Skip to content

chore(deps): bump the ci-toolchain group across 1 directory with 13 updates - #404

Closed
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/pip/requirements/dev/ci-toolchain-7f48d028da
Closed

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/pip/requirements/dev/ci-toolchain-7f48d028da

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the ci-toolchain group with 13 updates in the /requirements directory:

Package From To
hatchling 1.32.0 1.32.4
idna 3.19 3.20
coverage 7.16.1 7.16.2
blake3 1.0.9 1.0.10
fastapi 0.141.1 0.142.1
httpcore2 2.12.0 2.13.1
httpx2 2.12.0 2.13.1
opentelemetry-api 1.44.0 1.45.0
sse-starlette 3.4.11 3.5.0
starlette 1.6.0 1.7.0
uvicorn 0.53.0 0.54.0
watchfiles 1.2.0 1.3.0
cyclonedx-bom 7.3.0 7.5.0

Updates hatchling from 1.32.0 to 1.32.4

Release notes

Sourced from hatchling's releases.

Hatchling v1.32.4

Fixed:

  • Revert the extra type parameter added to BuildHookInterface in 1.32.3, which broke plugins that subscripted the interface with a single argument (e.g. BuildHookInterface[MyConfig]) by raising TypeError at import time. BuilderConfig is likewise no longer generic, restoring the pre-1.32.3 plugin interface.
  • Strip spaces around version metadata when using original input for CalVer to keep leading zeroes.

Hatchling v1.32.3

Fixed:

  • Preserve the version string exactly as written in core metadata, so stylized versions such as CalVer 2026.08.10 are no longer stripped of leading zeros. Distribution file names and .dist-info directories continue to use the PEP 440 normalized form.
Commits

Updates idna from 3.19 to 3.20

Release notes

Sourced from idna's releases.

v3.20

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Changelog

Sourced from idna's changelog.

3.20 (2026-09-17)

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Commits
  • d55e65e Release 3.20
  • 0c0824a Pre-release 3.20rc0
  • bd7c316 Note Python 3.15 support in the 3.20 changelog
  • b6cce85 Merge pull request #276 from kjd/unicode-18
  • 9a4bc59 Update to Unicode 18.0.0
  • dfab5a0 Merge branch 'python-3.15'
  • 417c354 Read the latest Unicode version from the DerivedAge.txt header instead of the...
  • cd17392 Merge pull request #274 from kjd/fix-decode-length-check
  • c5796d7 Skip the decode round-trip check for domains past encode's length limit
  • d6ee690 Update to Python 3.15 release candidate in CI and add trove classifier
  • Additional commits viewable in compare view

Updates coverage from 7.16.1 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Commits

Updates blake3 from 1.0.9 to 1.0.10

Release notes

Sourced from blake3's releases.

1.0.10

What's Changed

Full Changelog: oconnor663/blake3-py@1.0.9...1.0.10

Commits

Updates fastapi from 0.141.1 to 0.142.1

Release notes

Sourced from fastapi's releases.

0.142.1

Fixes

0.142.0

Features

Refactors

Docs

Translations

Internal

... (truncated)

Commits

Updates httpcore2 from 2.12.0 to 2.13.1

Release notes

Sourced from httpcore2's releases.

v2.13.1

Highlights

📤 Accurate file upload lengths

Passing a file as content= now calculates Content-Length from its remaining bytes, respecting the current file position (#1214).

🔐 Reliable proxy TLS and HTTP/2 negotiation

TLS hostname overrides now apply inside HTTP proxy tunnels without affecting the proxy's own TLS connection (#1223). HTTP/2 is advertised first when enabled, and HTTP/1.1 is omitted when disabled (#1155).

🧹 Clean WebSocket shutdown

The sync WebSocket keepalive thread now exits cleanly when a ping races with connection shutdown (#1228).

httpx2

Fixed

  • Calculate Content-Length from the remaining bytes when a file is passed as content=, respecting its current position (#1214).
  • Stop the sync WebSocket keepalive thread cleanly when a ping races with connection shutdown (#1228).

httpcore2

Fixed

  • Honor the sni_hostname extension for TLS inside HTTP proxy tunnels without applying it to the proxy's TLS connection (#1223).
  • Prefer HTTP/2 during TLS protocol negotiation when enabled, and stop advertising HTTP/1.1 when it is disabled (#1155).

Full Changelog: pydantic/httpx2@v2.13.0...v2.13.1

v2.13.0

Highlights

🔐 Reliable TLS verification controls

The CLI --no-verify flag now disables TLS certificate verification as intended, and --verify provides an explicit counterpart (pydantic/httpx2#1140, pydantic/httpx2#1186).

🧹 Safer async stream cleanup

Stopping a streamed response early no longer risks a nested async generator finalization error (pydantic/httpx2#1204).

httpx2

Changed

  • Require brotlicffi 1.2.0.2 or later for the brotli extra on non-CPython implementations in pydantic/httpx2#1179

Fixed

... (truncated)

Commits
  • d91c9f4 Correct the upcoming release version to 2.13.1 (#1228)
  • 62a607d Prepare version 2.14.0 (#1227)
  • 392bbed Honor the TLS hostname override in proxy tunnels (#1223)
  • df9783d Respect file cursor positions when calculating raw content length (#1214)
  • 36c4009 httpcore2: prefer h2 for ALPN protocol if requesting HTTP/2 (#1155)
  • 04d152b docs: correct stale URL.query example (#1222)
  • f295185 Prepare version 2.13.0 (#1208)
  • c518f71 Avoid nested async generator finalization errors (#1204)
  • 8f215b5 Use portable links in API docstrings (#1202)
  • 81c523f Revert "Maintain connection reservations incrementally in the pool" (#1197)
  • Additional commits viewable in compare view

Updates httpx2 from 2.12.0 to 2.13.1

Release notes

Sourced from httpx2's releases.

v2.13.1

Highlights

📤 Accurate file upload lengths

Passing a file as content= now calculates Content-Length from its remaining bytes, respecting the current file position (#1214).

🔐 Reliable proxy TLS and HTTP/2 negotiation

TLS hostname overrides now apply inside HTTP proxy tunnels without affecting the proxy's own TLS connection (#1223). HTTP/2 is advertised first when enabled, and HTTP/1.1 is omitted when disabled (#1155).

🧹 Clean WebSocket shutdown

The sync WebSocket keepalive thread now exits cleanly when a ping races with connection shutdown (#1228).

httpx2

Fixed

  • Calculate Content-Length from the remaining bytes when a file is passed as content=, respecting its current position (#1214).
  • Stop the sync WebSocket keepalive thread cleanly when a ping races with connection shutdown (#1228).

httpcore2

Fixed

  • Honor the sni_hostname extension for TLS inside HTTP proxy tunnels without applying it to the proxy's TLS connection (#1223).
  • Prefer HTTP/2 during TLS protocol negotiation when enabled, and stop advertising HTTP/1.1 when it is disabled (#1155).

Full Changelog: pydantic/httpx2@v2.13.0...v2.13.1

v2.13.0

Highlights

🔐 Reliable TLS verification controls

The CLI --no-verify flag now disables TLS certificate verification as intended, and --verify provides an explicit counterpart (pydantic/httpx2#1140, pydantic/httpx2#1186).

🧹 Safer async stream cleanup

Stopping a streamed response early no longer risks a nested async generator finalization error (pydantic/httpx2#1204).

httpx2

Changed

  • Require brotlicffi 1.2.0.2 or later for the brotli extra on non-CPython implementations in pydantic/httpx2#1179

Fixed

... (truncated)

Changelog

Sourced from httpx2's changelog.

2.13.1 (September 23rd, 2026)

Fixed

  • Calculate Content-Length from the remaining bytes when a file is passed as content=, respecting its current position. (#1214)
  • Stop the sync WebSocket keepalive thread cleanly when a ping races with connection shutdown. (#1228)

2.13.0 (September 14th, 2026)

Changed

  • Require brotlicffi 1.2.0.2 or later for the brotli extra on non-CPython implementations. (#1179)

Fixed

  • Make the --no-verify CLI flag disable TLS certificate verification and add an explicit --verify counterpart. (#1140, #1186)
  • Avoid nested async generator finalization errors when streamed responses are abandoned early. (#1204)
Commits

Updates opentelemetry-api from 1.44.0 to 1.45.0

Release notes

Sourced from opentelemetry-api's releases.

Version 1.45.0/0.66b0

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions define as a valid value for this metric. (#5509)
  • opentelemetry-semantic-conventions: update semantic conventions to v1.44.0 (#5511)
  • opentelemetry-sdk: add host.id to the host resource detector (#5653)
  • opentelemetry-test-utils: add CapturingSampler to record what samplers receive in instrumentation tests (#5681)

Changed

  • Enable PIE (flake8-pie) ruff rule and fix all violations (#5150)
  • The public opentelemetry.util.types.AttributeValue type in package opentelemetry-api is being expanded to include None, heterogeneous sequences of primitive types (and nested sequences) as opposed to only homogeneous primitive sequences, and Mappings of strings to any primitive types or sequences/mappings (which themselves must only contain primitive types or sequences/mappings validated the same way). If a bytes type is set as an attribute value in the SDK, it will no longer be utf-8 decoded to a string, instead it will be passed along as is in accordance with the OTEL spec, since bytes is a valid type in the OTLP proto. (#5266)
  • opentelemetry-exporter-otlp-proto-http: add a max_request_size argument to the OTLP HTTP exporters (traces, logs, metrics); serialized requests larger than the limit are dropped before sending, measured before compression. Defaults to 64 MiB (enabled); set to 0 to disable. Mirrors opentelemetry-go#8157. (#5369)
  • [BREAKING] opentelemetry-api: subclasses of Logger need to implement the enabled method (#5380)
  • opentelemetry-exporter-otlp-proto-http: refactor to use shared opentelemetry-exporter-otlp-common and opentelemetry-exporter-http-transport packages and switch default HTTP backend to urllib3 (#5389)
  • opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • opentelemetry-python: enable Ruff default ruleset and fix auto-fixable lint issues (#5491)
  • opentelemetry-sdk: SimpleSpanProcessor now drops spans ended after shutdown() instead of passing them to the exporter, and counts them on otel.sdk.processor.span.processed with error.type=already_shutdown. (#5512)
  • Bump pytest to 9.0.3 (#5518)
  • opentelemetry-exporter-otlp-proto-http: clarify that the endpoint= kwarg requires the full signal path (#5633)
  • opentelemetry-sdk: fix typos in SpanLimits docstring (#5658)

Fixed

  • opentelemetry-configuration: perform environment variable substitution on scalar values after parsing the configuration file, so ${VAR} references inside comments and mapping keys are no longer substituted and undefined references in comments no longer abort loading (#5407)
  • opentelemetry-configuration: declarative config environment variable substitution now replaces an unset variable that has no default with an empty value instead of raising an error, per the configuration spec. Resource attributes whose value resolves to null (an unset ${VAR} with no default) are skipped with a warning instead of being inserted as a null value. (#5408)
  • 'scripts/build.sh: add opentelemetry-configurationandopentelemetry-proto-json` to the package to release (#5425)
  • opentelemetry-sdk: fix View instrument-name matching so a view configured with an instrument's real (mixed-case) name is applied; matching is now case-insensitive and platform-independent instead of relying on fnmatch's OS-dependent case handling (#5430)
  • opentelemetry-sdk: fix missing f-prefix in exponential histogram error messages (#5434)
  • opentelemetry-configuration: resolve false-positive warning logs for newer schema minor version (#5436)
  • opentelemetry-sdk: make methods on FixedSizeExemplarReservoirABC thread safe (#5437)
  • opentelemetry-propagator-jaeger: fix typing issues and enable pyright typechecking for the package opentelemetry-propagator-jaeger: skip uberctx- baggage headers with an empty value on extraction instead of raising TypeError (#5440)
  • opentelemetry-sdk: fix TypeError when instantiating a _BaseConfigurator subclass whose __init__ takes arguments (#5441)
  • opentelemetry-sdk: fix TypeError in os.fork() when a BatchProcessor or PeriodicExportingMetricReader is garbage collected (#5453)
  • opentelemetry-configuration: a declarative config key present with an empty (null) value on an object-typed node (e.g. always_on:, a - service: detector, or a metric console: exporter) is now treated the same as an explicit empty config (always_on: {}) instead of failing type dispatch or silently skipping the node. Both dict-typed nodes and dataclasses constructible with no arguments are covered. (#5454)
  • opentelemetry-api: fix copy-pasted log message in SpanContext.__delattr__ (#5455)
  • opentelemetry-sdk: reject views with ExponentialBucketHistogramAggregation for asynchronous instruments instead of silently producing no data (#5461)
  • opentelemetry-sdk: fill every bucket of SimpleFixedSizeExemplarReservoir before random sampling (#5462)

... (truncated)

Changelog

Sourced from opentelemetry-api's changelog.

Version 1.45.0/0.66b0 (2026-09-25)

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions

... (truncated)

Commits
  • 4f0fcfa Prepare release 1.45.0/0.66b0 (#5690)
  • 9406f34 opentelemetry-test-utils: add CapturingSampler for instrumentation tests (#5681)
  • 1fe31a9 fix: update W3CBaggagePropagator to properly handle whitespace (#5680)
  • 008b5b0 feat(config): wire top-level attribute_limits into per-signal providers (#5365)
  • edfad0c [opentelemetry-sdk] Fix overwriting of the service.instance.id which has been...
  • f5e0f62 opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • e4021aa chore(ci): update ci (#5677)
  • 0c6508c ci: restrict checkout credential persistence (#5589)
  • 2e88971 Add host.id to host resource attributes (#5653)
  • 5f851d2 opentelemetry-exporter-otlp-proto-grpc: fix incorrect default port for gRPC i...
  • Additional commits viewable in compare view

Updates sse-starlette from 3.4.11 to 3.5.0

Release notes

Sourced from sse-starlette's releases.

v3.5.0

Fixed

  • A stopped uvicorn server no longer cancels SSE streams of later servers in the same process (#211, regression since 3.1.1). Typical trigger: test suites starting a real server per test.

Behaviour change

  • AppStatus.should_exit is no longer set when sse-starlette detects uvicorn's own Server.should_exit (fallback path, e.g. uvicorn "module:app"). Streams still close on shutdown. If you read AppStatus.should_exit to detect shutdown, use shutdown_event instead.
  • A real SIGTERM/SIGINT still sets AppStatus.should_exit process-wide; see README "Testing" if your tests send real signals to an in-process server.

Upgrade note

  • If you called AppStatus.disable_automatic_graceful_drain() only to work around #211, remove it to get automatic stream draining back.

What's Changed

Full Changelog: sysid/sse-starlette@v3.4.11...v3.5.0

Commits
  • 1705b2d Bump version to 3.5.0
  • 16179fd Merge pull request #212 from sysid/fix/issue211
  • 3821353 fix(shutdown): re-resolve uvicorn server on every watcher poll
  • 6925c68 fix(tests): import httpx2 instead of removed httpx dependency
  • aa3b89e build(deps): bump starlette to 1.7.0 for anyio BlockingPortal deprecation
  • 329a72c build(deps): bump anyio, autobahn, setuptools for security advisories
  • d43a29f test(experimentation): assert consumer line counts in main thread
  • 96afe01 fix(shutdown): stop latching AppStatus.should_exit from uvicorn state
  • See full diff in compare view

Updates starlette from 1.6.0 to 1.7.0

Release notes

Sourced from starlette's releases.

Version 1.7.0

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING] OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

Description has been truncated

…pdates

Bumps the ci-toolchain group with 13 updates in the /requirements directory:

| Package | From | To |
| --- | --- | --- |
| [hatchling](https://github.com/pypa/hatch) | `1.32.0` | `1.32.4` |
| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.16.1` | `7.16.2` |
| [blake3](https://github.com/oconnor663/blake3-py) | `1.0.9` | `1.0.10` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.141.1` | `0.142.1` |
| [httpcore2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.1` |
| [httpx2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.1` |
| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.44.0` | `1.45.0` |
| [sse-starlette](https://github.com/sysid/sse-starlette) | `3.4.11` | `3.5.0` |
| [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.53.0` | `0.54.0` |
| [watchfiles](https://github.com/samuelcolvin/watchfiles) | `1.2.0` | `1.3.0` |
| [cyclonedx-bom](https://github.com/CycloneDX/cyclonedx-python) | `7.3.0` | `7.5.0` |



Updates `hatchling` from 1.32.0 to 1.32.4
- [Release notes](https://github.com/pypa/hatch/releases)
- [Commits](pypa/hatch@hatchling-v1.32.0...hatchling-v1.32.4)

Updates `idna` from 3.19 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.19...v3.20)

Updates `coverage` from 7.16.1 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.1...7.16.2)

Updates `blake3` from 1.0.9 to 1.0.10
- [Release notes](https://github.com/oconnor663/blake3-py/releases)
- [Changelog](https://github.com/oconnor663/blake3-py/blob/master/release.md)
- [Commits](oconnor663/blake3-py@1.0.9...1.0.10)

Updates `fastapi` from 0.141.1 to 0.142.1
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.141.1...0.142.1)

Updates `httpcore2` from 2.12.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Commits](pydantic/httpx2@v2.12.0...v2.13.1)

Updates `httpx2` from 2.12.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](pydantic/httpx2@v2.12.0...v2.13.1)

Updates `opentelemetry-api` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `sse-starlette` from 3.4.11 to 3.5.0
- [Release notes](https://github.com/sysid/sse-starlette/releases)
- [Commits](sysid/sse-starlette@v3.4.11...v3.5.0)

Updates `starlette` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.6.0...1.7.0)

Updates `uvicorn` from 0.53.0 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.53.0...0.54.0)

Updates `watchfiles` from 1.2.0 to 1.3.0
- [Release notes](https://github.com/samuelcolvin/watchfiles/releases)
- [Commits](samuelcolvin/watchfiles@v1.2.0...v1.3.0)

Updates `cyclonedx-bom` from 7.3.0 to 7.5.0
- [Release notes](https://github.com/CycloneDX/cyclonedx-python/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-python/blob/main/CHANGELOG.md)
- [Commits](CycloneDX/cyclonedx-python@v7.3.0...v7.5.0)

---
updated-dependencies:
- dependency-name: hatchling
  dependency-version: 1.32.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-toolchain
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-toolchain
- dependency-name: blake3
  dependency-version: 1.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-toolchain
- dependency-name: fastapi
  dependency-version: 0.142.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: httpcore2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: httpx2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: opentelemetry-api
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: sse-starlette
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: watchfiles
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
- dependency-name: cyclonedx-bom
  dependency-version: 7.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-toolchain
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 3, 2026
@dependabot
dependabot Bot requested a review from Brad-Edwards as a code owner October 3, 2026 03:43
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 3, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 4, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/requirements/dev/ci-toolchain-7f48d028da branch October 4, 2026 02:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants