Skip to content

chore(deps): bump the runtime-dependencies group across 1 directory with 3 updates - #105

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/runtime-dependencies-3eddd250d9
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/runtime-dependencies-3eddd250d9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown

Bumps the runtime-dependencies group with 3 updates in the / directory: sqlalchemy, ruff and openai-agents.

Updates sqlalchemy from 2.0.54 to 2.1.1

Release notes

Sourced from sqlalchemy's releases.

2.1.1

Released: September 25, 2026

platform

  • [platform] [bug] Removed the legacy underscore-separated extra names such as mssql_pymssql and postgresql_psycopg from pyproject.toml. They normalize to the same names as the existing dash-separated extras, which is disallowed by PEP 685, and caused the 2.1.0 source distribution to fail to build with installers that enforce this rule, such as uv. The underscore spellings continue to work when installing, as installers normalize extra names before matching them.

    References: #13604

2.1.0

Released: September 24, 2026

orm

  • [orm] [feature] Added _orm.composite.column_template parameter to _orm.composite(). When the composite class is a dataclass, this parameter accepts a string template such as "person_%s", containing exactly one %s placeholder, that's used to generate column names for dataclass fields that don't otherwise have an explicit name, rather than using the bare field name. This removes the need to hand-write a _orm.mapped_column() for each field when the same composite dataclass is mapped multiple times on the same class with different column-name prefixes. Pull request courtesy Leonardo Rosa.

    References: #12575

  • [orm] [bug] Fixed issue where pickling an ORM object that had an instance level lazy loader established, such as when the _orm.raiseload() option is used, would emit a spurious warning regarding the loader containing additional criteria, if the object had itself been unpickled from a previous serialization. This would occur for objects that cross more than one serialization boundary, such as when using multiprocessing.

    This change is also backported to: 2.0.53

    References: #13574

  • [orm] [bug] Fixed issue where calling _orm.aliased() against an existing _orm.aliased() construct, without passing an explicit selectable, would disregard the selectable of the existing construct and produce an

... (truncated)

Commits

Updates ruff from 0.16.7 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates openai-agents from 0.22.2 to 0.22.3

Release notes

Sourced from openai-agents's releases.

v0.22.3

What's Changed

Documentation & Other Changes

New Contributors

Full Changelog: openai/openai-agents-python@v0.22.2...v0.22.3

Changelog

Sourced from openai-agents's changelog.

Changelog

0.23.0 (2026-10-01)

Features

  • mcp: add configurable MCP listing page limits (#5133) (9a21ab1)
  • sandbox: add opt-in Docker removal protection (#5116) (ae5803f)
  • sandbox: allow configuring memory consolidation turns (#5135) (daa1bcb)
  • sessions: add an opt-in encrypted history scan budget (#5118) (a2fdb94)

Bug Fixes

  • avoid awaiting cleanup during coroutine closure (#5163) (719c4e7)
  • ci: update and group CodeQL actions together (#5262) (f76153c)
  • ci: validate release source before building distributions (#5220) (2747c1c)
  • core/extensions: respect sensitive trace capture for model metadata (#5129) (88b722d)
  • core: bound agent tool streaming callback backlogs (#5106) (f23da76)
  • core: isolate nested agent tool state across fresh runs (#5123) (46cc8d8)
  • core: preserve closed parent constraints in singleton allOf (#5131) (f010d18)
  • core: preserve guarded final outputs in agent tools (#5115) (f3a15f6)
  • core: preserve structured guardrail diagnostics and agent output during persistence (#5016) (51bcea7)
  • core: preserve tool identity during asynchronous enablement (#5136) (f2ae64c)
  • core: redact default tool failure details (#5112) (40956e0)
  • core: redact streaming task exception tracebacks (#5121) (c329e92)
  • core: reject silently discarded kwargs tool arguments (#5174) (a9b1ce7)
  • core: resolve tools after agent start hooks (#5124) (5237420)
  • core: restore nested agent tool state against the tool's own agent (#5142) (ad93f54)
  • core: retry pre-request WebSocket handshake failures (#4780) (265f16f)
  • core: scope function tool approvals to their owning agent (#5144) (de25d82)
  • core: select built-in shell and apply_patch tools by their own type (#4952) (eb68131)
  • core: serialize only traced fields in ModelSettings.to_traceable_dict (#5003) (57f0b38)
  • core: validate agent tool stream callbacks before execution (#5125) (fae72a4)
  • core: validate tool_use_behavior callback results (#5173) (5a2d63f)
  • deps-dev: bump coverage from 7.10.3 to 7.16.1 (#5152) (47c21ee)
  • deps-dev: bump cryptography from 50.0.0 to 50.0.1 (#5234) (e6c6806)
  • deps-dev: bump dapr from 1.16.0 to 1.18.3 (#5154) (e94309d)
  • deps-dev: bump pymongo from 4.16.0 to 4.18.1 (#5155) (971c5f3)
  • deps-dev: bump ruff from 0.9.2 to 0.16.8 (#5249) (9d2b318)
  • deps-dev: bump textual from 8.2.3 to 8.2.8 (#5248) (f2df6e4)
  • deps-dev: bump types-pynput from 1.8.1.20250809 to 1.8.1.20260712 (#5246) (582d048)
  • deps: bump actions/create-github-app-token from 2.2.2 to 3.2.0 (#5245) (e6467e2)
  • deps: bump anyio from 4.10.0 to 4.14.2 (#5091) (0910b46)
  • deps: bump astral-sh/setup-uv from 9.0.0 to 10.2.0 (#5252) (52aa07c)
  • deps: bump cbor2 from 5.9.0 to 6.1.4 (#5153) (34952bc)
  • deps: bump pyjwt from 2.13.0 to 2.15.0 (#5271) (dc81a17)
  • deps: bump runloop-api-client from 1.31.0 to 1.32.0 (#5156) (32edd3c)
  • deps: bump temporalio from 1.26.0 to 1.33.0 (#5233) (6b5bad7)

... (truncated)

Commits
  • fdf21db release: 0.22.3 (#5077)
  • e34311b docs(examples): drop the duplicated word in the Temporal trace name (#5079)
  • 1d17ca4 fix(core): align conditional approvals with validated tool arguments (#5066)
  • 58a6d2c docs: update translated pages (#5065)
  • 9f6f6b1 docs: clarify Unix-local execution boundaries (#5064)
  • d59fdb8 fix(tracing): do not cache a missing OPENAI_API_KEY (#5017)
  • f03103a Add SDKs team as repository code owner (#5058)
  • 5f9899d fix(deps): update starlette requirement from >=1.3.1 to >=1.6.0 in /examples/...
  • 40a9888 fix(deps): bump starlette from 1.3.1 to 1.6.0 (#5038)
  • bcda491 fix(deps): bump runloop-api-client from 1.16.0 to 1.31.0 (#5037)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/runtime-dependencies-3eddd250d9 branch from 7c2cf61 to 9743dfa Compare October 1, 2026 15:43
…ith 3 updates

Bumps the runtime-dependencies group with 3 updates in the / directory: [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy), [ruff](https://github.com/astral-sh/ruff) and [openai-agents](https://github.com/openai/openai-agents-python).


Updates `sqlalchemy` from 2.0.54 to 2.1.1
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

Updates `ruff` from 0.16.7 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.7...0.16.9)

Updates `openai-agents` from 0.22.2 to 0.22.3
- [Release notes](https://github.com/openai/openai-agents-python/releases)
- [Changelog](https://github.com/openai/openai-agents-python/blob/main/CHANGELOG.md)
- [Commits](openai/openai-agents-python@v0.22.2...v0.22.3)

---
updated-dependencies:
- dependency-name: openai-agents
  dependency-version: 0.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime-dependencies
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime-dependencies
- dependency-name: sqlalchemy
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/runtime-dependencies-3eddd250d9 branch from 9743dfa to c0de6bb Compare October 2, 2026 13:18

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants