Skip to content

chore(deps): bump the python-minor-and-patch group across 1 directory with 27 updates - #1494

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/uv/shifter/shifter_platform/dev/python-minor-and-patch-cddf2d2e85
Open

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/uv/shifter/shifter_platform/dev/python-minor-and-patch-cddf2d2e85

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-minor-and-patch group with 27 updates in the /shifter/shifter_platform directory:

Package From To
asyncssh 2.23.0 2.24.0
boto3 1.43.2 1.43.98
daphne 4.2.1 4.2.3
django 6.0.6 6.1.1
django-anymail 15.0 15.2
django-ses 4.7.2 4.8.0
djangorestframework 3.17.1 3.18.1
drf-spectacular 0.29.0 0.30.0
drf-spectacular-sidecar 2026.6.1 2026.9.1
firebase-admin 7.4.0 7.6.0
markdown 3.10.2 3.10.3
pycurl 7.46.0 7.48.0
pydantic 2.13.4 2.13.5
python-dotenv 1.2.2 1.2.3
regex 2026.6.28 2026.9.10
requests 2.33.1 2.34.2
import-linter 2.11 2.15
pytest 9.0.3 9.1.1
pytest-django 4.12.0 4.14.0
ruff 0.15.13 0.16.8
pre-commit 4.6.0 4.6.2
pytest-asyncio 1.3.0 1.4.0
mypy 2.1.0 2.3.1
django-stubs 6.0.4 6.1.1
types-bleach 6.3.0.20260508 6.4.0.20260728
google-auth 2.50.0 2.58.0
google-cloud-storage 3.10.1 3.14.1

Updates asyncssh from 2.23.0 to 2.24.0

Changelog

Sourced from asyncssh's changelog.

Release 2.24.0 (27 Jun 2026)

  • Added support for creating and validating SSHSIG signatures, as well as OpenSSH "allowed signers" files.

  • Added support for ML-KEM key exchange from the PyCA cryptography package when it is available. This avoids the need to have the liboqs library installed to use ML-KEM. However, liboqs is still required to support SNTRUP kex exchange.

  • Fixed an issue with handling of SSH maximum packet size when opening a new SSH channel, aborting with a protocol error if a peer attempts to set this size to 0. Thanks go to GitHub user afldl for reporting this issue and providing analysis and reproduction code.

  • Fixed an issue with include directives in OpenSSH config files. Thanks go to GitHub users sethholmes and tazle for reporting this issue and providing analysis and a proposed fix.

Release 2.23.1 (6 Jun 2026)

  • Fixed an SCP path traversal issue. Thanks go to Jaden Furtado for reporting this issue.

  • Expanded previous fix to block unsafe user substitutions in server config. Thanks go to GitHub user cesabici-bit for reporting this issue.

  • Fixed default value for reuse_address and reuse_port, matching the behaavior of asyncio.create_server(). Thanks go to Alexander Shlemin for reporting the inconsistency.

Commits
  • 3577224 Bump version number up to 2.24.0 and update change log
  • 321588d Avoid a coverage issue on a protocol definition
  • eefa2fa Update the documentation to list supported SSHSIG options
  • 9c35427 Add input validation on maximum packet size
  • c3ab96f Remove unused import
  • b3039b2 Bump cryptography from 2.8 to 48.0.1 in /docs
  • 9ef998c Bump cryptography min version to pick up security vulnerability fix
  • d1caa62 Add support for ML-KEM implementation in PyCA
  • c0d349b Fix an issue with include directives in SSH confid files
  • 87c58b2 Add support for creating and validating SSHSIG format signatures
  • Additional commits viewable in compare view

Updates boto3 from 1.43.2 to 1.43.98

Commits
  • 3314d84 Merge branch 'release-1.43.98'
  • 3a3637f Bumping version to 1.43.98
  • d802350 Add changelog entries from botocore
  • ed7de96 Merge branch 'release-1.43.97'
  • fba1e41 Merge branch 'release-1.43.97' into develop
  • 275709c Bumping version to 1.43.97
  • a5c0088 Add changelog entries from botocore
  • 2be9967 Merge branch 'release-1.43.96'
  • bc62489 Merge branch 'release-1.43.96' into develop
  • 6e1774a Bumping version to 1.43.96
  • Additional commits viewable in compare view

Updates daphne from 4.2.1 to 4.2.3

Changelog

Sourced from daphne's changelog.

4.2.3 (2026-07-21)

  • Added --websocket-max-message-size and --websocket-max-frame-size CLI flags to the runserver management command for use in development.

4.2.2 (2026-06-03)

  • Fixed a denial of service vulnerability via unbounded WebSocket message sizes. Daphne previously passed no message or frame size limits to autobahn, whose defaults are unbounded. This allowed an unauthenticated client to exhaust server memory by sending a very large WebSocket messages/frames (CVE-2026-44545).

    Both limits now default to 1 MiB and can be configured via the new --websocket-max-message-size and --websocket-max-frame-size CLI flags (or the matching Server constructor arguments). Pass 0 to restore the previous unlimited behaviour.

    Thanks to ParkHyunWoo for the report.

  • Fixed a header injection vulnerability on the WebSocket upgrade path (CVE-2026-44546).

    Header values containing \x0b, \x0c, \x1c, \x1d, \x1e, or \x85 were parsed as a single header by Twisted but split into multiple headers by autobahn during the WebSocket handshake. An attacker could exploit this parser differential to smuggle additional headers (e.g. authentication tokens, X-Forwarded-For, Origin, Daphne-Root-Path) into the ASGI scope passed to the application.

    Daphne now rejects requests carrying these bytes in any header value with a 400 Bad Request response, as required by RFC 9110 §5.5.

    Thanks to Rene Henningsen for the report.

Commits

Updates django from 6.0.6 to 6.1.1

Commits
  • 249b13d [6.1.x] Bumped version for 6.1.1 release.
  • 5f26fa8 [6.1.x] Added release date for 6.1.1.
  • fdcf78a [6.1.x] Added remaining community package mentions to the documentation.
  • 7241568 [6.1.x] Fixed #37222 -- Fixed QuerySet.distinct() crash on duplicated selecti...
  • ef3fc80 [6.1.x] Fixed #37312, Refs #36605 -- Fixed annotation preservation and key se...
  • b09cb6b [6.1.x] Clarified scope of object-level admin view permissions.
  • a6d3aa2 [6.1.x] Corrected heading hierarchy in the admin actions documentation.
  • 9031d41 [6.1.x] Clarified object-level permission checks in admin actions.
  • fc805c6 [6.1.x] Fixed #37311 -- Prevented consumption of rhs iterators in annotation ...
  • 4b0185a [6.1.x] Fixed #37300 -- Preserved parent instance hints on custom Prefetch qu...
  • Additional commits viewable in compare view

Updates django-anymail from 15.0 to 15.2

Release notes

Sourced from django-anymail's releases.

v15.2

Changelog

v15.1

Changelog

Changelog

Sourced from django-anymail's changelog.

v15.2

2026-09-05

Features


* **Amazon SES:** Add support for inbound messages using S3 encryption.
  This requires the :pypi:`amazon-s3-encryption-client-python` package, which
  is now included when installing with the ``django-anymail[amazon-ses]`` extra.
  • Amazon SES: When using the S3 receipt action for inbound email, large messages are now downloaded and parsed incrementally to reduce memory usage.

  • Mailtrap: Support signature verification for tracking event webhooks.

  • Mailtrap: Add support for inbound email. See docs <https://anymail.dev/en/stable/esps/mailtrap/#inbound-webhook>.

  • Postmark: Add support for Postmark's bulk API. See Using Postmark's bulk API <https://anymail.dev/en/stable/esps/postmark/#using-postmark-s-bulk-api>_.

  • Postmark: Add POSTMARK_MESSAGE_STREAM option to specify the id of the Postmark message stream used for sending. With Django 6.1 MAILERS you can use a different message_stream for each configured mailer.

  • Resend: Large inbound messages are now downloaded and parsed incrementally to reduce memory usage.

Fixes


* **Amazon SES:** Avoid a Python bug that could corrupt images and attachments
  in inbound messages.
  • Inbound: AnymailInboundMessage's text and html attributes
    and get_content_text() method now normalize line endings to \n.
    In earlier releases, either \n or \r\n could be returned,
    inconsistently and somewhat unpredictably.

v15.1

2026-07-30

Fixes

</tr></table>

... (truncated)

Commits
  • 81c6505 Release 15.2
  • 8ce3aca Mailgun: Stop polling event API in integration tests
  • d3c121c Resend: Stream inbound messages
  • 9ab940e Mailtrap: Make inbound download chunk size configurable
  • 8540841 Remove unused AnymailInboundMessage.parse_raw_mime_file()
  • 05dd35a Amazon SES: Stream inbound messages from S3
  • d8b4593 Inbound: Normalize line endings on text parts
  • aef5d9d Brevo: Update quirks documentation for HTML body
  • bc8d362 Mailtrap: Make inbound work with example payload
  • 7bc9520 Amazon SES: Support inbound S3 encryption
  • Additional commits viewable in compare view

Updates django-ses from 4.7.2 to 4.8.0

Release notes

Sourced from django-ses's releases.

v4.8.0

What's Changed

New Contributors

Full Changelog: django-ses/django-ses@v4.7.2...v4.8.0

Changelog

Sourced from django-ses's changelog.

Change Log

For a list of releases, see: https://github.com/django-ses/django-ses/releases/

Upcoming (dev)

The following changes are not yet released, but are code complete:

Pulls and Issues:

  • None

Features:

  • None

Changes:

  • None

Deprecations:

  • None

Fixes:

  • None

Current

4.8.0

Add support for Django 6.1, including use as a MAILERS backend.

SESBackend no longer forwards fail_silently to BaseEmailBackend.__init__(). Django 6.1 removed that argument: forwarding it raised InvalidMailer when the backend was instantiated from a MAILERS alias, and emitted a RemovedInDjango70Warning otherwise.

Pulls:

Past

4.7.2

Handle bounce with bounceType when status is missing

Pulls:

... (truncated)

Commits
  • f3e10d5 Update changelog, bump minor
  • bfabcbd Add Django 6.1 support, including use as a MAILERS backend (#376)
  • f49e897 Bump idna from 3.11 to 3.15 (#375)
  • 8bbe73d Fix LocalStack CI; align Poetry Django bounds with tox matrix (#374)
  • efbdc70 Update pyproject.toml, default python to 3.14 (#372)
  • See full diff in compare view

Updates djangorestframework from 3.17.1 to 3.18.1

Release notes

Sourced from djangorestframework's releases.

3.18.1

What's Changed

Bug fixes

Other changes

New Contributors

Full Changelog: encode/django-rest-framework@3.18.0...3.18.1

3.18.0

What's Changed

Breaking changes

Features

Bug fixes

Other changes

New Contributors

... (truncated)

Commits
  • dd23495 Prepare release 3.18.1 (#10036)
  • cb1fb66 Install gettext in prepare-release
  • 858f1fc Reject non-finite values (nan, inf) in FloatField (#9998)
  • ea695cd Ensure translations are up to date when preparing release
  • 0406c6e Update pygments requirement from >=2.17,<2.21 to ==2.21.* in the optional gro...
  • 8c92e89 Expand deprecation classes and review deprecation policy (#10034)
  • 3157a6a Update pytest config to native TOML format from v9 (#10035)
  • 4f77428 Fixing issue #9484 (#10033)
  • f17d70f Fix int64 format detection for negative IntegerField minimums in Open API s...
  • 5668281 Add a compatibility setting for ListSerializer error formats (#10027)
  • Additional commits viewable in compare view

Updates drf-spectacular from 0.29.0 to 0.30.0

Release notes

Sourced from drf-spectacular's releases.

0.30.0

After working through the backlog for several week, we are finally in a comfortable place again. Thank you to all contributors and users that waited patiently for me the catch up. It does not include all the PRs that were opened, but imho the most critical ones.

This release includes many small improvement, a few bug fixes, updates to the test suite and a renovated test matrix. Some minor schema corrections are to be expected, but nothing drastic. It is mostly fixing small inconsistencies and improving corner cases.

What's Changed

New Contributors

Full Changelog: tfranzel/drf-spectacular@0.29.0...0.30.0

Changelog

Sourced from drf-spectacular's changelog.

0.30.0 (2026-07-06)

  • Add OAS 3.2 schema for validation & test
  • Type hint build_bearer_security_scheme_object ([#1509](https://github.com/tfranzel/drf-spectacular/issues/1509) <https://github.com/tfranzel/drf-spectacular/issues/1509>_) [johnthagen]
  • Fix formatted CharField allow_blank handling ([#1511](https://github.com/tfranzel/drf-spectacular/issues/1511) <https://github.com/tfranzel/drf-spectacular/issues/1511>, ([#1499](https://github.com/tfranzel/drf-spectacular/issues/1499) <https://github.com/tfranzel/drf-spectacular/issues/1499>)) [Luciano de la Iglesia]
  • Consider allOf anyOf with nullable on OAS3.1 [#1480](https://github.com/tfranzel/drf-spectacular/issues/1480) <https://github.com/tfranzel/drf-spectacular/issues/1480>_
  • Proper handling for OAS 3.2
  • fix modification of user-provided schematas [#1500](https://github.com/tfranzel/drf-spectacular/issues/1500) <https://github.com/tfranzel/drf-spectacular/issues/1500>_
  • relax contraint on oneOf null case with OAS3.1 [#1480](https://github.com/tfranzel/drf-spectacular/issues/1480) <https://github.com/tfranzel/drf-spectacular/issues/1480>_
  • Add blueprint for django-rest-knox ([#1506](https://github.com/tfranzel/drf-spectacular/issues/1506) <https://github.com/tfranzel/drf-spectacular/issues/1506>_) [johnthagen]
  • Mitigate GeneratedField lost arguments and special case for DecimalField [#1166](https://github.com/tfranzel/drf-spectacular/issues/1166) <https://github.com/tfranzel/drf-spectacular/issues/1166>_
  • Webhook explicit operationId ([#1505](https://github.com/tfranzel/drf-spectacular/issues/1505) <https://github.com/tfranzel/drf-spectacular/issues/1505>_)
  • change conflicting license field for 3.8 ([#1504](https://github.com/tfranzel/drf-spectacular/issues/1504) <https://github.com/tfranzel/drf-spectacular/issues/1504>_)
  • Document django-rest-knox support [johnthagen]
  • add help text to spectacular management command arguments [#1175](https://github.com/tfranzel/drf-spectacular/issues/1175) <https://github.com/tfranzel/drf-spectacular/issues/1175>_ [Jean-Baptiste Braun]
  • Mark FileField as nullable in response when not required [#1493](https://github.com/tfranzel/drf-spectacular/issues/1493) <https://github.com/tfranzel/drf-spectacular/issues/1493>_ [mojtaba sohrabi]
  • Extend Choices hint fix with generated label description [#1486](https://github.com/tfranzel/drf-spectacular/issues/1486) <https://github.com/tfranzel/drf-spectacular/issues/1486>_
  • Suppress py<=3.14 deprecation warning [#1497](https://github.com/tfranzel/drf-spectacular/issues/1497) <https://github.com/tfranzel/drf-spectacular/issues/1497>_
  • Remove ancient DRF3.11 and Django2.2 due to contrib packages failing
  • feat: add support for django 6.0 and and drf 3.17 [Vjeran Grozdanic]
  • Add setting to disable docstring extraction [Phil Starkey]
  • feat: add support for polymorphic built-in drf support [Benedikt Bauer]
  • Clarifies post-processing hooks [Andy Piltser-Cowan]
  • Clarifies customizations step 5 [Andy Piltser-Cowan]
  • Fix dependency definition for Django 5.2 [Ülgen Sarıkavak]
  • Implement x-spec-enum-id for type hint Choices. [Noam Kushinsky]
  • Add Support for unsigned integers uint16, uint32 and uint64 [Nicolas Delaby]
  • Fix regression introduced in [#1450](https://github.com/tfranzel/drf-spectacular/issues/1450) <https://github.com/tfranzel/drf-spectacular/issues/1450>_ ([#1469](https://github.com/tfranzel/drf-spectacular/issues/1469) <https://github.com/tfranzel/drf-spectacular/issues/1469>_) [Oleg Höfling]

Breaking changes / important additions:

  • Many small improvement, bug fixes, updates to the test suite and renovated test matrix. Some minor schema corrections are to be expected, but nothing drastic.
Commits

Updates drf-spectacular-sidecar from 2026.6.1 to 2026.9.1

Commits

Updates firebase-admin from 7.4.0 to 7.6.0

Release notes

Sourced from firebase-admin's releases.

Firebase Admin Python SDK v7.6.0

New Features

  • feat(appcheck): Verify one-time tokens for replay protection (#976)
  • feat(ml): deprecate Machine Learning APIs (#981)

Miscellaneous

  • [chore] Release 7.6.0 (#985)
  • chore(ml): Skip flaky ML tests blocking nightly builds (#979)
  • update GitHub Actions to Node 24 versions (#974)
  • chore(ci): Fix zizmor security findings in workflows (#956)

Firebase Admin Python SDK v7.5.0

New Features

  • feat(fcm): Enable fid and deprecate token for Send API (#951)

Bug Fixes

  • fix(deps): Added universe_domain override to MockGoogleComputeEngineCredential (#954)

Miscellaneous

  • [chore] Release 7.5.0 (#958)
  • chore(deps): update pytest-mock requirement from >=3.6.1 to >=3.15.1 (#959)
  • chore(deps): update pytest-localserver requirement (#961)
  • chore(deps): update pytest requirement from >=8.2.2 to >=8.4.2 (#946)
  • chore(deps): update google-cloud-firestore requirement (#947)
  • chore(deps): update pyjwt requirement from >=2.10.1 to >=2.12.1 (#948)
  • chore: Pinned cryptography version for older PyPy interpreters (#952)
Commits
  • cbacb02 [chore] Release 7.6.0 (#985)
  • 2ef3414 feat(appcheck): Verify one-time tokens for replay protection (#976)
  • a7aafa2 feat(ml): deprecate Machine Learning APIs (#981)
  • eba8fa0 chore(ml): Skip flaky ML tests blocking nightly builds (#979)
  • 62e559b update GitHub Actions to Node 24 versions (#974)
  • b40e738 chore(ci): Fix zizmor security findings in workflows (#956)
  • c5e66f8 [chore] Release 7.5.0 (#958)
  • 0656dc2 chore(deps): update pytest-mock requirement from >=3.6.1 to >=3.15.1 (#959)
  • a013e56 chore(deps): update pytest-localserver requirement (#961)
  • 6d3fc8e chore(deps): update pytest requirement from >=8.2.2 to >=8.4.2 (#946)
  • Additional commits viewable in compare view

Updates markdown from 3.10.2 to 3.10.3

Release notes

Sourced from markdown's releases.

Release 3.10.3

Fixed

  • Fix SetextHeaderProcessor regex to prevent mixed = and - chars in setext-style headers (#1606).
  • Add AI Policy to Contributing Guide.
  • Officially document all included extensions as being in maintenance mode.
  • Link the Extension API documentation to the API Reference (#1612).
Changelog

Sourced from markdown's changelog.

[3.10.3] - 2026-07-30

Fixed

  • Fix SetextHeaderProcessor regex to prevent mixed = and - chars in setext-style headers (#1606).
  • Add AI Policy to Contributing Guide.
  • Officially document all included extensions as being in maintenance mode.
  • Link the Extension API documentation to the API Reference (#1612).
Commits
  • bb50627 Bump version to 3.10.3
  • 8453df0 Update Extension API documentation
  • 93ac448 Document that all extensions are in maintenance mode
  • d38fd4a Create AI Policy
  • ddead47 Prevent mixed =/- chars in Setext-style headings
  • See full diff in compare view

Updates pycurl from 7.46.0 to 7.48.0

Release notes

Sourced from pycurl's releases.

PycURL 7.48.0

Changes in this release:

  • Expose more CURLOPT_SSL_OPTIONS (patch by Scott Talbert)
  • Read long description from README.rst instead of duplicating it in setup.py (patch by Scott Talbert)
  • Fix test_redir_protocols_setopt (patch by Scott Talbert)
  • Add CURL_LOCK_DATA_HSTS as a CurlShare option (patch by Scott Talbert)
  • Add libpsl support to vcpkg installs for CI and wheel builds (patch by Scott Talbert)
  • Configure nuget repo access as read-only from PRs (patch by Scott Talbert)
  • Officially change project URL to https://pycurl.github.io/ (patch by Scott Talbert)
  • Replace bare except clauses in examples with specific exception types (patch by Kotesh Kumar Yelamati)
  • Add HTTP/3 support in libcurl wheel (patch by Will Noble)
  • Fix segfault when calling duphandle() on a closed Curl handle (patch by Jorge Rocamora)
  • Fix abort on non-text string arguments (patch by Jorge Rocamora)
  • Fix CurlShare leak when close() detaches attached handles (patch by Jorge Rocamora)
  • Document that views derived from the callback memoryview are not released (patch by Jorge Rocamora)
  • Fix crash when duplicating a handle that uses set_ca_certs() (patch by Jorge Rocamora)
  • Add CurlUrl object wrapping libcurl's URL API, with CURLOPT_CURLU support (patch by Jorge Rocamora)
  • Fix callback exceptions being replaced by SystemError (patch by Jorge Rocamora)
  • Fix test guard silently passing on real libcurl errors (patch by Jorge Rocamora)
  • Update the docstring and manifest source lists (patch by Jorge Rocamora)
  • Refuse pause() from a thread other than the performing one (patch by Jorge Rocamora)
  • Add support for Python 3.15 (patch by Scott Talbert)
  • Refuse integers for blob options instead of crashing (patch by Jorge Rocamora)
  • Accept buffer objects for blob options (patch by Jorge Rocamora)
  • Release all httppost encoded values and unset the form before MIMEPOST (patch by Jorge Rocamora)
  • Reject callback return values that do not fit in an int (patch by Jorge Rocamora)
  • Clear CurlMulti callbacks before deallocating attached handles (patch by Eric Buehl)
  • Serve the test apps from a threaded WSGI server (patch by Jorge Rocamora)
  • Add support for missing CURL options (patch by Khavish Anshudass Bhundoo)
  • Add CURLOPT_SSL_EC_CURVES & CURLOPT_SSL_SIGNATURE_ALGORITHMS options (patch by Khavish Anshudass Bhundoo)
  • Remove unused variable from do_curl_setopt_httppost (patch by Scott Talbert)
  • test: silence WSGI test server access logging to stderr (patch by Scott Talbert)
  • test: pin down oversized mime data_cb error assertions (patch by Scott Talbert)
  • Give vendored OpenSSL a private OPENSSLDIR on Linux manylinux wheels (patch by Scott Talbert)
  • Enable -Werror for the pycurl build in cibuildwheel without affecting vcpkg (patch by Scott Talbert)
  • Handle libcurl options deprecated in 8.22.0 (patch by Scott Talbert)

PycURL 7.47.0

What's Changed

Other changes

  • Use dynamic SSL ports in certificate tests (patch by Jorge Rocamora)
  • Harden test_clear_assignment_inside_socket_callback_resets_socketp test (patch by Jorge Rocamora)
  • Rename index field to idx in HstsIndex to avoid shadowing (patch by Jorge Rocamora)
  • Fix test_callbacks_non_minus_one_return_continues_transfer on macOS (patch by Jorge Rocamora)
  • Use PYCURL_REQUIRE_HANDLE and PYCURL_REQUIRE_NOT_RUNNING instead of magic numbers (patch by Jorge Rocamora)
  • Convert pycurl to a Python package with the C extension renamed to pycurl._pycurl (patch by Jorge Rocamora)
  • Fix flaky CONNECT_ONLY send/recv tests by waiting on active socket readiness instead of sleeping after EAGAIN (#997) (patch by Jorge Rocamora)
  • Add PyMutex support on Python 3.13+ (patch by Jorge Rocamora)

... (truncated)

Changelog

Sourced from pycurl's changelog.

Version 7.48.0 [requires libcurl-7.19.0 or better] - 2026-09-15

    * Expose more CURLOPT_SSL_OPTIONS (patch by Scott Talbert)
    * Read long description from README.rst instead of duplicating it in setup.py (patch by Scott Talbert)
    * Fix test_redir_protocols_setopt (patch by Scott Talbert)
    * Add CURL_LOCK_DATA_HSTS as a CurlShare option (patch by Scott Talbert)
    * Add libpsl support to vcpkg installs for CI and wheel builds (patch by Scott Talbert)
    * Configure nuget repo access as read-only from PRs (patch by Scott Talbert)
    * Officially change project URL to https://pycurl.github.io/ (patch by Scott Talbert)
    * Replace bare except clauses in examples with specific exception types (patch by Kotesh Kumar Yelamati)
    * Add HTTP/3 support in libcurl wheel (patch by Will Noble)
    * Fix segfault when calling duphandle() on a closed Curl handle (patch by Jorge Rocamora)
    * Fix abort on non-text string arguments (patch by Jorge Rocamora)
    * Fix CurlShare leak when close() detaches attached handles (patch by Jorge Rocamora)
    * Document that views derived from the callback memoryview are not released (patch by Jorge Rocamora)
    * Fix crash when duplicating a handle that uses set_ca_certs() (patch by Jorge Rocamora)
    * Add CurlUrl object wrapping libcurl's URL API, with CURLOPT_CURLU support (patch by Jorge Rocamora)
    * Fix callback exceptions being replaced by SystemError (patch by Jorge Rocamora)
    * Fix test guard silently passing on real libcurl errors (patch by Jorge Rocamora)
    * Update the docstring and manifest source lists (patch by Jorge Rocamora)
    * Refuse pause() from a thread other than the performing one (patch by Jorge Rocamora)
    * Add support for Python 3.15 (patch by Scott Talbert)
    * Refuse integers for blob options instead of crashing (patch by Jorge Rocamora)
    * Accept buffer objects for blob options (patch by Jorge Rocamora)
    * Release all httppost encoded values and unset the form before MIMEPOST (patch by Jorge Rocamora)
    * Reject callback return values that do not fit in an int (patch by Jorge Rocamora)
    * Clear CurlMulti callbacks before deallocating attached handles (patch by Eric Buehl)
    * Serve the test apps from a threaded WSGI server (patch by Jorge Rocamora)
    * Add support for missing CURL options (patch by Khavish Anshudass Bhundoo)
    * Add CURLOPT_SSL_EC_CURVES & CURLOPT_SSL_SIGNATURE_ALGORITHMS options (patch by Khavish A...

Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/shifter/shifter_platform/dev/python-minor-and-patch-cddf2d2e85 branch from 22a5a64 to bb0e4f3 Compare September 16, 2026 22:07
… with 27 updates

Bumps the python-minor-and-patch group with 27 updates in the /shifter/shifter_platform directory:

| Package | From | To |
| --- | --- | --- |
| [asyncssh](https://github.com/ronf/asyncssh) | `2.23.0` | `2.24.0` |
| [boto3](https://github.com/boto/boto3) | `1.43.2` | `1.43.98` |
| [daphne](https://github.com/django/daphne) | `4.2.1` | `4.2.3` |
| [django](https://github.com/django/django) | `6.0.6` | `6.1.1` |
| [django-anymail](https://github.com/anymail/django-anymail) | `15.0` | `15.2` |
| [django-ses](https://github.com/django-ses/django-ses) | `4.7.2` | `4.8.0` |
| [djangorestframework](https://github.com/encode/django-rest-framework) | `3.17.1` | `3.18.1` |
| [drf-spectacular](https://github.com/tfranzel/drf-spectacular) | `0.29.0` | `0.30.0` |
| [drf-spectacular-sidecar](https://github.com/tfranzel/drf-spectacular-sidecar) | `2026.6.1` | `2026.9.1` |
| [firebase-admin](https://github.com/firebase/firebase-admin-python) | `7.4.0` | `7.6.0` |
| [markdown](https://github.com/Python-Markdown/markdown) | `3.10.2` | `3.10.3` |
| [pycurl](https://github.com/pycurl/pycurl) | `7.46.0` | `7.48.0` |
| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |
| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.6.28` | `2026.9.10` |
| [requests](https://github.com/psf/requests) | `2.33.1` | `2.34.2` |
| [import-linter](https://github.com/seddonym/import-linter) | `2.11` | `2.15` |
| [pytest](https://github.com/pytest-dev/pytest) | `9.0.3` | `9.1.1` |
| [pytest-django](https://github.com/pytest-dev/pytest-django) | `4.12.0` | `4.14.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.13` | `0.16.8` |
| [pre-commit](https://github.com/pre-commit/pre-commit) | `4.6.0` | `4.6.2` |
| [pytest-asyncio](https://github.com/pytest-dev/pytest-asyncio) | `1.3.0` | `1.4.0` |
| [mypy](https://github.com/python/mypy) | `2.1.0` | `2.3.1` |
| [django-stubs](https://github.com/typeddjango/django-stubs) | `6.0.4` | `6.1.1` |
| [types-bleach](https://github.com/python/typeshed) | `6.3.0.20260508` | `6.4.0.20260728` |
| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.50.0` | `2.58.0` |
| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.10.1` | `3.14.1` |



Updates `asyncssh` from 2.23.0 to 2.24.0
- [Changelog](https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst)
- [Commits](ronf/asyncssh@v2.23.0...v2.24.0)

Updates `boto3` from 1.43.2 to 1.43.98
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.2...1.43.98)

Updates `daphne` from 4.2.1 to 4.2.3
- [Changelog](https://github.com/django/daphne/blob/main/CHANGELOG.txt)
- [Commits](django/daphne@4.2.1...4.2.3)

Updates `django` from 6.0.6 to 6.1.1
- [Commits](django/django@6.0.6...6.1.1)

Updates `django-anymail` from 15.0 to 15.2
- [Release notes](https://github.com/anymail/django-anymail/releases)
- [Changelog](https://github.com/anymail/django-anymail/blob/main/CHANGELOG.rst)
- [Commits](anymail/django-anymail@v15.0...v15.2)

Updates `django-ses` from 4.7.2 to 4.8.0
- [Release notes](https://github.com/django-ses/django-ses/releases)
- [Changelog](https://github.com/django-ses/django-ses/blob/main/CHANGES.md)
- [Commits](django-ses/django-ses@v4.7.2...v4.8.0)

Updates `djangorestframework` from 3.17.1 to 3.18.1
- [Release notes](https://github.com/encode/django-rest-framework/releases)
- [Commits](encode/django-rest-framework@3.17.1...3.18.1)

Updates `drf-spectacular` from 0.29.0 to 0.30.0
- [Release notes](https://github.com/tfranzel/drf-spectacular/releases)
- [Changelog](https://github.com/tfranzel/drf-spectacular/blob/master/CHANGELOG.rst)
- [Commits](tfranzel/drf-spectacular@0.29.0...0.30.0)

Updates `drf-spectacular-sidecar` from 2026.6.1 to 2026.9.1
- [Commits](tfranzel/drf-spectacular-sidecar@2026.6.1...2026.9.1)

Updates `firebase-admin` from 7.4.0 to 7.6.0
- [Release notes](https://github.com/firebase/firebase-admin-python/releases)
- [Commits](firebase/firebase-admin-python@v7.4.0...v7.6.0)

Updates `markdown` from 3.10.2 to 3.10.3
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](Python-Markdown/markdown@3.10.2...3.10.3)

Updates `pycurl` from 7.46.0 to 7.48.0
- [Release notes](https://github.com/pycurl/pycurl/releases)
- [Changelog](https://github.com/pycurl/pycurl/blob/master/ChangeLog)
- [Commits](https://github.com/pycurl/pycurl/commits/v7.48.0)

Updates `pydantic` from 2.13.4 to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.13.4...v2.13.5)

Updates `python-dotenv` from 1.2.2 to 1.2.3
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.2...v1.2.3)

Updates `regex` from 2026.6.28 to 2026.9.10
- [Changelog](https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt)
- [Commits](mrabarnett/mrab-regex@2026.6.28...2026.9.10)

Updates `requests` from 2.33.1 to 2.34.2
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.33.1...v2.34.2)

Updates `import-linter` from 2.11 to 2.15
- [Changelog](https://github.com/seddonym/import-linter/blob/main/docs/release_notes.md)
- [Commits](seddonym/import-linter@v2.11...v2.15)

Updates `pytest` from 9.0.3 to 9.1.1
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest@9.0.3...9.1.1)

Updates `pytest-django` from 4.12.0 to 4.14.0
- [Release notes](https://github.com/pytest-dev/pytest-django/releases)
- [Changelog](https://github.com/pytest-dev/pytest-django/blob/main/docs/changelog.rst)
- [Commits](pytest-dev/pytest-django@v4.12.0...v4.14.0)

Updates `ruff` from 0.15.13 to 0.16.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.13...0.16.8)

Updates `pre-commit` from 4.6.0 to 4.6.2
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md)
- [Commits](pre-commit/pre-commit@v4.6.0...v4.6.2)

Updates `pytest-asyncio` from 1.3.0 to 1.4.0
- [Release notes](https://github.com/pytest-dev/pytest-asyncio/releases)
- [Commits](pytest-dev/pytest-asyncio@v1.3.0...v1.4.0)

Updates `mypy` from 2.1.0 to 2.3.1
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v2.1.0...v2.3.1)

Updates `django-stubs` from 6.0.4 to 6.1.1
- [Release notes](https://github.com/typeddjango/django-stubs/releases)
- [Commits](typeddjango/django-stubs@6.0.4...6.1.1)

Updates `types-bleach` from 6.3.0.20260508 to 6.4.0.20260728
- [Commits](https://github.com/python/typeshed/commits)

Updates `google-auth` from 2.50.0 to 2.58.0
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](googleapis/google-cloud-python@google-auth-v2.50.0...google-auth-v2.58.0)

Updates `google-cloud-storage` from 3.10.1 to 3.14.1
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](googleapis/google-cloud-python@google-cloud-storage-v3.10.1...google-cloud-storage-v3.14.1)

---
updated-dependencies:
- dependency-name: asyncssh
  dependency-version: 2.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: boto3
  dependency-version: 1.43.89
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: daphne
  dependency-version: 4.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: django
  dependency-version: 6.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: django-anymail
  dependency-version: '15.1'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: django-ses
  dependency-version: 4.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: django-stubs
  dependency-version: 6.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: djangorestframework
  dependency-version: 3.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: drf-spectacular
  dependency-version: 0.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: drf-spectacular-sidecar
  dependency-version: 2026.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: firebase-admin
  dependency-version: 7.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: google-auth
  dependency-version: 2.57.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: google-cloud-storage
  dependency-version: 3.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: import-linter
  dependency-version: '2.15'
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: markdown
  dependency-version: 3.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: mypy
  dependency-version: 2.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: pre-commit
  dependency-version: 4.6.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: pycurl
  dependency-version: 7.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: pytest
  dependency-version: 9.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: pytest-asyncio
  dependency-version: 1.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: pytest-django
  dependency-version: 4.14.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: python-dotenv
  dependency-version: 1.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: regex
  dependency-version: 2026.9.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: requests
  dependency-version: 2.34.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: ruff
  dependency-version: 0.16.6
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: types-bleach
  dependency-version: 6.4.0.20260728
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/shifter/shifter_platform/dev/python-minor-and-patch-cddf2d2e85 branch from bb0e4f3 to 2a76670 Compare September 21, 2026 21:43

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants