Skip to content

build(deps-dev): bump openapi-python-client from 0.29.0 to 0.29.1 - #4

Merged
MattJackson merged 1 commit into
devfrom
dependabot/pip/dev/openapi-python-client-0.29.1
Oct 2, 2026
Merged

MattJackson merged 1 commit into
devfrom
dependabot/pip/dev/openapi-python-client-0.29.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown

Bumps openapi-python-client from 0.29.0 to 0.29.1.

Release notes

Sourced from openapi-python-client's releases.

0.29.1 (2026-08-30)

🚨Security

Arbitrary code generation vulnerability

Prior to this release, malicious OpenAPI documents could cause openapi-python-client to generate arbitrary code, which would then be executed by consumers of the generated client.

If you generate code from OpenAPI documents you don't control, you should upgrade to this release as soon as possible and validate any previously-generated code.

See the GitHub advisory for more details.

🚀 Features

  • Update uv_build to 0.12 when using --meta=uv (#1473)

🐛 Fixes

  • Apply PEP 639 for improved license metadata (#1459)
  • update generated code to use StrEnum and -> Self (#1474)
  • Remove trailing spaces in README example code (#1475)
  • Stopped generating empty docstrings for models with no description

Fixed invalid Python identifiers when resolving naming conflicts

When two property or parameter names conflicted after conversion to snake_case (e.g. foo-bar and fooBar), the conflict-resolution path preserved delimiters like -, ., and spaces in the generated Python identifiers, producing invalid code which failed generation. Conflicting names now keep their original casing but have any characters which are invalid in Python identifiers stripped (e.g. foobar and fooBar).

Improve readability of error messages

Errors and warnings which include a snippet of your OpenAPI document now render that snippet as JSON, making them much easier to read.

📝Notes

Breaking changes for all custom templates

ALL custom templates are expected to break with this version as a result of the security fix.

  1. The utils global has been renamed to strings
  2. Most string values can no longer be rendered directly into templates, you must describe how the value is being used so it can be properly escaped using either a Python function or Jinja filter:
    1. strings.snake_case() / | snakecase (existing)
    2. strings.kebab_case() / | kebabcase (existing)
    3. strings.pascal_case() / | pascalcase (existing)
    4. python_identifier() (existing)
    5. class_name() (existing)
    6. strings.safe_for_docstring() / | safe_for_docstring for values which get injected into a """ docstring
    7. strings.in_f_string_literal() / | in_f_string_literal for values that go into f"" f-strings
    8. strings.in_double_quote_literal() / | in_double_quote_literal for values that go into non-f-string "" literals
    9. .as_unembedded_code() / | as_unembedded_code ONLY for PythonCode values—those that are intended to be Python code which is not embedded into any string/docstring. Examples include usages of .python_code, .get_type_string(), .get_instance_type_string(), .get_type_strings_in_union(). You should not assume these values are safe to put in docstrings, string literals, or f-string literals. Use the dedicated helpers for those.

... (truncated)

Changelog

Sourced from openapi-python-client's changelog.

0.29.1 (2026-08-30)

🚨Security

Arbitrary code generation vulnerability

Prior to this release, malicious OpenAPI documents could cause openapi-python-client to generate arbitrary code, which would then be executed by consumers of the generated client.

If you generate code from OpenAPI documents you don't control, you should upgrade to this release as soon as possible and validate any previously-generated code.

See the GitHub advisory for more details.

🚀 Features

  • Update uv_build to 0.12 when using --meta=uv (#1473)

🐛 Fixes

  • Apply PEP 639 for improved license metadata (#1459)
  • update generated code to use StrEnum and -> Self (#1474)
  • Remove trailing spaces in README example code (#1475)
  • Stopped generating empty docstrings for models with no description

Fixed invalid Python identifiers when resolving naming conflicts

When two property or parameter names conflicted after conversion to snake_case (e.g. foo-bar and fooBar), the conflict-resolution path preserved delimiters like -, ., and spaces in the generated Python identifiers, producing invalid code which failed generation. Conflicting names now keep their original casing but have any characters which are invalid in Python identifiers stripped (e.g. foobar and fooBar).

Improve readability of error messages

Errors and warnings which include a snippet of your OpenAPI document now render that snippet as JSON, making them much easier to read.

📝Notes

Breaking changes for all custom templates

ALL custom templates are expected to break with this version as a result of the security fix.

  1. The utils global has been renamed to strings
  2. Most string values can no longer be rendered directly into templates, you must describe how the value is being used so it can be properly escaped using either a Python function or Jinja filter:
    1. strings.snake_case() / | snakecase (existing)
    2. strings.kebab_case() / | kebabcase (existing)
    3. strings.pascal_case() / | pascalcase (existing)
    4. python_identifier() (existing)
    5. class_name() (existing)
    6. strings.safe_for_docstring() / | safe_for_docstring for values which get injected into a """ docstring
    7. strings.in_f_string_literal() / | in_f_string_literal for values that go into f"" f-strings
    8. strings.in_double_quote_literal() / | in_double_quote_literal for values that go into non-f-string "" literals

... (truncated)

Commits
  • 4a2f3db Release 0.29.1 (#1460)
  • 1c99af4 Comprehensive string handling rewrite (#1483)
  • ee9a8c4 chore(deps): update pypa/gh-action-pypi-publish action to v1.14.2 (#1476)
  • edaae66 fix: Remove trailing spaces in README example code (#1475)
  • 2216c15 feat: Update uv_build to 0.12 when using --meta=uv (#1473)
  • 2aae596 fix: update generated code to use StrEnum and -> Self (#1474)
  • 468cfda chore(deps): update actions/checkout action to v7.0.1 (#1470)
  • 852116c chore(deps): pin dependencies (#1467)
  • d5c5367 chore(deps): update actions/cache action to v6.1.0 (#1468)
  • 0414726 Update Renovate configuration
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [openapi-python-client](https://github.com/openapi-generators/openapi-python-client) from 0.29.0 to 0.29.1.
- [Release notes](https://github.com/openapi-generators/openapi-python-client/releases)
- [Changelog](https://github.com/openapi-generators/openapi-python-client/blob/main/CHANGELOG.md)
- [Commits](openapi-generators/openapi-python-client@v0.29.0...v0.29.1)

---
updated-dependencies:
- dependency-name: openapi-python-client
  dependency-version: 0.29.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 1, 2026
@MattJackson

Copy link
Copy Markdown
Contributor

Merged into the bundle branch; continues in #7 (owner ruling: all dependabot PRs merge through one branch).

@MattJackson
MattJackson merged commit b57ed92 into dev Oct 2, 2026
1 of 2 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/dev/openapi-python-client-0.29.1 branch October 2, 2026 04:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant