
</details>

<br />

Updates starlette from 1.6.0 to 1.7.0

Release notes

Sourced from starlette's releases.

Version 1.7.0

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING] OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

Full changelog: 1.6.0...1.7.0

Changelog

Sourced from starlette's changelog.

1.7.0 (September 23, 2026)

This release adds experimental OpenTelemetry tracing and requires AnyIO 4.

!!! warning "OpenTelemetryMiddleware is experimental" Its API and emitted telemetry may change in minor releases without a deprecation period #3574.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.
Commits
  • 2269e9a Version 1.7.0 (#3575)
  • 4fe55eb Preserve FileResponse status for range requests (#3568)
  • 1f08daf Mark OpenTelemetryMiddleware as experimental (#3574)
  • 57de5fa Support HTTP response trailers in TestClient (#3563)
  • 03f12b7 Allow HTTPException to use non-standard status codes (#3545)
  • 76fd00f Reject WebSocket requests to StaticFiles (#3532)
  • f03f65c docs: fix 'its not available' and 'This ensure' wording (#3526)
  • 485aca4 docs: the test client is built on httpx2, not httpx (#3525)
  • fd662b1 Implement identity on SimpleUser and UnauthenticatedUser (#3271)
  • 41db6a7 Stabilize CodSpeed upload buffer allocations (#3524)
  • Additional commits viewable in compare view

Updates watchfiles from 1.2.0 to 1.3.0

Release notes

Sourced from watchfiles's releases.

v1.3.0 2026-09-21

What's Changed

New Contributors

Full Changelog: https://github.com/samuelcolvin/watchfiles/compare/v1.2.0...v1.3.0

Commits

Updates cyclonedx-bom from 7.3.0 to 7.4.0

Release notes

Sourced from cyclonedx-bom's releases.

v7.4.0 (2026-09-15)

Features

  • Respect env var SOURCE_DATE_EPOCH when generating reproducible output (#1084, 51813c7)

What's Changed

New Contributors

Full Changelog: https://github.com/CycloneDX/cyclonedx-python/compare/v7.3.1...v7.4.0

v7.3.1 (2026-07-23)

Bug Fixes

  • Improve error message for non-PEP 621 pyproject.toml (#1080, 6715bd9)

Documentation


What's Changed

... (truncated)

Changelog

Sourced from cyclonedx-bom's changelog.

v7.4.0 (2026-09-15)

Features

  • Respect env var SOURCE_DATE_EPOCH when generating reproducible output (#1084, 51813c7)

v7.3.1 (2026-07-23)

Bug Fixes

  • Improve error message for non-PEP 621 pyproject.toml (#1080, 6715bd9)

Documentation

Commits
  • f6f4941 chore(release): 7.4.0
  • f97a9a9 chore(deps): Bump actions/download-artifact from 7.0.0 to 8.0.1 (#1046)
  • 0fd16c3 chore(deps): Bump actions/upload-artifact from 6.0.0 to 7.0.1 (#1048)
  • d48f71c chore(deps): Bump python from 3.14-slim to 3.14.6-slim (#1065)
  • 2abed0f chore(deps): Bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#1100)
  • 51813c7 feat: respect env var SOURCE_DATE_EPOCH when generating reproducible output...
  • 0e4de7a chore(deps): Bump docker/login-action from 3.7.0 to 4.6.0 (#1092)
  • b51c001 chore(deps): Bump pypa/gh-action-pypi-publish from 1.14.1 to 1.14.2 (#1090)
  • 25bfa4c chore(deps-dev): Update uv requirement from 0.11.32 to 0.12.10 (#1101)
  • 20a8345 chore(deps): Bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 (#1091)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…dates

Bumps the ci-toolchain group with 8 updates in the /requirements directory:

| Package | From | To |
| --- | --- | --- |
| [hatchling](https://github.com/pypa/hatch) | `1.32.0` | `1.32.4` |
| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |
| [httpcore2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.1` |
| [httpx2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.1` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.14.0` | `2.15.0` |
| [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` |
| [watchfiles](https://github.com/samuelcolvin/watchfiles) | `1.2.0` | `1.3.0` |
| [cyclonedx-bom](https://github.com/CycloneDX/cyclonedx-python) | `7.3.0` | `7.4.0` |



Updates `hatchling` from 1.32.0 to 1.32.4
- [Release notes](https://github.com/pypa/hatch/releases)
- [Commits](pypa/hatch@hatchling-v1.32.0...hatchling-v1.32.4)

Updates `idna` from 3.19 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.19...v3.20)

Updates `httpcore2` from 2.12.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Commits](pydantic/httpx2@v2.12.0...v2.13.1)

Updates `httpx2` from 2.12.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](pydantic/httpx2@v2.12.0...v2.13.1)

Updates `pyjwt` from 2.14.0 to 2.15.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.14.0...2.15.0)

Updates `starlette` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.6.0...1.7.0)

Updates `watchfiles` from 1.2.0 to 1.3.0
- [Release notes](https://github.com/samuelcolvin/watchfiles/releases)
- [Commits](samuelcolvin/watchfiles@v1.2.0...v1.3.0)

Updates `cyclonedx-bom` from 7.3.0 to 7.4.0
- [Release notes](https://github.com/CycloneDX/cyclonedx-python/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-python/blob/main/CHANGELOG.md)
- [Commits](CycloneDX/cyclonedx-python@v7.3.0...v7.4.0)

---
updated-dependencies:
- dependency-name: hatchling
  dependency-version: 1.32.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-toolchain
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: httpcore2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: httpx2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: watchfiles
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: cyclonedx-bom
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 27, 2026
@dependabot
dependabot Bot requested a review from Brad-Edwards as a code owner September 27, 2026 02:56
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 27, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants