Skip to content

build(deps): Bump the python-deps group across 1 directory with 5 updates - #15

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-deps-71bf87a8b1
Open

build(deps): Bump the python-deps group across 1 directory with 5 updates#15
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-deps-71bf87a8b1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 12, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-deps group with 5 updates in the / directory:

Package From To
mcp 2.1.1 2.2.0
openai 3.8.0 3.11.0
mujoco 3.12.0 3.13.0
onnxruntime 1.27.0 1.29.0
types-pyyaml 6.0.12.20260815 6.0.12.20260906

Updates mcp from 2.1.1 to 2.2.0

Release notes

Sourced from mcp's releases.

v2.2.0

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

A few defaults changed in this release. If you run a server or client on 2.x, skim these first:

Behaviour changes

HTTP client redirects are only followed within the endpoint's origin (#3397)

  • Client("https://..."), streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host).
  • A redirect anywhere else is not followed: the call fails with MCPError and the session stays usable (an SSE connect fails with httpx2.HTTPStatusError). If that other URL is the server you meant, use it as the endpoint URL.
  • The follow_redirects setting on an httpx2.AsyncClient you pass in is no longer used for MCP requests, so you don't need it for the trailing-slash redirect any more.
  • The OAuth providers apply the same rule to their own requests.

Idle Streamable HTTP sessions now expire (legacy <=2025-11-25 spec( (#3395)

  • A stateful session with nothing in flight for 30 minutes is closed. The client's next request gets a 404 and it has to initialize again.
  • Clients that keep the GET stream open (the SDK's Client does) are not affected. Neither are stateless servers or 2026-07-28 connections.
  • A server also holds at most 10 000 sessions at once; beyond that, new sessions get a 503.
  • To turn either off: mcp.run(transport="streamable-http", session_idle_timeout=None, max_sessions=None) (also on streamable_http_app() and run_streamable_http_async()).

The OAuth client checks the authorization server's issuer on the legacy path too (#3398)

  • For servers without protected resource metadata, authorization server metadata whose issuer isn't the server's own origin is now rejected with OAuthFlowError: Authorization server metadata issuer mismatch. The protected-resource-metadata path has done this since 2.0.
  • A 403 that isn't an insufficient_scope challenge is returned to the caller instead of retried.
  • If protected resource metadata can't be fetched because of a 5xx/429, the flow now stops instead of falling back to the legacy endpoints.

Two new MCPDeprecationWarnings (#3435, #3447)

  • ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider without issuer=. Pass your authorization server's issuer URL; 3.0 will require it.
  • AuthSettings with resource_server_url set but validate_token_resource unset. Set it to True or False; 3.0 defaults it to True.
  • Both keep working as before in 2.x; this mostly matters if your tests turn warnings into errors.

New

  • AuthSettings.validate_token_resource: only accept tokens your TokenVerifier reports as issued for this server (#3447).
  • issuer= on ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider (#3398).
  • session_idle_timeout= and max_sessions= on the Streamable HTTP server entry points (#3395).

Fixes

  • A client DELETE frees its session immediately, and a refused opening request no longer leaves a session behind (#2455, #3228, #3300).
  • $refs in a tool's outputSchema resolve within that schema only; an unresolvable one surfaces as RuntimeError: Invalid schema for tool ... (#3394).

Known gaps

The tasks extension (SEP-2663), DPoP (SEP-1932) and the jwt-bearer grant are not implemented yet; https://github.com/modelcontextprotocol/python-sdk/blob/main/ROADMAP.md tracks them.

What's Changed

... (truncated)

Commits
  • 9972c21 Replace RootModel wrappers with type aliases and TypeAdapter validation (#3470)
  • fd66270 docs: refresh translations, and translate pages in parallel (#3458)
  • 08a3bc8 docs: ask for AI disclosure on comments too (#3459)
  • 7bb486a docs: stop presenting the in-memory client as the way to connect (#3443)
  • 0c91368 Add AuthSettings.validate_token_resource to check a bearer token's resource (...
  • 9771e6b Keep following a relative redirect when the endpoint URL carries userinfo (#3...
  • a925e55 Bump the locked versions of eight dev and test dependencies (#3449)
  • e8b9486 Bump pymdown-extensions from 11.0 to 11.0.1 (#3285)
  • c6762e8 Follow redirects only within the MCP endpoint's origin (#3397)
  • 5fd3abc Skip automatic docs previews for fork PRs and drop the setup-uv retry steps (...
  • Additional commits viewable in compare view

Updates openai from 3.8.0 to 3.11.0

Release notes

Sourced from openai's releases.

v3.11.0

3.11.0 (2026-09-09)

Features

  • api: Add expiration controls for service account keys (#3825) (f348ec8)

v3.10.0

3.10.0 (2026-09-08)

Features

  • api: add GPT Image 2.5 models and image options (#3824) (5b39c45)
  • api: add service-account API key expiration fields (#3802) (f1cd7f0)

v3.9.0

3.9.0 (2026-09-05)

Features

  • api: Add prompt cache diagnostics (#3800) (8326784)
  • api: correct function argument completion event fields (openapi-545) (#3801) (2a98f6a)

Bug Fixes

  • api: accept incomplete web search call statuses (#3786) (3cc8d78)
  • refuse overflowing server retry delays (#3799) (88b4d43)

Chores

  • api: document throttling and model overload responses — SDK-235 (#3803) (be92815)
  • migrate to forked steady (#3795) (b24aeda)
Changelog

Sourced from openai's changelog.

3.11.0 (2026-09-09)

Features

  • api: Add expiration controls for service account keys (#3825) (f348ec8)

3.10.0 (2026-09-08)

Features

  • api: add GPT Image 2.5 models and image options (#3824) (5b39c45)
  • api: add service-account API key expiration fields (#3802) (f1cd7f0)

3.9.0 (2026-09-05)

Features

  • api: Add prompt cache diagnostics (#3800) (8326784)
  • api: correct function argument completion event fields (openapi-545) (#3801) (2a98f6a)

Bug Fixes

  • api: accept incomplete web search call statuses (#3786) (3cc8d78)
  • refuse overflowing server retry delays (#3799) (88b4d43)

Chores

  • api: document throttling and model overload responses — SDK-235 (#3803) (be92815)
  • migrate to forked steady (#3795) (b24aeda)
Commits
  • 41f0a23 release: 3.11.0 (#3829)
  • f348ec8 feat(api): Add expiration controls for service account keys (#3825)
  • 8011140 release: 3.10.0 (#3822)
  • 5b39c45 feat(api): add GPT Image 2.5 models and image options (#3824)
  • f1cd7f0 feat(api): add service-account API key expiration fields (#3802)
  • 182af73 release: 3.9.0 (#3796)
  • be92815 chore(api): document throttling and model overload responses — SDK-235 (#3803)
  • 2a98f6a feat(api): correct function argument completion event fields (openapi-545) (#...
  • 88b4d43 fix: refuse overflowing server retry delays (#3799)
  • 8326784 feat(api): Add prompt cache diagnostics (#3800)
  • Additional commits viewable in compare view

Updates mujoco from 3.12.0 to 3.13.0

Release notes

Sourced from mujoco's releases.

3.13.0

Version 3.13.0 (September 8, 2026)

General

  1. eb18d77ca The .mjz encoder now writes the root file as model.xml in the archive as this is less susceptible to breakage due to file renaming.

  2. 4affbb64a Site geometries can now also be associated with meshes (type="mesh" with mesh="name"), supporting visualization, the insidesite sensor, and the new mj_insideSite function.

  3. b59b07fae Added support for Python 3.15 (GIL and Free-Threading).

Engine

  1. 5660353ec Added a new integrator discrete: the constraint solve and the implicit velocity update merge into one operation, performed in the effective metric $\widehat{M} = M + hD + h^2K$, which incorporates both implicit damping $hD$ and implicit position stiffness $h^2 K$. Under this integrator mjData.qacc is the discrete step map $(v^+ - v)/h$, and joint, tendon and actuator stiffness and damping join the solver's metric, making passive springs and actuator position gains stable at timesteps far beyond the explicit stability limit. Constraint rows are treated implicitly as well: solref spring--dampers are evaluated at the end of the step, so constraints are stable at any timeconst; under this integrator the refsafe flag replaces contact and limit rows stiffer than the timestep can resolve by the stiffest zero-restitution row instead of clamping timeconst. The actuator-gain treatment resolves the stiff-servo timestep limitation of #3443 (analysis contributed by @​qiayuanl). See the integrator documentation for semantics and current limitations.

[!WARNING] Breaking API changes

Removed the implicit flex effective-metric special case under implicit/implicitfast with the CG solver, introduced in 3.11.0. This behavior now requires integrator="discrete" (with a primal solver: CG or Newton), which additionally treats joint damping and stiffness implicitly inside the solve. Models relying on the old behavior should set integrator to discrete; models with flex elasticity or passive flex contact under implicit/implicitfast now raise a runtime error carrying this migration note.

  1. 0b4e17747 Restored clamping of non-positive pivots in the sparse inertia factorization, along with the associated mjWARN_INERTIA warning. The guard was inadvertently dropped in the 3.3.0 conversion of qLD to CSR format; since then, models with singular mass matrices silently produced non-finite accelerations, typically surfacing as divergence warnings and automatic resets.

  2. c9d997610 Added single-shot multicontact for collisions with cylinder geoms.

  3. 10eeb8289 The Newton solver with elliptic cones now rebuilds the cone-augmented Hessian factor with a single refactorization instead of per-contact rank-1 updates when a flop-count model predicts this is faster. Scenes with many simultaneously sliding contacts speed up by 1.4-2x on average and 3-4x on the slowest steps. Contribution by @​kevinzakka.

... (truncated)

Changelog

Sourced from mujoco's changelog.

Version 3.13.0 (September 8, 2026)

General ^^^^^^^

  1. :commit:eb18d77ca The :ref:.mjz <MJZArchives> encoder now writes the root file as model.xml in the archive as this is less susceptible to breakage due to file renaming.
  2. :commit:4affbb64a Site geometries can now also be associated with meshes (:ref:type="mesh"<body-site-type> with :ref:mesh="name"<body-site-mesh>), supporting visualization, the :ref:insidesite<sensor-insidesite> sensor, and the new :ref:mj_insideSite function.
  3. :commit:b59b07fae Added support for Python 3.15 (GIL and Free-Threading).

Engine ^^^^^^ 4. :commit:5660353ec Added a new integrator discrete: the constraint solve and the implicit velocity update merge into one operation, performed in the effective metric :math:\widehat{M} = M + hD + h^2K, which incorporates both implicit damping :math:hD and implicit position stiffness :math:h^2 K. Under this integrator mjData.qacc is the discrete step map :math:(v^+ - v)/h, and joint, tendon and actuator stiffness and damping join the solver's metric, making passive springs and actuator position gains stable at timesteps far beyond the explicit stability limit. Constraint rows are treated implicitly as well: :at:solref spring--dampers are evaluated at the end of the step, so constraints are stable at any timeconst; under this integrator the :ref:refsafe<option-flag-refsafe> flag replaces contact and limit rows stiffer than the timestep can resolve by the stiffest zero-restitution row instead of clamping timeconst. The actuator-gain treatment resolves the stiff-servo timestep limitation of :issue:3443 (analysis contributed by :github:user:qiayuanl). See the :ref:integrator documentation<geIntegrators> for semantics and current limitations.

.. admonition:: Breaking API changes :class: attention

  Removed the implicit flex effective-metric special case under ``implicit``/``implicitfast`` with the ``CG``
  solver, introduced in 3.11.0. This behavior now requires ``integrator="discrete"`` (with a primal solver:
  ``CG`` or ``Newton``), which additionally treats joint damping and stiffness implicitly inside the solve. Models
  relying on the old behavior should set :ref:`integrator<option-integrator>` to ``discrete``; models with flex
  elasticity or passive flex contact under ``implicit``/``implicitfast`` now raise a runtime error carrying this
  migration note.
  1. :commit:0b4e17747 Restored clamping of non-positive pivots in the sparse inertia factorization, along with the associated mjWARN_INERTIA warning. The guard was inadvertently dropped in the 3.3.0 conversion of qLD to CSR format; since then, models with singular mass matrices silently produced non-finite accelerations, typically surfacing as divergence warnings and automatic resets.
  2. :commit:c9d997610 Added single-shot :ref:multicontact<coMultiCCD> for collisions with cylinder geoms.
  3. :commit:10eeb8289 The Newton solver with :ref:elliptic cones<option-cone> now rebuilds the cone-augmented Hessian factor with a single refactorization instead of per-contact rank-1 updates when a flop-count model predicts this is faster. Scenes with many simultaneously sliding contacts speed up by 1.4-2x on average and 3-4x on the slowest steps. Contribution by :github:user:kevinzakka.

Compiler ^^^^^^^^ 8. :commit:2a3957558 Custom text fields (:ref:custom/text<custom-text>) in MJCF now accept their values inside a <![CDATA[ ... ]]> block in addition to the data attribute. When saving a model via :ref:mj_saveXML, custom

... (truncated)

Commits
  • 123347c Update changelog for the 3.13.0 release.
  • 5cc54f3 Add Googler @​mention to failure alerts.
  • 297f5fc Merge pull request #3267 from njfletcher215:order-siblings-deterministically
  • 9f42b35 Keep the authored damping ratio in the discrete refsafe row.
  • 6b5c05d Remove trailing underscore from local variable.
  • a6cb503 Import NVIDIA Warp 1.17.0
  • 4990fa5 Merge pull request #3541 from proudhare:fix/ph-issue-3540
  • a90ca41 Enable MultiCCD by default in MuJoCo global settings.
  • d1da09a Enable island rendering draw mode.
  • 2944f5e Introduce internal mjPacked32 struct in engine_collision_driver.c to handle p...
  • Additional commits viewable in compare view

Updates onnxruntime from 1.27.0 to 1.29.0

Release notes

Sourced from onnxruntime's releases.

ONNX Runtime v1.29.0

Announcements & Breaking Changes

  • onnxruntime-web has announced the deprecation of WebGL and JSEP. The native WebGPU EP is the recommended path going forward. See the deprecation and migration plans for details (#29716, #31683).
  • POSIX telemetry is now available on Linux, macOS, Android, and iOS when ONNX Runtime is built with telemetry enabled. It does not change the public ABI, WebAssembly remains telemetry-free, and setting ORT_DISABLE_TELEMETRY=1 before initialization disables non-Windows telemetry for the process (#27379, #29872).
  • The unused internal onnxruntime/python/tools/tensorrt dashboard tooling was removed. This does not affect the TensorRT Execution Provider APIs (#29395).

Security Fixes

Path, bounds, and input validation

  • Fixed a path traversal vulnerability in TensorRT and NvTensorRTRTX engine refitting by making external-data path validation unconditional (#29396).
  • Validated the CPU MoE k attribute against the number of experts and fixed a CPU TensorScatter security issue (#29907, #29916).
  • Added missing rank, shape, and parameter validation for pooling, LSTM and DynamicQuantizeLSTM, Sampling, FeatureVectorizer, SkipLayerNorm, QLinearConv, Whisper decoding, RNN activations, GridSample, contrib Range, and CropAndResize (#29254, #29255, #29265, #29579, #29595, #29605, #29871, #31636, #31671, #31675, #31676, #31684).
  • Hardened CUDA indexing and buffer handling in GridSample, transpose, GatherBlockQuantized, InstanceNormalization, LayerNorm/RMSNorm, BeamSearch, DeformConv, AveragePool, and MaxPool (#29581, #29631, #29638, #31640, #31642, #31644, #31645, #31647, #31650).
  • Fixed packed sub-byte tensor over-copying in OrtApi::GetValue and validated DML constant tensor byte sizes (#29157, #31665).

Supply chain and tooling

  • Updated npm lockfiles, refreshed the Next.js end-to-end fixture lockfile for security advisories, and upgraded adm-zip for onnxruntime-node (#29827, #29926, #31192).

New Features

Core APIs & Runtime

  • Default intra-op and inter-op thread-pool sizes can now be set with ORT_INTRA_OP_NUM_THREADS and ORT_INTER_OP_NUM_THREADS. Explicit thread settings still take precedence, and 0 preserves machine-sized defaults (#29688).
  • Added weightless-model support for all initializer types, allowed zero-input EpContext nodes, and wired maximum-shape inference into workspace estimation (#29607, #29799, #31613).
  • Added ONNX-domain support for rotary embedding and a fused MRotaryEmbedding contrib operator for Qwen mRoPE variants (#29261, #31728).
  • Added multi-shape profiling to onnxruntime_perf_test through --data_shape, plus verbose graph-transformer tracing and broader inference-session error-path coverage (#29555, #29558, #29569, #29571).

Execution Provider ABI & Plugin EPs

  • WebGPU now supports device-free compile-only sessions for offline graph transformation (#29681).
  • Expanded CUDA plugin EP packaging and testing, including Windows ARM64 package and size options, updated package outputs, and aligned architecture selections across Python, C API, TensorRT, Node.js, and plugin packages (#31635, #31722, #31992).
  • Improved plugin lifecycle handling by unloading failed EP library loads and fixing allocator-deleter lifetime (#29634, #29770).

Execution Provider Updates

NVIDIA CUDA EP

Attention and decoding

  • Added PagedAttention with quantized KV cache, XQA decode, MLA, QK-Norm, and head-sink support (#29912).
  • Extended quantized KV-cache support with attention sinks, independent and per-channel scales, sliding-window cache support, and a fused K/V dequantization launch (#29900, #29904, #31480).
  • Added a cuDNN SDPA decode tier to the standard ONNX Attention CUDA kernel and enabled cuDNN SDPA for contrib Attention (#29715, #29717).
  • Added attention_bias support to the GroupQueryAttention unfused path and state_window support to LinearAttention and CausalConvWithState for MTP (#29525, #31157).
  • Fixed LinearAttention on GPUs with limited shared memory (#31982).

MoE and quantized GEMM

... (truncated)

Commits

Updates types-pyyaml from 6.0.12.20260815 to 6.0.12.20260906

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ates

Bumps the python-deps group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `2.1.1` | `2.2.0` |
| [openai](https://github.com/openai/openai-python) | `3.8.0` | `3.11.0` |
| [mujoco](https://github.com/google-deepmind/mujoco) | `3.12.0` | `3.13.0` |
| [onnxruntime](https://github.com/microsoft/onnxruntime) | `1.27.0` | `1.29.0` |
| [types-pyyaml](https://github.com/python/typeshed) | `6.0.12.20260815` | `6.0.12.20260906` |



Updates `mcp` from 2.1.1 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v2.1.1...v2.2.0)

Updates `openai` from 3.8.0 to 3.11.0
- [Release notes](https://github.com/openai/openai-python/releases)
- [Changelog](https://github.com/openai/openai-python/blob/main/CHANGELOG.md)
- [Commits](openai/openai-python@v3.8.0...v3.11.0)

Updates `mujoco` from 3.12.0 to 3.13.0
- [Release notes](https://github.com/google-deepmind/mujoco/releases)
- [Changelog](https://github.com/google-deepmind/mujoco/blob/main/doc/changelog.rst)
- [Commits](google-deepmind/mujoco@3.12.0...3.13.0)

Updates `onnxruntime` from 1.27.0 to 1.29.0
- [Release notes](https://github.com/microsoft/onnxruntime/releases)
- [Changelog](https://github.com/microsoft/onnxruntime/blob/main/docs/ReleaseNotesWorkflow.md)
- [Commits](microsoft/onnxruntime@v1.27.0...v1.29.0)

Updates `types-pyyaml` from 6.0.12.20260815 to 6.0.12.20260906
- [Commits](https://github.com/python/typeshed/commits)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-deps
- dependency-name: openai
  dependency-version: 3.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-deps
- dependency-name: mujoco
  dependency-version: 3.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-deps
- dependency-name: onnxruntime
  dependency-version: 1.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-deps
- dependency-name: types-pyyaml
  dependency-version: 6.0.12.20260906
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants