Skip to content

deps(pip): bump the pip-major group across 1 directory with 10 updates - #3252

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pip-major-022e3118b5
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pip-major-022e3118b5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the pip-major group with 10 updates in the / directory:

Package From To
rich 14.3.4 15.0.0
mcp 1.28.1 2.2.0
anthropic 0.116.0 1.8.0
filelock 3.29.7 4.0.5
huggingface-hub 1.23.0 2.0.0
importlib-metadata 8.9.0 9.0.1
multidict 6.7.1 7.0.0
openai 2.41.1 3.19.2
textual 7.5.0 8.2.8
websockets 16.1 16.1.1

Updates rich from 14.3.4 to 15.0.0

Release notes

Sourced from rich's releases.

The So Long 3.8 Release

A few fixes. The major version bump is to honor the passing of 3.8 support which reached its EOL in October 7, 2024

[15.0.0] - 2026-04-12

Changed

  • Breaking change: Dropped support for Python3.8

Fixed

Changelog

Sourced from rich's changelog.

[15.0.0] - 2026-04-12

Changed

  • Breaking change: Dropped support for Python3.8

Fixed

Commits

Updates mcp from 1.28.1 to 2.2.0

Release notes

Sourced from mcp's releases.

v2.2.0

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

A few defaults changed in this release. If you run a server or client on 2.x, skim these first:

Behaviour changes

HTTP client redirects are only followed within the endpoint's origin (#3397)

  • Client("https://..."), streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host).
  • A redirect anywhere else is not followed: the call fails with MCPError and the session stays usable (an SSE connect fails with httpx2.HTTPStatusError). If that other URL is the server you meant, use it as the endpoint URL.
  • The follow_redirects setting on an httpx2.AsyncClient you pass in is no longer used for MCP requests, so you don't need it for the trailing-slash redirect any more.
  • The OAuth providers apply the same rule to their own requests.

Idle Streamable HTTP sessions now expire (legacy <=2025-11-25 spec( (#3395)

  • A stateful session with nothing in flight for 30 minutes is closed. The client's next request gets a 404 and it has to initialize again.
  • Clients that keep the GET stream open (the SDK's Client does) are not affected. Neither are stateless servers or 2026-07-28 connections.
  • A server also holds at most 10 000 sessions at once; beyond that, new sessions get a 503.
  • To turn either off: mcp.run(transport="streamable-http", session_idle_timeout=None, max_sessions=None) (also on streamable_http_app() and run_streamable_http_async()).

The OAuth client checks the authorization server's issuer on the legacy path too (#3398)

  • For servers without protected resource metadata, authorization server metadata whose issuer isn't the server's own origin is now rejected with OAuthFlowError: Authorization server metadata issuer mismatch. The protected-resource-metadata path has done this since 2.0.
  • A 403 that isn't an insufficient_scope challenge is returned to the caller instead of retried.
  • If protected resource metadata can't be fetched because of a 5xx/429, the flow now stops instead of falling back to the legacy endpoints.

Two new MCPDeprecationWarnings (#3435, #3447)

  • ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider without issuer=. Pass your authorization server's issuer URL; 3.0 will require it.
  • AuthSettings with resource_server_url set but validate_token_resource unset. Set it to True or False; 3.0 defaults it to True.
  • Both keep working as before in 2.x; this mostly matters if your tests turn warnings into errors.

New

  • AuthSettings.validate_token_resource: only accept tokens your TokenVerifier reports as issued for this server (#3447).
  • issuer= on ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider (#3398).
  • session_idle_timeout= and max_sessions= on the Streamable HTTP server entry points (#3395).

Fixes

  • A client DELETE frees its session immediately, and a refused opening request no longer leaves a session behind (#2455, #3228, #3300).
  • $refs in a tool's outputSchema resolve within that schema only; an unresolvable one surfaces as RuntimeError: Invalid schema for tool ... (#3394).

Known gaps

The tasks extension (SEP-2663), DPoP (SEP-1932) and the jwt-bearer grant are not implemented yet; https://github.com/modelcontextprotocol/python-sdk/blob/main/ROADMAP.md tracks them.

What's Changed

... (truncated)

Commits
  • 9972c21 Replace RootModel wrappers with type aliases and TypeAdapter validation (#3470)
  • fd66270 docs: refresh translations, and translate pages in parallel (#3458)
  • 08a3bc8 docs: ask for AI disclosure on comments too (#3459)
  • 7bb486a docs: stop presenting the in-memory client as the way to connect (#3443)
  • 0c91368 Add AuthSettings.validate_token_resource to check a bearer token's resource (...
  • 9771e6b Keep following a relative redirect when the endpoint URL carries userinfo (#3...
  • a925e55 Bump the locked versions of eight dev and test dependencies (#3449)
  • e8b9486 Bump pymdown-extensions from 11.0 to 11.0.1 (#3285)
  • c6762e8 Follow redirects only within the MCP endpoint's origin (#3397)
  • 5fd3abc Skip automatic docs previews for fork PRs and drop the setup-uv retry steps (...
  • Additional commits viewable in compare view

Updates anthropic from 0.116.0 to 1.8.0

Release notes

Sourced from anthropic's releases.

v1.8.0

1.8.0 (2026-09-22)

Full Changelog: v1.7.0...v1.8.0

Features

  • api: add support for claude-opus-5-5, inline tool definitions and MCP tool-list pinning (beta) (b5cc700)

Bug Fixes

  • api: share one evaluated_permission enum across Managed Agents events (f4f51c8)
  • streaming: avoid a Python 3.13 crash at exit when a stream is left open (af029bd)
  • tools: add_tools() takes effect straight away (#874) (06d0a6b)
  • tools: leave reply-only params off the tool runner's compaction request (#871) (4687310)

Chores

  • docs: add descriptions to the Dreams API reference (5574c63)
  • docs: add descriptions to the User Profiles API reference (5574c63)
  • docs: add memory store descriptions to the Managed Agents API reference (5574c63)
  • docs: improve descriptions in the Dreams API reference (1f5e477)
  • docs: simplify the session thread agent type description (a45b7ec)
  • docs: update diagnostics field descriptions on beta messages (367750c)
  • internal: fix tests (70c8cbd)
  • internal: remove mypy (be01ed6)
  • tests: update fixtures (77f6df8)

Documentation

  • add path and header parameter descriptions (f429a30)

Refactors

  • client: remove the request param transform in favour of the JSON encoder (539422c)

v1.7.0

1.7.0 (2026-09-18)

Full Changelog: v1.6.0...v1.7.0

Features

  • api: add group with display_name to rate limits, deprecate group_type (28f0a83)
  • tools: add compact_before_next_turn() to the tool runner (#641) (8b23fb3)

... (truncated)

Changelog

Sourced from anthropic's changelog.

1.8.0 (2026-09-22)

Full Changelog: v1.7.0...v1.8.0

Features

  • api: add support for claude-opus-5-5, inline tool definitions and MCP tool-list pinning (beta) (b5cc700)

Bug Fixes

  • api: share one evaluated_permission enum across Managed Agents events (f4f51c8)
  • streaming: avoid a Python 3.13 crash at exit when a stream is left open (af029bd)
  • tools: add_tools() takes effect straight away (#874) (06d0a6b)
  • tools: leave reply-only params off the tool runner's compaction request (#871) (4687310)

Chores

  • docs: add descriptions to the Dreams API reference (5574c63)
  • docs: add descriptions to the User Profiles API reference (5574c63)
  • docs: add memory store descriptions to the Managed Agents API reference (5574c63)
  • docs: improve descriptions in the Dreams API reference (1f5e477)
  • docs: simplify the session thread agent type description (a45b7ec)
  • docs: update diagnostics field descriptions on beta messages (367750c)
  • internal: fix tests (70c8cbd)
  • internal: remove mypy (be01ed6)
  • tests: update fixtures (77f6df8)

Documentation

  • add path and header parameter descriptions (f429a30)

Refactors

  • client: remove the request param transform in favour of the JSON encoder (539422c)

1.7.0 (2026-09-18)

Full Changelog: v1.6.0...v1.7.0

Features

  • api: add group with display_name to rate limits, deprecate group_type (28f0a83)
  • tools: add compact_before_next_turn() to the tool runner (#641) (8b23fb3)

Bug Fixes

... (truncated)

Commits
  • 4421d56 Merge pull request #1946 from anthropics/release-please--branches--main--chan...
  • d0247c2 release: 1.8.0
  • be01ed6 chore(internal): remove mypy
  • 06d0a6b fix(tools): add_tools() takes effect straight away (#874)
  • af029bd fix(streaming): avoid a Python 3.13 crash at exit when a stream is left open
  • 4687310 fix(tools): leave reply-only params off the tool runner's compaction request ...
  • b5cc700 feat(api): add support for claude-opus-5-5, inline tool definitions and MCP t...
  • 70c8cbd chore(internal): fix tests
  • 539422c refactor(client): remove the request param transform in favour of the JSON en...
  • 10a4c07 codegen metadata
  • Additional commits viewable in compare view

Updates filelock from 3.29.7 to 4.0.5

Release notes

Sourced from filelock's releases.

4.0.5

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.4...4.0.5

4.0.4

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.3...4.0.4

4.0.3

What's Changed

Full Changelog: tox-dev/filelock@4.0.2...4.0.3

4.0.2

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.1...4.0.2

... (truncated)

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.0.8 (2026-10-01)


  • ReadWriteLock.release() and SoftReadWriteLock.release() from a thread that does not hold the write lock now raise RuntimeError instead of dropping the holder's lock and letting a second writer in. :pr:761

4.0.7 (2026-09-29)


  • File locks now raise ValueError at construction when mode denies the owner read or write, such as mode=0o444, instead of failing on a later acquire and staying broken until someone deletes the lock file. :pr:760

4.0.6 (2026-09-28)


  • Reject negative blocking timeouts other than -1 before reentrant ReadWriteLock and SoftReadWriteLock acquisition. Preserve unlimited waits and nonblocking acquisition. :pr:756

4.0.5 (2026-09-28)


  • Fix MarkerSoftFileLock acquisition and prevent contenders from evicting live protocol-2 owners after two seconds. Reclaim recognized records after owner death; preserve unknown contracts. :pr:749
  • Honor instance timeout and blocking settings in sync and async ReadWriteLock acquisition, including waits between tasks on one instance. Preserve explicit per-call overrides. :pr:750
  • Skip access-denial checks when the process can read mode-0o000 files. Keep mode-bit checks enabled for privileged processes on filesystems that support POSIX permissions. :pr:753
  • Skip vanished StrictSoftFileLock claims after a read-permission retry expires. Recheck the directory before raising a protocol error so concurrent removal does not turn a stale claim listing into an acquisition failure. :pr:754
  • Reject negative timeouts other than -1 in blocking AsyncReadWriteLock and AsyncSoftReadWriteLock acquisitions. Keep -1 as an unlimited wait and ignore timeouts when blocking=False. :pr:755

4.0.4 (2026-09-26)


  • Hostnames that still differ after their first 253 escaped characters now publish distinct owners, so a soft lock no longer takes another such host's live holder for its own and reclaims its marker. :pr:748

... (truncated)

Commits

Updates huggingface-hub from 1.23.0 to 2.0.0

Release notes

Sourced from huggingface-hub's releases.

[v2.0.0] The httpx2 release

See MIGRATION GUIDE in docs.

💔 Breaking Change: HTTP stack moves to httpx2

See migration plan in huggingface/huggingface_hub#4802 .

huggingface_hub v2.0 replaces its HTTP dependency with httpx2: clients and transport exceptions now come from httpx2/httpcore2 instead of httpx/httpcore. Custom client factories (via set_client_factory / set_async_client_factory) and any except clauses catching transport errors must use httpx2 types. For code that must support both v1.x (starting with v1.30.0) and v2.x, import the HTTP module from huggingface_hub.utils:

from huggingface_hub.utils import get_session, httpx
try:
response = get_session().get("https://huggingface.co/api/models/gpt2")
response.raise_for_status()
except httpx.HTTPError:
...

Note that httpx2 uses the operating system's certificate trust store by default (custom CA bundles via SSL_CERT_FILE / SSL_CERT_DIR still work), logging configuration should target the httpx2 and httpcore2 loggers, and the oauth extra now requires authlib>=1.8.0.

💔 Breaking Change: deprecated APIs are removed

This release also removes all APIs deprecated in 1.x:

  • upload_large_folder / HfApi.upload_large_folder → use upload_folder
  • duplicate_space → use duplicate_repo
  • request_space_storage / delete_space_storage → use the volume APIs (set_space_volumes, delete_space_volumes)
  • repo_type_and_id_from_hf_id → use parse_hf_uri
  • InferenceEndpointType.PROTECTED → use AUTHENTICATED (create_inference_endpoint(type="protected") now raises ValueError)
  • list_models(model_name=...) → use list_models(search=...)
  • create_repo / duplicate_repo(space_storage=...) → use space_volumes
  • text_generation(stop_sequences=...) → use stop
  • Boolean InferenceClient(token=...) → pass a token string or None

On the CLI side, the following entry points and options are gone: huggingface-cli (use hf), hf repo and hf repo-files delete (use hf repos and hf repos delete-files), hf upload-large-folder (use hf upload), hf repos create/duplicate --storage (use --volume), hf jobs ps and hf jobs scheduled ps -f/--filter (use --status/--label), and hf skills add/update --claude (Claude Code installation is now automatic).

A migration guide covering all of this is available at https://github.com/huggingface/huggingface_hub/blob/main/docs/source/en/concepts/migration_v2.md.

🏗️ Internal

... (truncated)

Commits
  • 97c5f5f Release: v2.0.0
  • e2d609e Release: v2.0.0.rc0
  • 89ae51f unbump
  • 9f51867 [Release] Prepare huggingface_hub 2.0 (#4994)
  • c2e6e0a Post-release: bump version to 1.34.0.dev0 (#4993)
  • fa26f34 [CI] Support major (pre-)releases in release workflow (#4991)
  • ac3ed2f [Xet] Show Validating progress during shard finalization (#4478)
  • b904b94 Apply the repo_id length limit to the namespace as well (#4988)
  • 1e0c305 Send PrivateLink config under privateService in create_inference_endpoint (#4...
  • da5e244 Scope GITHUB_TOKEN permissions per job (#4982)
  • Additional commits viewable in compare view

Updates importlib-metadata from 8.9.0 to 9.0.1

Changelog

Sourced from importlib-metadata's changelog.

v9.0.1

Bugfixes

  • Marked the other parameter of SimplePath.joinpath and SimplePath.__truediv__ positional-only, so pathlib.Path satisfies the protocol under type checkers that compare parameter names. (#542)

v9.0.0

Deprecations and Removals

  • Added MetadataNotFound (subclass of FileNotFoundError) and updated Distribution.metadata/metadata() to raise it when the metadata files are missing instead of returning Nonepython/cpython#143387#532)
Commits

Updates multidict from 6.7.1 to 7.0.0
Updates openai from 2.41.1 to 3.19.2

Release notes

Sourced from openai's releases.

v3.19.2

3.19.2 (2026-09-23)

Bug Fixes

  • preserve single files for fallback extraction paths (#3875) (bfd3680)

Chores

  • api: clarify approximate web search location defaults (#3953) (a95c95e)
  • api: clarify Realtime modality array definitions (#3954) (e79cf53)
  • api: correct fine-tuning bounds and Realtime response reference (#3949) (325a948)

v3.19.1

3.19.1 (2026-09-23)

Bug Fixes

  • chat: preserve single-pass tool iterables (#3770) (33ffa1f)
  • client: merge HTTP headers case-insensitively (#3486) (5e39766)

Chores

  • api: clarify Chat Completions seed limits (#3945) (be9d666)

Documentation

  • clarify collaborator-only pull request policy (#3948) (ead1fa2)

v3.19.0

3.19.0 (2026-09-22)

Features

Bug Fixes

  • _utils/_transform: propagate api_exclude in _async_transform_recursive (#3324) (161ae65)
  • api: handle omission markers in queued WebSocket events (#3944) (63e4616)
  • client: retry only replayable request content (#3771) (6e0c2be)
  • client: tolerate older optional aiohttp installations (#3941) (0d91efb)

... (truncated)

Changelog

Sourced from openai's changelog.

3.19.2 (2026-09-23)

Bug Fixes

  • preserve single files for fallback extraction paths (#3875) (bfd3680)

Chores

  • api: clarify approximate web search location defaults (#3953) (a95c95e)
  • api: clarify Realtime modality array definitions (#3954) (e79cf53)
  • api: correct fine-tuning bounds and Realtime response reference (#3949) (325a948)

3.19.1 (2026-09-23)

Bug Fixes

  • chat: preserve single-pass tool iterables (#3770) (33ffa1f)
  • client: merge HTTP headers case-insensitively (#3486) (5e39766)

Chores

  • api: clarify Chat Completions seed limits (#3945) (be9d666)

Documentation

  • clarify collaborator-only pull request policy (#3948) (ead1fa2)

3.19.0 (2026-09-22)

Features

Bug Fixes

  • _utils/_transform: propagate api_exclude in _async_transform_recursive (#3324) (161ae65)
  • api: handle omission markers in queued WebSocket events (#3944) (63e4616)
  • client: retry only replayable request content (#3771) (6e0c2be)
  • client: tolerate older optional aiohttp installations (#3941) (0d91efb)
  • helpers: use asyncio.get_running_loop() inside async methods (#3289) (bac3545)

3.18.0 (2026-09-22)

... (truncated)

Commits
  • d9f7b7a release: 3.19.2 (#3951)
  • e79cf53 chore(api): clarify Realtime modality array definitions (#3954)
  • a95c95e chore(api): clarify approximate web search location defaults (#3953)
  • 325a948 chore(api): correct fine-tuning bounds and Realtime response reference (#3949)
  • bfd3680 fix: preserve single files for fallback extraction paths (#3875)
  • 4d12746 release: 3.19.1 (#3946)
  • 33ffa1f fix(chat): preserve single-pass tool iterables (#3770)
  • 5e39766 fix(client): merge HTTP headers case-insensitively (#3486)
  • ead1fa2 docs: clarify collaborator-only pull request policy (#3948)
  • be9d666 chore(api): clarify Chat Completions seed limits (#3945)
  • Additional commits viewable in compare view

Updates textual from 7.5.0 to 8.2.8

Release notes

Sourced from textual's releases.

The more super release

Fixes for extended key processing, and a crash bug for clicking the screen padding area.

[8.2.8] - 2026-06-30

Fixed

Changed

The more Kitty Release

This release adds additional support for the Kitty key protocol. Which enables some additional keys on some terminals. Additionally, Textual will report modifier keys as separate key events.

Additionally there are a few more shortcuts to the Text Area.

This release sponsored by Mistral AI. See release notes for detail.

[8.2.7] - 2026-05-19

Added

  • Added support for Kitty key protocol "Report all keys as escape codes" which enabled alt+backspace on Warp Textualize/textual#6544
  • Added support for detecting separate modifier keys for terminals that support the Kitty key protocol Textualize/textual#6544
  • Added TEXTUAL_DISABLE_KITTY_KEY env var to disable Kitty key protocol support (debug aid). Textualize/textual#6544

Changed

The more selective release

Improved text select logic. You can select text without first clicking on a content area.

May break snapshots without affecting appearance.

[8.2.6] - 2026-04-13

Fixed

  • Fixed selection to the right of code fence blocks (may break some snapshots)
  • Fixed Markdown code fences losing content when switching themes Textualize/textual#6537

Added

... (truncated)

Changelog

Sourced from textual's changelog.

[8.2.8] - 2026-06-30

Fixed

Changed

[8.2.7] - 2026-05-19

Added

  • Added support for Kitty key protocol "Report all keys as escape codes" which enabled alt+backspace on Warp Textualize/textual#6544
  • Added support for detecting separate modifier keys for terminals that support the Kitty key protocol Textualize/textual#6544
  • Added TEXTUAL_DISABLE_KITTY_KEY env var to disable Kitty key protocol support (debug aid). Textualize/textual#6544

Changed

  • Undo/redo/copy/cut/paste in TextArea will now work with cmd+ on supported terminals Textualize/textual#6543
  • In Te...

    Description has been truncated

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 30, 2026
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 30, 2026
@greptile-apps

greptile-apps Bot commented Sep 30, 2026

Copy link
Copy Markdown

PR author is not in the allowed authors list.

@github-actions github-actions Bot added the gitar-managed Enables Gitar automatic repair for a pull request label Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: CHILL

Plan: Advanced

Run ID: 2d8f8d3e-0750-4b68-bd45-1a6b2f13badc

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot
dependabot Bot force-pushed the dependabot/pip/pip-major-022e3118b5 branch 16 times, most recently from 4d6c739 to f554997 Compare October 1, 2026 11:11
Bumps the pip-major group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [rich](https://github.com/Textualize/rich) | `14.3.4` | `15.0.0` |
| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `1.28.1` | `2.2.0` |
| [anthropic](https://github.com/anthropics/anthropic-sdk-python) | `0.116.0` | `1.8.0` |
| [filelock](https://github.com/tox-dev/py-filelock) | `3.29.7` | `4.0.5` |
| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.23.0` | `2.0.0` |
| [importlib-metadata](https://github.com/python/importlib_metadata) | `8.9.0` | `9.0.1` |
| [multidict](https://github.com/aio-libs/multidict) | `6.7.1` | `7.0.0` |
| [openai](https://github.com/openai/openai-python) | `2.41.1` | `3.19.2` |
| [textual](https://github.com/Textualize/textual) | `7.5.0` | `8.2.8` |
| [websockets](https://github.com/python-websockets/websockets) | `16.1` | `16.1.1` |



Updates `rich` from 14.3.4 to 15.0.0
- [Release notes](https://github.com/Textualize/rich/releases)
- [Changelog](https://github.com/Textualize/rich/blob/main/CHANGELOG.md)
- [Commits](Textualize/rich@v14.3.4...v15.0.0)

Updates `mcp` from 1.28.1 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v1.28.1...v2.2.0)

Updates `anthropic` from 0.116.0 to 1.8.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-python/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-python@v0.116.0...v1.8.0)

Updates `filelock` from 3.29.7 to 4.0.5
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@3.29.7...4.0.5)

Updates `huggingface-hub` from 1.23.0 to 2.0.0
- [Release notes](https://github.com/huggingface/huggingface_hub/releases)
- [Commits](huggingface/huggingface_hub@v1.23.0...v2.0.0)

Updates `importlib-metadata` from 8.9.0 to 9.0.1
- [Release notes](https://github.com/python/importlib_metadata/releases)
- [Changelog](https://github.com/python/importlib_metadata/blob/main/NEWS.rst)
- [Commits](python/importlib_metadata@v8.9.0...v9.0.1)

Updates `multidict` from 6.7.1 to 7.0.0
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v6.7.1...v7.0.0)

Updates `openai` from 2.41.1 to 3.19.2
- [Release notes](https://github.com/openai/openai-python/releases)
- [Changelog](https://github.com/openai/openai-python/blob/main/CHANGELOG.md)
- [Commits](openai/openai-python@v2.41.1...v3.19.2)

Updates `textual` from 7.5.0 to 8.2.8
- [Release notes](https://github.com/Textualize/textual/releases)
- [Changelog](https://github.com/Textualize/textual/blob/main/CHANGELOG.md)
- [Commits](Textualize/textual@v7.5.0...v8.2.8)

Updates `websockets` from 16.1 to 16.1.1
- [Release notes](https://github.com/python-websockets/websockets/releases)
- [Commits](python-websockets/websockets@16.1...16.1.1)

---
updated-dependencies:
- dependency-name: anthropic
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-major
- dependency-name: filelock
  dependency-version: 4.0.4
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-major
- dependency-name: huggingface-hub
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-major
- dependency-name: importlib-metadata
  dependency-version: 9.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-major
- dependency-name: mcp
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-major
- dependency-name: multidict
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-major
- dependency-name: openai
  dependency-version: 3.19.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-major
- dependency-name: rich
  dependency-version: 15.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-major
- dependency-name: textual
  dependency-version: 8.2.8
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-major
- dependency-name: websockets
  dependency-version: 16.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/pip-major-022e3118b5 branch from f554997 to d33dd0d Compare October 1, 2026 11:53

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file gitar-managed Enables Gitar automatic repair for a pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants