Skip to content

deps(deps): bump the minor-and-patch group across 1 directory with 7 updates - #413

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/minor-and-patch-c186530c56
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/minor-and-patch-c186530c56

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 7 updates in the / directory:

Package From To
coverage 7.16.1 7.16.2
pytest-mock 3.15.1 3.16.0
markdown 3.10.3 3.11
psycopg-pool 3.3.2 3.3.3
sqlalchemy 2.0.54 2.1.1
uvicorn 0.53.0 0.54.0
werkzeug 3.1.8 3.1.9

Updates coverage from 7.16.1 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Commits

Updates pytest-mock from 3.15.1 to 3.16.0

Release notes

Sourced from pytest-mock's releases.

v3.16.0

2026-09-27

  • #604: Fixed duplicate_iterators=True for async functions spied with mocker.spy.
  • #611: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
  • #606: mocker.resetall(return_value=True, side_effect=True) now also applies to non-callable mocks, such as those returned by mocker.create_autospec(SomeClass, instance=True). Previously both arguments were silently ignored for them.
  • #547: Added SpyType for annotating mocker.spy results.
  • Dropped support for EOL Python 3.9.
  • #147: Removed handling of RuntimeError: stop called on unstarted patcher, which can no longer occur in the supported Python versions.
  • Added support for Python 3.15.
Changelog

Sourced from pytest-mock's changelog.

3.16.0

2026-09-27

  • [#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604>_: Fixed duplicate_iterators=True for async functions spied with mocker.spy.
  • [#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
  • [#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606>_: mocker.resetall(return_value=True, side_effect=True) now also applies to non-callable mocks, such as those returned by mocker.create_autospec(SomeClass, instance=True). Previously both arguments were silently ignored for them.
  • [#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547>_: Added SpyType for annotating mocker.spy results.
  • Dropped support for EOL Python 3.9.
  • [#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147>_: Removed handling of RuntimeError: stop called on unstarted patcher, which can no longer occur in the supported Python versions.
  • Added support for Python 3.15.
Commits

Updates markdown from 3.10.3 to 3.11

Release notes

Sourced from markdown's releases.

Release 3.11.0

Changed

  • Inline processors now resume searching after the previous match, improving performance for repeated inline patterns (#1619).
  • Officially support Python 3.15 and drop support for Python 3.10
  • Walk backtick runs in BacktickInlineProcessor without a regex (#1620).
  • Switch static site generator for documentation from MkDocs to Zensical (#1627, #1635, #1637, and #1638).

Fixed

  • Ensure removing Abbreviations does not raise an error (#1634).
  • Fix an issue with excessive backtracking when matching inline code blocks (#1617).
  • md_in_html now honors tags added to Markdown.block_level_elements after the extension is loaded (#1246).
  • Fix quadratic-time regex backtracking in ReferenceProcessor when a link reference definition has no URL, e.g. a line consisting only of [id]: followed by many trailing spaces (#798).
  • Document attr_list usage for def_list (#1123).
Changelog

Sourced from markdown's changelog.


title: Changelog toc_depth: 2

Python-Markdown Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to the Python Version Specification. See the Contributing Guide for details.

[Unreleased]

  • Update serializer to be non-recursive (#1644).
  • Improve ancestor handling in the inline Treeprocessor (#1646).

[3.11.0] - 2026-09-25

Changed

  • Inline processors now resume searching after the previous match, improving performance for repeated inline patterns (#1619).
  • Officially support Python 3.15 and drop support for Python 3.10
  • Walk backtick runs in BacktickInlineProcessor without a regex (#1620).
  • Switch static site generator for documentation from MkDocs to Zensical (#1627, #1635, #1637, and #1638).

Fixed

  • Ensure removing Abbreviations does not raise an error (#1634).
  • Fix an issue with excessive backtracking when matching inline code blocks (#1617).
  • md_in_html now honors tags added to Markdown.block_level_elements after the extension is loaded (#1246).
  • Fix quadratic-time regex backtracking in ReferenceProcessor when a link reference definition has no URL, e.g. a line consisting only of [id]: followed by many trailing spaces (#798).
  • Document attr_list usage for def_list (#1123).
Commits
  • 0ffbf00 Bump version to 3.11.0
  • 547a934 Show adminitions as rendered examples in contrbuting guide
  • 571f050 Cleanup archived changelog
  • a5176b0 Ensure py-render codeblock title in properly escaped.
  • 819fff9 Document the use of attr_list with def_list.
  • 36cdbd3 Final cleanup for Zensical transition
  • 8a96db5 Add py-render custom code block formater
  • 5d1363c Fix quadratic-time backtracking when a reference link has no URL
  • 0d6afd1 Add Markdown renderer as superfences formatter
  • 175fb5a Ensure removing Abbreviations does not raise an error.
  • Additional commits viewable in compare view

Updates psycopg-pool from 3.3.2 to 3.3.3

Changelog

Sourced from psycopg-pool's changelog.

.. currentmodule:: psycopg

.. index:: single: Release notes single: News

psycopg release notes

Future releases

Psycopg 3.3.7 (unreleased) ^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Fix segfault fetching arrays of strings or timestamps after closing the connection (:ticket:[#1428](https://github.com/psycopg/psycopg/issues/1428)).

Current release

Psycopg 3.3.6 ^^^^^^^^^^^^^

  • Add support for Python 3.15 (:ticket:[#1245](https://github.com/psycopg/psycopg/issues/1245)).
  • Improve performance of async queries by reducing the overhead of the !wait_async() function (:ticket:[#1331](https://github.com/psycopg/psycopg/issues/1331)).
  • Don't wait forever for a query to terminate after interrupting it, for instance if the server is unresponsive. The fix requires libpq 17 or newer (:ticket:[#1371](https://github.com/psycopg/psycopg/issues/1371)).
  • Cancel a running query upon receiving !SystemExit (:ticket:[#1384](https://github.com/psycopg/psycopg/issues/1384)).
  • Report !None instead of 65535 as the Column.precision of an :sql:interval column declared with a fields restriction and no explicit precision, such as e.g. :sql:interval day to second (:ticket:[#1397](https://github.com/psycopg/psycopg/issues/1397)).
  • Fix dumping of nested subclasses of lists as arrays (:ticket:[#1398](https://github.com/psycopg/psycopg/issues/1398)).
  • Discard prepared statements upon :sql:DEALLOCATE ALL (:ticket:[#1408](https://github.com/psycopg/psycopg/issues/1408)).
  • Better guards dumping large Python !int to binary numeric (:ticket:[#1414](https://github.com/psycopg/psycopg/issues/1414)).

Psycopg 3.3.5 ^^^^^^^^^^^^^

  • Discard prepared statements upon :sql:ALTER * or DISCARD * (:ticket:[#1307](https://github.com/psycopg/psycopg/issues/1307)).
  • Fix !ProgrammingError when dumping non-!None values with no !NoneType dumper registered in python implementation (:ticket:[#1325](https://github.com/psycopg/psycopg/issues/1325)).
  • Fix !wait_selector wait function to not raise !KeyError (:ticket:[#1327](https://github.com/psycopg/psycopg/issues/1327)).
  • Fix !DataError messages leaking the literal {...} placeholder instead

... (truncated)

Commits
  • 1a8f65a chore: bump psycopg package version to 3.3.3
  • db3c435 Merge pull request #1260 from ggevay/sync-error-fix
  • 0237586 Fix ValueError when server sends ErrorResponse during Sync after Parse
  • cb97ef7 docs: fix typos
  • 09c8918 Merge pull request #1256 from veeceey/fix/tstrings-error-msg-and-docs-improve...
  • 9e74d96 fix: fix error message incorrectly generated by Claude AI
  • 0db9d8b fix: correct typo in tstrings error message and fix sql.rst docs
  • 86a0e1b chore(deps): bump pypa/cibuildwheel in the actions group
  • f5d90fa Merge pull request #1233 from lysnikolaou/pgconn-critical-section
  • d7dc6c7 Merge critical section and nogil blocks into one context manager
  • Additional commits viewable in compare view

Updates sqlalchemy from 2.0.54 to 2.1.1

Release notes

Sourced from sqlalchemy's releases.

2.1.1

Released: September 25, 2026

platform

  • [platform] [bug] Removed the legacy underscore-separated extra names such as mssql_pymssql and postgresql_psycopg from pyproject.toml. They normalize to the same names as the existing dash-separated extras, which is disallowed by PEP 685, and caused the 2.1.0 source distribution to fail to build with installers that enforce this rule, such as uv. The underscore spellings continue to work when installing, as installers normalize extra names before matching them.

    References: #13604

2.1.0

Released: September 24, 2026

orm

  • [orm] [feature] Added _orm.composite.column_template parameter to _orm.composite(). When the composite class is a dataclass, this parameter accepts a string template such as "person_%s", containing exactly one %s placeholder, that's used to generate column names for dataclass fields that don't otherwise have an explicit name, rather than using the bare field name. This removes the need to hand-write a _orm.mapped_column() for each field when the same composite dataclass is mapped multiple times on the same class with different column-name prefixes. Pull request courtesy Leonardo Rosa.

    References: #12575

  • [orm] [bug] Fixed issue where pickling an ORM object that had an instance level lazy loader established, such as when the _orm.raiseload() option is used, would emit a spurious warning regarding the loader containing additional criteria, if the object had itself been unpickled from a previous serialization. This would occur for objects that cross more than one serialization boundary, such as when using multiprocessing.

    This change is also backported to: 2.0.53

    References: #13574

  • [orm] [bug] Fixed issue where calling _orm.aliased() against an existing _orm.aliased() construct, without passing an explicit selectable, would disregard the selectable of the existing construct and produce an

... (truncated)

Commits

Updates uvicorn from 0.53.0 to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)
Commits

Updates werkzeug from 3.1.8 to 3.1.9

Release notes

Sourced from werkzeug's releases.

3.1.9

This is the Werkzeug 3.1.9 security fix release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Werkzeug/3.1.9/ Changes: https://werkzeug.palletsprojects.com/page/changes/#version-3-1-9 Milestone: https://github.com/pallets/werkzeug/milestone/46?closed=1

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. GHSA-g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. #3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. #3189
  • Improve performance of parse_options_header. #3231
  • Improve performance of parse_etags. #3231
  • Improve performance of parse_cookie. #3231
  • get_host also checks that the port is in the valid range. #3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). #3237
  • Improve debugger PIN generation from cgroup data inside Podman. #3245
  • Authorization parsing basic auth disallows non-base64 characters. #3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. #3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. #3253
  • Rules with 10 or more converters in a single part assign matched values correctly. #3254
  • The invalid Range suffix length -0 is no longer accepted. #3255
Changelog

Sourced from werkzeug's changelog.

Version 3.1.9

Released 2026-09-27

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. :ghsa:g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. :issue:3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. :issue:3189
  • Improve performance of parse_options_header. :pr:3231
  • Improve performance of parse_etags. :pr:3231
  • Improve performance of parse_cookie. :pr:3231
  • get_host also checks that the port is in the valid range. :pr:3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). :issue:3237
  • Improve debugger PIN generation from cgroup data inside Podman. :issue:3245
  • Authorization parsing basic auth disallows non-base64 characters. :pr:3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. :pr:3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. :pr:3253
  • Rules with 10 or more converters in a single part assign matched values correctly. :pr:3254
  • The invalid Range suffix length -0 is no longer accepted. :pr:3255
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the minor-and-patch group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.16.1` | `7.16.2` |
| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` | `3.16.0` |
| [markdown](https://github.com/Python-Markdown/markdown) | `3.10.3` | `3.11` |
| [psycopg-pool](https://github.com/psycopg/psycopg) | `3.3.2` | `3.3.3` |
| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.54` | `2.1.1` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.53.0` | `0.54.0` |
| [werkzeug](https://github.com/pallets/werkzeug) | `3.1.8` | `3.1.9` |



Updates `coverage` from 7.16.1 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.1...7.16.2)

Updates `pytest-mock` from 3.15.1 to 3.16.0
- [Release notes](https://github.com/pytest-dev/pytest-mock/releases)
- [Changelog](https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest-mock@v3.15.1...v3.16.0)

Updates `markdown` from 3.10.3 to 3.11
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](Python-Markdown/markdown@3.10.3...3.11.0)

Updates `psycopg-pool` from 3.3.2 to 3.3.3
- [Changelog](https://github.com/psycopg/psycopg/blob/master/docs/news.rst)
- [Commits](psycopg/psycopg@3.3.2...3.3.3)

Updates `sqlalchemy` from 2.0.54 to 2.1.1
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

Updates `uvicorn` from 0.53.0 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.53.0...0.54.0)

Updates `werkzeug` from 3.1.8 to 3.1.9
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.8...3.1.9)

---
updated-dependencies:
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: pytest-mock
  dependency-version: 3.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: markdown
  dependency-version: '3.11'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: psycopg-pool
  dependency-version: 3.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: sqlalchemy
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: werkzeug
  dependency-version: 3.1.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added automated Opened by automation dependencies Dependency updates labels Oct 1, 2026
@jwvanderstam

Copy link
Copy Markdown
Owner

@dependabot recreate

@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 2, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/minor-and-patch-c186530c56 branch October 2, 2026 12:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Opened by automation dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant