Skip to content

chore(deps): bump the patch-and-minor group across 1 directory with 179 updates - #522

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend/patch-and-minor-0aec07e48f
Open

chore(deps): bump the patch-and-minor group across 1 directory with 179 updates#522
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend/patch-and-minor-0aec07e48f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the patch-and-minor group with 179 updates in the /backend directory:

Package From To
fastapi 0.135.3 0.141.1
uvicorn 0.35.0 0.52.4
sqlalchemy 2.0.48 2.0.52
alembic 1.18.4 1.19.1
asyncpg 0.30.0 0.31.0
psycopg2-binary 2.9.10 2.9.12
gitpython 3.1.50 3.1.61
pyjwt 2.12.0 2.13.0
authlib 1.6.11 1.8.0
prometheus-client 0.22.1 0.26.0
opentelemetry-api 1.40.0 1.44.0
opentelemetry-sdk 1.40.0 1.44.0
opentelemetry-distro 0.61b0 0.65b0
opentelemetry-exporter-otlp 1.40.0 1.44.0
opentelemetry-exporter-otlp-proto-common 1.40.0 1.44.0
opentelemetry-exporter-otlp-proto-grpc 1.40.0 1.44.0
opentelemetry-exporter-otlp-proto-http 1.40.0 1.44.0
opentelemetry-instrumentation 0.61b0 0.65b0
opentelemetry-instrumentation-asgi 0.61b0 0.65b0
opentelemetry-instrumentation-fastapi 0.61b0 0.65b0
opentelemetry-instrumentation-httpx 0.61b0 0.65b0
opentelemetry-instrumentation-logging 0.61b0 0.65b0
opentelemetry-instrumentation-redis 0.61b0 0.65b0
opentelemetry-instrumentation-sqlalchemy 0.61b0 0.65b0
opentelemetry-instrumentation-system-metrics 0.61b0 0.65b0
opentelemetry-instrumentation-celery 0.61b0 0.65b0
opentelemetry-proto 1.40.0 1.44.0
opentelemetry-semantic-conventions 0.61b0 0.65b0
opentelemetry-util-http 0.61b0 0.65b0
langgraph 1.1.0 1.2.11
langgraph-prebuilt 1.0.8 1.1.0
langgraph-checkpoint 4.0.1 4.2.0
langgraph-sdk 0.3.13 0.4.4
langchain-community 0.3.5 0.4.2
langserve 0.2.1 0.3.3
celery 5.6.2 5.6.3
chromadb 1.0.15 1.5.9
eth-account 0.13.0 0.14.0
eth-keys 0.7.1 0.8.0
aiohttp 3.13.4 3.14.3
requests 2.33.0 2.34.2
python-socketio 5.14.0 5.16.4
python-engineio 4.12.2 4.14.0
python-multipart 0.0.26 0.0.32
discord-py 2.5.2 2.7.1
py-cord 2.6.1 2.8.1
docker 7.1.0 7.2.0
click 8.2.1 8.5.0
typer 0.16.0 0.27.2
python-dotenv 1.2.2 1.2.3
apscheduler 3.11.2 3.11.3
slowapi 0.1.9 0.1.10
colorlog 6.9.0 6.12.0
beautifulsoup4 4.13.4 4.15.0
lxml 6.1.0 6.1.3
feedparser 6.0.11 6.0.14
numpy 2.3.2 2.5.2
matplotlib 3.10.5 3.11.1
scipy 1.16.1 1.18.1
scikit-learn 1.7.1 1.9.0
strawberry-graphql 0.312.3 0.327.2
graphql-core 3.2.8 3.2.12
qiskit 2.3.1 2.5.2
networkx 3.5 3.6.1
onnxruntime 1.22.1 1.29.0
pyyaml 6.0.2 6.0.3
durationpy 0.10 0.11
levenshtein 0.27.3 0.27.4
rapidfuzz 3.14.3 3.14.6
pytest 9.0.2 9.1.1
pytest-benchmark 5.1.0 5.3.0
hypothesis 6.131.0 6.167.1
black 26.3.1 26.5.1
ruff 0.9.0 0.16.6
pylint 4.0.5 4.0.8
bandit 1.8.6 1.9.4
semgrep 1.92.0 1.176.0
pip-audit 2.8.0 2.10.1
autogen 0.5.0 0.14.1
aiohappyeyeballs 2.6.1 2.7.1
annotated-doc 0.0.4 0.0.5
annotated-types 0.7.0 0.8.0
anyio 4.9.0 4.15.0
arq 0.27.0 0.28.0
asgiref 3.11.1 3.12.1
astroid 4.0.4 4.3.1
bidict 0.23.1 0.24.1
boto3 1.42.64 1.43.88
botocore 1.42.64 1.43.88
build 1.3.0 1.6.0
cffi 2.0.0 2.1.1
charset-normalizer 3.4.2 3.5.1
coverage 7.13.4 7.16.0
cross-web 0.4.1 0.7.0
decorator 5.2.1 5.3.1
deprecated 1.2.18 1.3.1
docstring-parser 0.17.0 0.18.0
fabric 3.2.2 3.2.3
fakeredis 2.33.0 2.37.1
filelock 3.20.3 3.32.5
flask-cors 6.0.1 6.0.5
flask-socketio 5.5.1 5.6.1
flatbuffers 25.2.10 25.12.19
fonttools 4.60.2 4.64.0
frozenlist 1.7.0 1.8.0
fsspec 2026.3.0 2026.7.0
geographiclib 2.0 2.1
geopy 2.4.1 2.5.0
google-auth 2.40.3 2.57.1
googleapis-common-protos 1.70.0 1.75.3
greenlet 3.3.2 3.5.5
grpcio 1.74.0 1.83.1
hiredis 3.3.0 3.4.1
httptools 0.6.4 0.8.0
idna 3.10 3.19
iniconfig 2.1.0 2.3.0
jaraco-context 6.1.0 6.1.2
jiter 0.10.0 0.16.0
joblib 1.5.1 1.6.0
jsonpointer 3.0.0 3.1.1
jsonschema 4.25.0 4.26.0
jsonschema-specifications 2025.4.1 2025.9.1
kiwisolver 1.4.8 1.5.1
mako 1.3.12 1.4.1
markupsafe 3.0.2 3.0.3
mmh3 5.2.0 5.3.0
mpmath 1.3.0 1.4.1
msgpack 1.1.2 1.2.2
multidict 6.6.3 6.7.1
narwhals 2.0.1 2.25.0
orjson 3.11.7 3.12.0
pathspec 1.1.0 1.1.1
pip-tools 7.5.3 7.6.1
platformdirs 4.9.4 4.11.7
prompt-toolkit 3.0.52 3.0.53
propcache 0.3.2 0.5.2
pyasn1 0.6.3 0.6.4
pybase64 1.4.2 1.5.0
pydeck 0.9.1 0.9.3
pygithub 2.9.0 2.10.0
pygments 2.20.0 2.21.0
pyparsing 3.2.3 3.3.2
pypika 0.48.9 0.51.1
pyreadline3 3.5.4 3.5.6
python-levenshtein 0.27.3 0.27.4
referencing 0.36.2 0.37.0
ruamel-yaml 0.18.14 0.19.1
ruamel-yaml-clib 0.2.12 0.2.15
rustworkx 0.17.1 0.18.1
s3transfer 0.16.0 0.19.2
safehttpx 0.1.6 0.1.7
smmap 5.0.2 5.0.3
soupsieve 2.7 2.9.2
stevedore 5.4.1 5.9.1
tomlkit 0.13.3 0.15.1
tornado 6.5.5 6.5.8
tqdm 4.67.1 4.70.0
types-requests 2.32.4.20260107 2.33.0.20260712
typing-inspection 0.4.2 0.4.4
typing-extensions 4.14.1 4.16.0
tzlocal 5.3.1 5.4.4
uuid-utils 0.14.1 0.17.0
watchfiles 1.1.0 1.2.0
wcwidth 0.5.3 0.8.3
websocket-client 1.8.0 1.9.2
werkzeug 3.1.6 3.1.8
wheel 0.46.2 0.48.0
wsproto 1.2.0 1.3.2
yarl 1.20.1 1.24.5
safety 3.2.0 3.8.1
accelerate 1.10.0 1.14.0
bitsandbytes 0.46.1 0.50.2
langchain-text-splitters 1.1.1 1.1.2
langsmith 0.7.16 0.12.1
nltk 3.9.1 3.10.3
safetensors 0.5.3 0.8.0
streamlit 1.54.0 1.63.0
tokenizers 0.21.4 0.23.2
torch 2.8.0 2.14.0

Updates fastapi from 0.135.3 to 0.141.1

Release notes

Sourced from fastapi's releases.

0.141.1

Fixes

  • 🐛 Fix support for background tasks and headers from dependencies in app.frontend(). PR #16105 by @​tiangolo.

Docs

0.141.0

Features

  • ✨ Add app.frontend(check_dir="auto"), to make local development more convenient with fastapi dev. PR #16102 by @​tiangolo.

0.140.13

Fixes

Docs

0.140.12

Fixes

0.140.11

Fixes

  • 🐛 Fix response_model_* params ignored for non-generator endpoints with Iterable[..] return type. PR #15093 by @​YuriiMotov.

0.140.10

Fixes

Internal

0.140.9

Fixes

  • 🐛 Fix exclude_defaults not propagated to dict keys and values in jsonable_encoder. PR #16043 by @​MBGrao.

... (truncated)

Commits
  • 95f8322 🔖 Release version 0.141.1 (#16106)
  • f137944 📝 Update release notes
  • d623544 🐛 Fix support for background tasks and headers from dependencies in `app.fron...
  • 1d211b9 📝 Update release notes
  • 8a1f876 📝 Document FASTAPI_ENV in FastAPI CLI guide (#16104)
  • c7e7b65 🔖 Release version 0.141.0 (#16103)
  • 6bceb84 📝 Update release notes
  • 5429fed ✨ Add app.frontend(check_dir="auto"), to make local development more conven...
  • 628663f 🔖 Release version 0.140.13 (#16096)
  • 0b54fd0 📝 Update release notes
  • Additional commits viewable in compare view

Updates uvicorn from 0.35.0 to 0.52.4

Release notes

Sourced from uvicorn's releases.

Version 0.52.4

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

Full Changelog: Kludex/uvicorn@0.52.3...0.52.4

Version 0.52.3

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

Full Changelog: Kludex/uvicorn@0.52.2...0.52.3

Version 0.52.2

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

Full Changelog: Kludex/uvicorn@0.52.1...0.52.2

Version 0.52.1

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#3041)

Full Changelog: Kludex/uvicorn@0.52.0...0.52.1

Version 0.52.0

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added

  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#2979)

Fixed

  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#3036)

Full Changelog: Kludex/uvicorn@0.51.0...0.52.0

Version 0.51.0

What's Changed

... (truncated)

Changelog

Sourced from uvicorn's changelog.

0.52.4 (August 18, 2026)

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

0.52.3 (August 13, 2026)

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

0.52.2 (August 13, 2026)

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

0.52.1 (August 1, 2026)

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#3041)

0.52.0 (July 29, 2026)

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added

  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#2979)

Fixed

  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#3036)

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

... (truncated)

Commits

Updates sqlalchemy from 2.0.48 to 2.0.52

Release notes

Sourced from sqlalchemy's releases.

2.0.52

Released: August 11, 2026

platform

  • [platform] [bug] Python 3.15 support has been added and tested, including minimal changes for full compatibility.

    References: #13477

orm

  • [orm] [bug] Fixed a result-column misalignment bug in ORM-enabled UPDATE statements where synchronize_session="fetch" is in use, either explicitly or because the statement uses constructs such as CTEs that implicitly select for it. Columns in rows returned by .returning() could be returned under incorrect keys (e.g. row[SomeClass.a] returning the value of a different column), a problem most likely to manifest under concurrent workloads. ORM DELETE statements were not affected.

    References: #13439

  • [orm] [bug] Fixed bug where a failed _orm.Session.bulk_insert_mappings(), _orm.Session.bulk_update_mappings() or _orm.Session.bulk_save_objects() call could leave the _orm.Session permanently in a "flushing" state, such as when the transaction could not be begun because a previous flush had left it needing a rollback. Unlike _orm.Session.flush(), the bulk methods set the internal flushing flag and began the transaction outside of the try/finally block that resets it, so that neither _orm.Session.rollback() nor _orm.Session.close() would clear it, and every subsequent flush would raise InvalidRequestError: Session is already flushing. Pull request courtesy Hamody We.

    References: #13485

  • [orm] [bug] Fixed issue where unpickling an ORM object that were loaded using loader options making use of wildcard tokens, such as _orm.load_only() or _orm.raiseload() with "*", would fail with KeyError or IndexError if the process doing the unpickling had not yet constructed a loader path making use of that same token. This would typically be observed when the object were unpickled in a separate process, such as with the spawn or forkserver multiprocessing start methods, the latter of which became the default on POSIX platforms as of Python 3.14. The internal collection of these tokens is now established up front, so that it is identical in every process.

... (truncated)

Commits

Updates alembic from 1.18.4 to 1.19.1

Release notes

Sourced from alembic's releases.

1.19.1

Released: August 8, 2026

bug

  • [bug] [autogenerate] Fixed bug in the check constraint detection implemented in #508 that failed to take into account column bound check constraints, leading to wrong autogenerate detections.

    References: #1842

1.19.0

Released: August 4, 2026

changed

  • [changed] [installation] Environmental updates:

    -   Trove classifiers now include Python 3.15 which is now part of CI
        integration
    
    • Python 3.14 is also added to trove classifiers which had been previously omitted

    • Implemented PEP 604 style unions in type annotations

feature

  • [feature] [autogenerate] Autogenerate now detects the addition and removal of named CHECK constraints, as part of the default autogenerate behavior. Detection is name-based only; a constraint whose name is unchanged is presumed equivalent regardless of its expression text, as reliably normalizing SQL expressions across backends for comparison purposes is not generally feasible. This behavior is implemented as a plugin named alembic.autogenerate.checkconstraint_byname, and may be disabled if not desired by excluding it from the EnvironmentContext.configure.autogenerate_plugins list. Pull request courtesy Francois van Kempen.

    References: #508

bug

... (truncated)

Commits

Updates asyncpg from 0.30.0 to 0.31.0

Release notes

Sourced from asyncpg's releases.

v0.31.0

Enable Python 3.14 with experimental subinterpreter/freethreading support.

Improvements

  • Add Python 3.14 support, experimental subinterpreter/freethreading support (#1279) (by @​elprans in 9e42642b)

  • Avoid performing type introspection on known types (#1243) (by @​elprans in 5c9986c4)

  • Make prepare() not use named statements by default when cache is disabled (#1245) (by @​elprans in 5b14653e)

  • Implement connection service file functionality (#1223) (by @​AndrewJackson2020 in 1d63bb15)

Fixes

Other

Commits

Updates psycopg2-binary from 2.9.10 to 2.9.12

Changelog

Sourced from psycopg2-binary's changelog.

Current release

What's new in psycopg 2.9.12 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Fix infinite loop with malformed interval (:ticket:1835).

What's new in psycopg 2.9.11 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Add support for Python 3.14.
  • Avoid a segfault passing more arguments than placeholders if Python is built with assertions enabled (:ticket:[#1791](https://github.com/psycopg/psycopg2/issues/1791)).
  • Add riscv64 platform binary packages (:ticket:[#1813](https://github.com/psycopg/psycopg2/issues/1813)).
  • ~psycopg2.errorcodes map and ~psycopg2.errors classes updated to PostgreSQL 18.
  • Drop support for Python 3.8.

What's new in psycopg 2.9.10 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Add support for Python 3.13.
  • Receive notifications on commit (:ticket:[#1728](https://github.com/psycopg/psycopg2/issues/1728)).
  • ~psycopg2.errorcodes map and ~psycopg2.errors classes updated to PostgreSQL 17.
  • Drop support for Python 3.7.

What's new in psycopg 2.9.9 ^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Add support for Python 3.12.
  • Drop support for Python 3.6.

What's new in psycopg 2.9.8 ^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Wheel package bundled with PostgreSQL 16 libpq in order to add support for recent features, such as sslcertmode.

What's new in psycopg 2.9.7 ^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Fix propagation of exceptions raised during module initialization (:ticket:[#1598](https://github.com/psycopg/psycopg2/issues/1598)).

... (truncated)

Commits
  • 3a6d9d6 ci: include almalinux in whieel building
  • ebca6bf chore: bump to version 3.9.12
  • 0196f02 build(deps): bump pypa/cibuildwheel from 3.3.1 to 3.4.0
  • d157bdc build(deps): bump docker/setup-qemu-action from 3 to 4
  • 7fccc0f build(deps): bump actions/upload-artifact from 6 to 7
  • d52a61e chore: bump dependency libraries
  • b231d72 chore: fix building binary images
  • 6d76e84 Merge pull request #1836 from psycopg/fix-1835
  • f7e314c fix: overflow in malformed interval
  • eb905c1 docs: replace bare except clause with except Exception
  • Additional commits viewable in compare view

Updates gitpython from 3.1.50 to 3.1.61

Release notes

Sourced from gitpython's releases.

3.1.61

Fix accidental removal of exploitable regex in Actor by bringing it back, and deprecating it.

What's Changed

New Contributors

Full Changelog: gitpython-developers/GitPython@3.1.60...3.1.61

3.1.60 Security

What's Changed

Full Changelog: gitpython-developers/GitPython@3.1.59...3.1.60

3.1.59 - Security

What's Changed

Full Changelog: gitpython-developers/GitPython@3.1.58...3.1.59

3.1.58 - Security and Fixes

What's Changed

New Contributors

... (truncated)

Commits
  • 5346d1b prepare next release
  • d81336b Merge pull request #2221 from gitpython-developers/re-add-regex
  • bc63b02 fix: restore Actor.name_email_regex (#2220)
  • a9fb008 Merge pull request #2219 from Vogtinator/main
  • db1a2cf fix: wait for git daemon to listen before connecting
  • 3481da9 Merge pull request #2218 from gitpython-developers/fix-repo-open
  • 56636c3 prepare new release
  • c7cf4d1 fix: prefer .git during repository discovery
  • d160fb4 Merge pull request #2217 from gitpython-developers/fix-advisory
  • 09f2cf3 fix: require opt-in for no-index diffs
  • Additional commits viewable in compare view

Updates pyjwt from 2.12.0 to 2.13.0

Release notes

Sourced from pyjwt's releases.

2.13.0

PyJWT 2.13.0 — Security Release

This release bundles five security fixes plus three additional hardening / spec-compliance changes. We recommend all users upgrade.

Security

  • GHSA-xgmm-8j9v-c9wx — JWK JSON accepted as HMAC secret (algorithm confusion). HMACAlgorithm.prepare_key previously rejected PEM- and SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON string. In a verifier configured with both symmetric and asymmetric algorithms in algorithms=[…] and a raw-JSON JWK as the key, an attacker could forge HS256 tokens using the JWK text as the HMAC secret. The guard has been extended to reject any JWK-shaped JSON. Reported by @​aradona91.

  • GHSA-jq35-7prp-9v3f — Algorithm allow-list bypass with PyJWK / PyJWKClient. When verifying with a PyJWK, the caller's algorithms=[…] allow-list was checked against the token header alg as a string only; actual verification used the algorithm bound to the PyJWK. An attacker who controlled a registered JWKS key could sign with one algorithm and advertise another on the header. PyJWT now requires the token header alg to match the PyJWK's algorithm before verification. Reported by @​sushi-gif.

  • GHSA-w7vc-732c-9m39 — DoS via base64 decode of unused payload segment when b64=false. For detached-payload JWS (b64=false), the compact-form payload segment was base64-decoded before being discarded in favor of the caller-supplied detached_payload. An attacker could inflate the unused segment to force CPU + memory cost without holding a valid signature. The segment is now required to be empty per RFC 7515 Appendix F, and is no longer decoded. Reported by @​thesmartshadow.

  • GHSA-993g-76c3-p5m4PyJWKClient accepts non-HTTP(S) URIs. PyJWKClient.fetch_data passed its URI to urllib.request.urlopen, which by default also handles file://, ftp://, and data: schemes. An application that fed an attacker-influenced URI into PyJWKClient could be coerced into reading local files or reaching other unintended schemes. PyJWKClient now rejects any URI whose scheme isn't http or https. Reported by @​KEIJOT.

  • GHSA-fhv5-28vv-h8m8PyJWKClient cache wiped on fetch error. A finally-block put(jwk_set=None) cleared the JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint outage into application-wide auth failure. The cache write was moved into the success path; transient errors no longer evict valid cached keys. Reported by @​eddieran.

Fixed

  • Reject empty HMAC keys outright in HMACAlgorithm.prepare_key with InvalidKeyError instead of accepting them with only a warning. Defends against the os.getenv("JWT_SECRET", "") footgun. Thanks to @​SnailSploit and @​spartan8806 for the reports.
  • Forward per-call options (including enforce_minimum_key_length) from PyJWT.decode through to PyJWS._verify_signature. The option was previously silently dropped between the two layers, so it only took effect when set on the PyJWT instance. Thanks to @​WLUB for the report.
  • RFC 7797 §3 compliance for b64=false: the encoder now auto-adds "b64" to crit, and the decoder rejects tokens that set b64=false without listing it in crit. Thanks to @​MachineLearning-Nerd for the report.

Changed

  • Migrate the dev, docs, and tests package extras to dependency groups, by @​kurtmckee in #1152.

Upgrade notes

Most fixes are invisible to correctly-configured callers. A few behavioral changes you may encounter:

  • Empty HMAC keys now raise. If your app passed "" or b"" as a secret (often via a missing env var, e.g. os.getenv("JWT_SECRET", "")), encode/decode will now raise InvalidKeyError. This is the intended behavior — fix the configuration.
  • PyJWK decoding now requires the token's alg to match the JWK's algorithm. Previously a mismatch was silently honored if the header alg appeared in the allow-list. Tokens that relied on this mismatch will now fail with InvalidAlgorithmError.
  • PyJWKClient now rejects non-HTTP(S) URIs at construction time. Tests or dev environments that fetched JWKS from file:// URIs need to switch to a local HTTP server or load the JWKS by other means (e.g. construct PyJWKSet.from_dict(...) directly).
  • b64=false tokens are now strictly RFC 7515 / 7797 compliant. Tokens with a non-empty compact-form payload segment, or that omit "b64" from crit, will be rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips through PyJWT are unaffected.
  • enforce_minimum_key_length set per-call now takes effect. Callers who passed options={"enforce_minimum_key_length": True} to jwt.decode() previously got no enforcement; they will now get InvalidKeyError on undersized keys, as documented.

Full changelog: jpadilla/pyjwt@2.12.1...2.13.0

2.12.1

What's Changed

Full Changelog: jpadilla/pyjwt@2.12.0...2.12.1

Changelog

Sourced from pyjwt's changelog.

v2.13.0 <https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0>__

Security


- Reject JWK JSON documents passed as raw HMAC secrets in
  ``HMACAlgorithm.prepare_key`` to close an algorithm-confusion gap that
  the existing PEM/SSH guard did not cover. Reported by @aradona91 in
  `GHSA-xgmm-8j9v-c9wx <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx>`__.
- Bind the JWT header ``alg`` to ``PyJWK.algorithm_name`` during
  verification so the caller's ``algorithms=[...]`` allow-list cannot be
  bypassed when decoding with a ``PyJWK`` / ``PyJWKClient`` key. Reported
  by @sushi-gif in `GHSA-jq35-7prp-9v3f <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f>`__.
- Reject non-``http(s)`` URI schemes in ``PyJWKClient`` so attacker-
  influenced URIs cannot read local files or reach unintended schemes via
  urllib's default ``file://`` / ``ftp://`` / ``data:`` handlers. Reported
  by @KEIJOT in `GHSA-993g-76c3-p5m4 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4>`__.
- Preserve the cached JWK Set on fetch errors in ``PyJWKClient.fetch_data``.
  The previous ``finally``-block ``put(None)`` pattern cleared the cache
  on any transient outage, turning one bad JWKS request into application-
  wide auth failure. Reported by @eddieran in `GHSA-fhv5-28vv-h8m8 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8>`__.
- Skip the unconditional base64 decode of the compact-form payload segment
  when ``b64=false`` is set in the protected header, and require that
  segment to be empty (RFC 7515 Appendix F detached form). Closes an
  unauthenticated DoS amplifier. Reported by @thesmartshadow in
  `GHSA-w7vc-732c-9m39 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39>`__.

Fixed


- Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with
  ``InvalidKeyError`` instead of accepting them with only a warning.
  Thanks to @SnailSploit and @spartan8806 for independently flagging the
  footgun.
- Forward per-call ``options`` (including ``enforce_minimum_key_length``)
  from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the
  option ...

Description has been truncated

@dependabot @github

dependabot Bot commented on behalf of github Sep 5, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

…79 updates

Bumps the patch-and-minor group with 179 updates in the /backend directory:

| Package | From | To |
| --- | --- | --- |
| [fastapi](https://github.com/fastapi/fastapi) | `0.135.3` | `0.141.1` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.52.4` |
| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.48` | `2.0.52` |
| [alembic](https://github.com/sqlalchemy/alembic) | `1.18.4` | `1.19.1` |
| [asyncpg](https://github.com/MagicStack/asyncpg) | `0.30.0` | `0.31.0` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.10` | `2.9.12` |
| [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.50` | `3.1.61` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.12.0` | `2.13.0` |
| [authlib](https://github.com/authlib/authlib) | `1.6.11` | `1.8.0` |
| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.1` | `0.26.0` |
| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.40.0` | `1.44.0` |
| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.40.0` | `1.44.0` |
| [opentelemetry-distro](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.61b0` | `0.65b0` |
| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python) | `1.40.0` | `1.44.0` |
| [opentelemetry-exporter-otlp-proto-common](https://github.com/open-telemetry/opentelemetry-python) | `1.40.0` | `1.44.0` |
| [opentelemetry-exporter-otlp-proto-grpc](https://github.com/open-telemetry/opentelemetry-python) | `1.40.0` | `1.44.0` |
| [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) | `1.40.0` | `1.44.0` |
| [opentelemetry-instrumentation](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.61b0` | `0.65b0` |
| [opentelemetry-instrumentation-asgi](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.61b0` | `0.65b0` |
| [opentelemetry-instrumentation-fastapi](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.61b0` | `0.65b0` |
| [opentelemetry-instrumentation-httpx](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.61b0` | `0.65b0` |
| [opentelemetry-instrumentation-logging](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.61b0` | `0.65b0` |
| [opentelemetry-instrumentation-redis](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.61b0` | `0.65b0` |
| [opentelemetry-instrumentation-sqlalchemy](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.61b0` | `0.65b0` |
| [opentelemetry-instrumentation-system-metrics](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.61b0` | `0.65b0` |
| [opentelemetry-instrumentation-celery](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.61b0` | `0.65b0` |
| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.40.0` | `1.44.0` |
| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.61b0` | `0.65b0` |
| [opentelemetry-util-http](https://github.com/open-telemetry/opentelemetry-python-contrib) | `0.61b0` | `0.65b0` |
| [langgraph](https://github.com/langchain-ai/langgraph) | `1.1.0` | `1.2.11` |
| [langgraph-prebuilt](https://github.com/langchain-ai/langgraph) | `1.0.8` | `1.1.0` |
| [langgraph-checkpoint](https://github.com/langchain-ai/langgraph) | `4.0.1` | `4.2.0` |
| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.3.13` | `0.4.4` |
| [langchain-community](https://github.com/langchain-ai/langchain-community) | `0.3.5` | `0.4.2` |
| [langserve](https://github.com/langchain-ai/langserve) | `0.2.1` | `0.3.3` |
| [celery](https://github.com/celery/celery) | `5.6.2` | `5.6.3` |
| [chromadb](https://github.com/chroma-core/chroma) | `1.0.15` | `1.5.9` |
| [eth-account](https://github.com/ApeWorX/eth-account) | `0.13.0` | `0.14.0` |
| [eth-keys](https://github.com/ApeWorX/eth-keys) | `0.7.1` | `0.8.0` |
| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.4` | `3.14.3` |
| [requests](https://github.com/psf/requests) | `2.33.0` | `2.34.2` |
| [python-socketio](https://github.com/miguelgrinberg/python-socketio) | `5.14.0` | `5.16.4` |
| [python-engineio](https://github.com/miguelgrinberg/python-engineio) | `4.12.2` | `4.14.0` |
| [python-multipart](https://github.com/Kludex/python-multipart) | `0.0.26` | `0.0.32` |
| [discord-py](https://github.com/Rapptz/discord.py) | `2.5.2` | `2.7.1` |
| [py-cord](https://github.com/Pycord-Development/pycord) | `2.6.1` | `2.8.1` |
| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |
| [click](https://github.com/pallets/click) | `8.2.1` | `8.5.0` |
| [typer](https://github.com/fastapi/typer) | `0.16.0` | `0.27.2` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |
| [apscheduler](https://github.com/agronholm/apscheduler) | `3.11.2` | `3.11.3` |
| [slowapi](https://github.com/laurents/slowapi) | `0.1.9` | `0.1.10` |
| [colorlog](https://github.com/borntyping/python-colorlog) | `6.9.0` | `6.12.0` |
| [beautifulsoup4](https://www.crummy.com/software/BeautifulSoup/bs4/) | `4.13.4` | `4.15.0` |
| [lxml](https://github.com/lxml/lxml) | `6.1.0` | `6.1.3` |
| [feedparser](https://github.com/kurtmckee/feedparser) | `6.0.11` | `6.0.14` |
| [numpy](https://github.com/numpy/numpy) | `2.3.2` | `2.5.2` |
| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.10.5` | `3.11.1` |
| [scipy](https://github.com/scipy/scipy) | `1.16.1` | `1.18.1` |
| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.7.1` | `1.9.0` |
| [strawberry-graphql](https://github.com/sponsors/strawberry-graphql) | `0.312.3` | `0.327.2` |
| [graphql-core](https://github.com/graphql-python/graphql-core) | `3.2.8` | `3.2.12` |
| [qiskit](https://github.com/Qiskit/qiskit) | `2.3.1` | `2.5.2` |
| [networkx](https://github.com/networkx/networkx) | `3.5` | `3.6.1` |
| [onnxruntime](https://github.com/microsoft/onnxruntime) | `1.22.1` | `1.29.0` |
| [pyyaml](https://github.com/yaml/pyyaml) | `6.0.2` | `6.0.3` |
| [durationpy](https://github.com/icholy/durationpy) | `0.10` | `0.11` |
| [levenshtein](https://github.com/rapidfuzz/Levenshtein) | `0.27.3` | `0.27.4` |
| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.14.3` | `3.14.6` |
| [pytest](https://github.com/pytest-dev/pytest) | `9.0.2` | `9.1.1` |
| [pytest-benchmark](https://github.com/ionelmc/pytest-benchmark) | `5.1.0` | `5.3.0` |
| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.167.1` |
| [black](https://github.com/psf/black) | `26.3.1` | `26.5.1` |
| [ruff](https://github.com/astral-sh/ruff) | `0.9.0` | `0.16.6` |
| [pylint](https://github.com/pylint-dev/pylint) | `4.0.5` | `4.0.8` |
| [bandit](https://github.com/PyCQA/bandit) | `1.8.6` | `1.9.4` |
| [semgrep](https://github.com/semgrep/semgrep) | `1.92.0` | `1.176.0` |
| [pip-audit](https://github.com/pypa/pip-audit) | `2.8.0` | `2.10.1` |
| [autogen](https://github.com/ag2ai/ag2classic) | `0.5.0` | `0.14.1` |
| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |
| [annotated-doc](https://github.com/fastapi/annotated-doc) | `0.0.4` | `0.0.5` |
| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |
| [anyio](https://github.com/agronholm/anyio) | `4.9.0` | `4.15.0` |
| [arq](https://github.com/python-arq/arq) | `0.27.0` | `0.28.0` |
| [asgiref](https://github.com/django/asgiref) | `3.11.1` | `3.12.1` |
| [astroid](https://github.com/pylint-dev/astroid) | `4.0.4` | `4.3.1` |
| [bidict](https://github.com/jab/bidict) | `0.23.1` | `0.24.1` |
| [boto3](https://github.com/boto/boto3) | `1.42.64` | `1.43.88` |
| [botocore](https://github.com/boto/botocore) | `1.42.64` | `1.43.88` |
| [build](https://github.com/pypa/build) | `1.3.0` | `1.6.0` |
| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.2` | `3.5.1` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.13.4` | `7.16.0` |
| [cross-web](https://github.com/usecross/cross-web) | `0.4.1` | `0.7.0` |
| [decorator](https://github.com/micheles/decorator) | `5.2.1` | `5.3.1` |
| [deprecated](https://github.com/laurent-laporte-pro/deprecated) | `1.2.18` | `1.3.1` |
| [docstring-parser](https://github.com/rr-/docstring_parser) | `0.17.0` | `0.18.0` |
| [fabric](https://github.com/fabric/fabric) | `3.2.2` | `3.2.3` |
| [fakeredis](https://github.com/cunla/fakeredis-py) | `2.33.0` | `2.37.1` |
| [filelock](https://github.com/tox-dev/py-filelock) | `3.20.3` | `3.32.5` |
| [flask-cors](https://github.com/corydolphin/flask-cors) | `6.0.1` | `6.0.5` |
| [flask-socketio](https://github.com/miguelgrinberg/flask-socketio) | `5.5.1` | `5.6.1` |
| [flatbuffers](https://github.com/google/flatbuffers) | `25.2.10` | `25.12.19` |
| [fonttools](https://github.com/fonttools/fonttools) | `4.60.2` | `4.64.0` |
| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.7.0` | `1.8.0` |
| [fsspec](https://github.com/fsspec/filesystem_spec) | `2026.3.0` | `2026.7.0` |
| [geographiclib](https://github.com/geographiclib/geographiclib-python) | `2.0` | `2.1` |
| [geopy](https://github.com/geopy/geopy) | `2.4.1` | `2.5.0` |
| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.3` | `2.57.1` |
| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |
| [greenlet](https://github.com/python-greenlet/greenlet) | `3.3.2` | `3.5.5` |
| [grpcio](https://github.com/grpc/grpc) | `1.74.0` | `1.83.1` |
| [hiredis](https://github.com/redis/hiredis-py) | `3.3.0` | `3.4.1` |
| [httptools](https://github.com/MagicStack/httptools) | `0.6.4` | `0.8.0` |
| [idna](https://github.com/kjd/idna) | `3.10` | `3.19` |
| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.1.0` | `2.3.0` |
| [jaraco-context](https://github.com/jaraco/jaraco.context) | `6.1.0` | `6.1.2` |
| [jiter](https://github.com/pydantic/jiter) | `0.10.0` | `0.16.0` |
| [joblib](https://github.com/joblib/joblib) | `1.5.1` | `1.6.0` |
| [jsonpointer](https://github.com/stefankoegl/python-json-pointer) | `3.0.0` | `3.1.1` |
| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.25.0` | `4.26.0` |
| [jsonschema-specifications](https://github.com/python-jsonschema/jsonschema-specifications) | `2025.4.1` | `2025.9.1` |
| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.8` | `1.5.1` |
| [mako](https://github.com/sqlalchemy/mako) | `1.3.12` | `1.4.1` |
| [markupsafe](https://github.com/pallets/markupsafe) | `3.0.2` | `3.0.3` |
| [mmh3](https://github.com/hajimes/mmh3) | `5.2.0` | `5.3.0` |
| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |
| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.2` | `1.2.2` |
| [multidict](https://github.com/aio-libs/multidict) | `6.6.3` | `6.7.1` |
| [narwhals](https://github.com/narwhals-dev/narwhals) | `2.0.1` | `2.25.0` |
| [orjson](https://github.com/ijl/orjson) | `3.11.7` | `3.12.0` |
| [pathspec](https://github.com/cpburnz/python-pathspec) | `1.1.0` | `1.1.1` |
| [pip-tools](https://github.com/jazzband/pip-tools) | `7.5.3` | `7.6.1` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.9.4` | `4.11.7` |
| [prompt-toolkit](https://github.com/prompt-toolkit/python-prompt-toolkit) | `3.0.52` | `3.0.53` |
| [propcache](https://github.com/aio-libs/propcache) | `0.3.2` | `0.5.2` |
| [pyasn1](https://github.com/pyasn1/pyasn1) | `0.6.3` | `0.6.4` |
| [pybase64](https://github.com/mayeut/pybase64) | `1.4.2` | `1.5.0` |
| [pydeck](https://github.com/visgl/deck.gl) | `0.9.1` | `0.9.3` |
| [pygithub](https://github.com/pygithub/pygithub) | `2.9.0` | `2.10.0` |
| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |
| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.3` | `3.3.2` |
| [pypika](https://github.com/kayak/pypika) | `0.48.9` | `0.51.1` |
| [pyreadline3](https://github.com/pyreadline3/pyreadline3) | `3.5.4` | `3.5.6` |
| [python-levenshtein](https://github.com/rapidfuzz/python-Levenshtein) | `0.27.3` | `0.27.4` |
| [referencing](https://github.com/python-jsonschema/referencing) | `0.36.2` | `0.37.0` |
| ruamel-yaml | `0.18.14` | `0.19.1` |
| ruamel-yaml-clib | `0.2.12` | `0.2.15` |
| [rustworkx](https://github.com/Qiskit/rustworkx) | `0.17.1` | `0.18.1` |
| [s3transfer](https://github.com/boto/s3transfer) | `0.16.0` | `0.19.2` |
| [safehttpx](https://github.com/gradio-app/safehttpx) | `0.1.6` | `0.1.7` |
| [smmap](https://github.com/gitpython-developers/smmap) | `5.0.2` | `5.0.3` |
| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.7` | `2.9.2` |
| [stevedore](https://docs.openstack.org/stevedore) | `5.4.1` | `5.9.1` |
| [tomlkit](https://github.com/python-poetry/tomlkit) | `0.13.3` | `0.15.1` |
| [tornado](https://github.com/tornadoweb/tornado) | `6.5.5` | `6.5.8` |
| [tqdm](https://github.com/tqdm/tqdm) | `4.67.1` | `4.70.0` |
| [types-requests](https://github.com/python/typeshed) | `2.32.4.20260107` | `2.33.0.20260712` |
| [typing-inspection](https://github.com/pydantic/typing-inspection) | `0.4.2` | `0.4.4` |
| [typing-extensions](https://github.com/python/typing_extensions) | `4.14.1` | `4.16.0` |
| [tzlocal](https://github.com/regebro/tzlocal) | `5.3.1` | `5.4.4` |
| [uuid-utils](https://github.com/aminalaee/uuid-utils) | `0.14.1` | `0.17.0` |
| [watchfiles](https://github.com/samuelcolvin/watchfiles) | `1.1.0` | `1.2.0` |
| [wcwidth](https://github.com/jquast/wcwidth) | `0.5.3` | `0.8.3` |
| [websocket-client](https://github.com/websocket-client/websocket-client) | `1.8.0` | `1.9.2` |
| [werkzeug](https://github.com/pallets/werkzeug) | `3.1.6` | `3.1.8` |
| [wheel](https://github.com/pypa/wheel) | `0.46.2` | `0.48.0` |
| [wsproto](https://github.com/python-hyper/wsproto) | `1.2.0` | `1.3.2` |
| [yarl](https://github.com/aio-libs/yarl) | `1.20.1` | `1.24.5` |
| [safety](https://github.com/pyupio/safety) | `3.2.0` | `3.8.1` |
| [accelerate](https://github.com/huggingface/accelerate) | `1.10.0` | `1.14.0` |
| [bitsandbytes](https://github.com/bitsandbytes-foundation/bitsandbytes) | `0.46.1` | `0.50.2` |
| [langchain-text-splitters](https://github.com/langchain-ai/langchain) | `1.1.1` | `1.1.2` |
| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.7.16` | `0.12.1` |
| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |
| [safetensors](https://github.com/huggingface/safetensors) | `0.5.3` | `0.8.0` |
| [streamlit](https://github.com/streamlit/streamlit) | `1.54.0` | `1.63.0` |
| [tokenizers](https://github.com/huggingface/tokenizers) | `0.21.4` | `0.23.2` |
| [torch](https://github.com/pytorch/pytorch) | `2.8.0` | `2.14.0` |



Updates `fastapi` from 0.135.3 to 0.141.1
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](https://github.com/fastapi/fastapi/compare/0.135.3...0.141.1)

Updates `uvicorn` from 0.35.0 to 0.52.4
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.35.0...0.52.4)

Updates `sqlalchemy` from 2.0.48 to 2.0.52
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

Updates `alembic` from 1.18.4 to 1.19.1
- [Release notes](https://github.com/sqlalchemy/alembic/releases)
- [Changelog](https://github.com/sqlalchemy/alembic/blob/main/CHANGES)
- [Commits](https://github.com/sqlalchemy/alembic/commits)

Updates `asyncpg` from 0.30.0 to 0.31.0
- [Release notes](https://github.com/MagicStack/asyncpg/releases)
- [Commits](https://github.com/MagicStack/asyncpg/compare/v0.30.0...v0.31.0)

Updates `psycopg2-binary` from 2.9.10 to 2.9.12
- [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS)
- [Commits](https://github.com/psycopg/psycopg2/compare/2.9.10...2.9.12)

Updates `gitpython` from 3.1.50 to 3.1.61
- [Release notes](https://github.com/gitpython-developers/GitPython/releases)
- [Changelog](https://github.com/gitpython-developers/GitPython/blob/main/CHANGES)
- [Commits](https://github.com/gitpython-developers/GitPython/compare/3.1.50...3.1.61)

Updates `pyjwt` from 2.12.0 to 2.13.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](https://github.com/jpadilla/pyjwt/compare/2.12.0...2.13.0)

Updates `authlib` from 1.6.11 to 1.8.0
- [Release notes](https://github.com/authlib/authlib/releases)
- [Commits](https://github.com/authlib/authlib/compare/v1.6.11...v1.8.0)

Updates `prometheus-client` from 0.22.1 to 0.26.0
- [Release notes](https://github.com/prometheus/client_python/releases)
- [Commits](https://github.com/prometheus/client_python/compare/v0.22.1...v0.26.0)

Updates `opentelemetry-api` from 1.40.0 to 1.44.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python/compare/v1.40.0...v1.44.0)

Updates `opentelemetry-sdk` from 1.40.0 to 1.44.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python/compare/v1.40.0...v1.44.0)

Updates `opentelemetry-distro` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-exporter-otlp` from 1.40.0 to 1.44.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python/compare/v1.40.0...v1.44.0)

Updates `opentelemetry-exporter-otlp-proto-common` from 1.40.0 to 1.44.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python/compare/v1.40.0...v1.44.0)

Updates `opentelemetry-exporter-otlp-proto-grpc` from 1.40.0 to 1.44.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python/compare/v1.40.0...v1.44.0)

Updates `opentelemetry-exporter-otlp-proto-http` from 1.40.0 to 1.44.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python/compare/v1.40.0...v1.44.0)

Updates `opentelemetry-instrumentation` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-asgi` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-fastapi` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-httpx` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-logging` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-redis` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-sqlalchemy` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-system-metrics` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-instrumentation-celery` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `opentelemetry-proto` from 1.40.0 to 1.44.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python/compare/v1.40.0...v1.44.0)

Updates `opentelemetry-semantic-conventions` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python/commits)

Updates `opentelemetry-util-http` from 0.61b0 to 0.65b0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python-contrib/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-python-contrib/commits)

Updates `langgraph` from 1.1.0 to 1.2.11
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](https://github.com/langchain-ai/langgraph/compare/1.1.0...1.2.11)

Updates `langgraph-prebuilt` from 1.0.8 to 1.1.0
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](https://github.com/langchain-ai/langgraph/compare/1.0.8...1.1.0)

Updates `langgraph-checkpoint` from 4.0.1 to 4.2.0
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](https://github.com/langchain-ai/langgraph/compare/checkpoint==4.0.1...checkpoint==4.2.0)

Updates `langgraph-sdk` from 0.3.13 to 0.4.4
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](https://github.com/langchain-ai/langgraph/compare/0.3.13...0.4.4)

Updates `langchain-community` from 0.3.5 to 0.4.2
- [Release notes](https://github.com/langchain-ai/langchain-community/releases)
- [Commits](https://github.com/langchain-ai/langchain-community/commits/libs/community/v0.4.2)

Updates `langserve` from 0.2.1 to 0.3.3
- [Release notes](https://github.com/langchain-ai/langserve/releases)
- [Commits](https://github.com/langchain-ai/langserve/compare/v0.2.1...v0.3.3)

Updates `celery` from 5.6.2 to 5.6.3
- [Release notes](https://github.com/celery/celery/releases)
- [Changelog](https://github.com/celery/celery/blob/v5.6.3/Changelog.rst)
- [Commits](https://github.com/celery/celery/compare/v5.6.2...v5.6.3)

Updates `chromadb` from 1.0.15 to 1.5.9
- [Release notes](https://github.com/chroma-core/chroma/releases)
- [Changelog](https://github.com/chroma-core/chroma/blob/main/RELEASE_PROCESS.md)
- [Commits](https://github.com/chroma-core/chroma/compare/1.0.15...1.5.9)

Updates `eth-account` from 0.13.0 to 0.14.0
- [Release notes](https://github.com/ApeWorX/eth-account/releases)
- [Changelog](https://github.com/ApeWorX/eth-account/blob/main/docs/release_notes.rst)
- [Commits](https://github.com/ApeWorX/eth-account/compare/v0.13.0...v0.14.0)

Updates `eth-keys` from 0.7.1 to 0.8.0
- [Release notes](https://github.com/ApeWorX/eth-keys/releases)
- [Changelog](https://github.com/ApeWorX/eth-keys/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/ApeWorX/eth-keys/commits/v0.8.0)

Updates `aiohttp` from 3.13.4 to 3.14.3
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](https://github.com/aio-libs/aiohttp/compare/v3.13.4...v3.14.3)

Updates `requests` from 2.33.0 to 2.34.2
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.33.0...v2.34.2)

Updates `python-socketio` from 5.14.0 to 5.16.4
- [Release notes](https://github.com/miguelgrinberg/python-socketio/releases)
- [Changelog](https://github.com/miguelgrinberg/python-socketio/blob/main/CHANGES.md)
- [Commits](https://github.com/miguelgrinberg/python-socketio/compare/v5.14.0...v5.16.4)

Updates `python-engineio` from 4.12.2 to 4.14.0
- [Release notes](https://github.com/miguelgrinberg/python-engineio/releases)
- [Changelog](https://github.com/miguelgrinberg/python-engineio/blob/main/CHANGES.md)
- [Commits](https://github.com/miguelgrinberg/python-engineio/compare/v4.12.2...v4.14.0)

Updates `python-multipart` from 0.0.26 to 0.0.32
- [Release notes](https://github.com/Kludex/python-multipart/releases)
- [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.32)

Updates `discord-py` from 2.5.2 to 2.7.1
- [Commits](https://github.com/Rapptz/discord.py/compare/v2.5.2...v2.7.1)

Updates `py-cord` from 2.6.1 to 2.8.1
- [Release notes](https://github.com/Pycord-Development/pycord/releases)
- [Changelog](https://github.com/Pycord-Development/pycord/blob/master/CHANGELOG.md)
- [Commits](https://github.com/Pycord-Development/pycord/compare/v2.6.1...v2.8.1)

Updates `docker` from 7.1.0 to 7.2.0
- [Release notes](https://github.com/docker/docker-py/releases)
- [Commits](https://github.com/docker/docker-py/compare/7.1.0...7.2.0)

Updates `click` from 8.2.1 to 8.5.0
- [Release notes](https://github.com/pallets/click/releases)
- [Changelog](https://github.com/pallets/click/blob/main/CHANGES.md)
- [Commits](https://github.com/pallets/click/compare/8.2.1...8.5.0)

Updates `typer` from 0.16.0 to 0.27.2
- [Release notes](https://github.com/fastapi/typer/releases)
- [Changelog](https://github.com/fastapi/typer/blob/master/docs/release-notes.md)
- [Commits](https://github.com/fastapi/typer/compare/0.16.0...0.27.2)

Updates `python-dotenv` from 1.2.2 to 1.2.3
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3)

Updates `apscheduler` from 3.11.2 to 3.11.3
- [Release notes](https://github.com/agronholm/apscheduler/releases)
- [Commits](https://github.com/agronholm/apscheduler/compare/3.11.2...3.11.3)

Updates `slowapi` from 0.1.9 to 0.1.10
- [Release notes](https://github.com/laurents/slowapi/releases)
- [Changelog](https://github.com/laurentS/slowapi/blob/master/CHANGELOG.md)
- [Commits](https://github.com/laurents/slowapi/compare/v0.1.9...v0.1.10)

Updates `colorlog` from 6.9.0 to 6.12.0
- [Release notes](https://github.com/borntyping/python-colorlog/releases)
- [Commits](https://github.com/borntyping/python-colorlog/compare/v6.9.0...v6.12.0)

Updates `beautifulsoup4` from 4.13.4 to 4.15.0

Updates `lxml` from 6.1.0 to 6.1.3
- [Release notes](https://github.com/lxml/lxml/releases)
- [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt)
- [Commits](https://github.com/lxml/lxml/compare/lxml-6.1.0...lxml-6.1.3)

Updates `feedparser` from 6.0.11 to 6.0.14
- [Release notes](https://github.com/kurtmckee/feedparser/releases)
- [Changelog](https://github.com/kurtmckee/feedparser/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/kurtmckee/feedparser/compare/6.0.11...v6.0.14)

Updates `numpy` from 2.3.2 to 2.5.2
- [Release notes](https://github.com/numpy/numpy/releases)
- [Changelog](https://github.com/numpy/numpy/blob/main/doc/RELEASE_WALKTHROUGH.rst)
- [Commits](https://github.com/numpy/numpy/compare/v2.3.2...v2.5.2)

Updates `matplotlib` from 3.10.5 to 3.11.1
- [Release notes](https://github.com/matplotlib/matplotlib/releases)
- [Commits](https://github.com/matplotlib/matplotlib/compare/v3.10.5...v3.11.1)

Updates `scipy` from 1.16.1 to 1.18.1
- [Release notes](https://github.com/scipy/scipy/releases)
- [Commits](https://github.com/scipy/scipy/compare/v1.16.1...v1.18.1)

Updates `scikit-learn` from 1.7.1 to 1.9.0
- [Release notes](https://github.com/scikit-learn/scikit-learn/releases)
- [Commits](https://github.com/scikit-learn/scikit-learn/compare/1.7.1...1.9.0)

Updates `strawberry-graphql` from 0.312.3 to 0.327.2
- [Commits](https://github.com/sponsors/strawberry-graphql/commits)

Updates `graphql-core` from 3.2.8 to 3.2.12
- [Release notes](https://github.com/graphql-python/graphql-core/releases)
- [Commits](https://github.com/graphql-python/graphql-core/compare/v3.2.8...v3.2.12)

Updates `qiskit` from 2.3.1 to 2.5.2
- [Release notes](https://github.com/Qiskit/qiskit/releases)
- [Changelog](https://github.com/Qiskit/qiskit/blob/main/docs/release_notes.rst)
- [Commits](https://github.com/Qiskit/qiskit/compare/2.3.1...2.5.2)

Updates `networkx` from 3.5 to 3.6.1
- [Release notes](https://github.com/networkx/networkx/releases)
- [Commits](https://github.com/networkx/networkx/compare/networkx-3.5...networkx-3.6.1)

Updates `onnxruntime` from 1.22.1 to 1.29.0
- [Release notes](https://github.com/microsoft/onnxruntime/releases)
- [Changelog](https://github.com/microsoft/onnxruntime/blob/main/docs/ReleaseNotesWorkflow.md)
- [Commits](https://github.com/microsoft/onnxruntime/compare/v1.22.1...v1.29.0)

Updates `pyyaml` from 6.0.2 to 6.0.3
- [Release notes](https://github.com/yaml/pyyaml/releases)
- [Changelog](https://github.com/yaml/pyyaml/blob/6.0.3/CHANGES)
- [Commits](https://github.com/yaml/pyyaml/compare/6.0.2...6.0.3)

Updates `durationpy` from 0.10 to 0.11
- [Commits](https://github.com/icholy/durationpy/compare/0.10...0.11)

Updates `levenshtein` from 0.27.3 to 0.27.4
- [Release notes](https://github.com/rapidfuzz/Levenshtein/releases)
- [Changelog](https://github.com/rapidfuzz/Levenshtein/blob/main/HISTORY.md)
- [Commits](https://github.com/rapidfuzz/Levenshtein/compare/v0.27.3...v0.27.4)

Updates `rapidfuzz` from 3.14.3 to 3.14.6
- [Release notes](https://github.com/rapidfuzz/RapidFuzz/releases)
- [Changelog](https://github.com/rapidfuzz/RapidFuzz/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/rapidfuzz/RapidFuzz/compare/v3.14.3...v3.14.6)

Updates `pytest` from 9.0.2 to 9.1.1
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/9.0.2...9.1.1)

Updates `pytest-benchmark` from 5.1.0 to 5.3.0
- [Release notes](https://github.com/ionelmc/pytest-benchmark/releases)
- [Changelog](https://github.com/ionelmc/pytest-benchmark/blob/master/CHANGELOG.rst)
- [Commits](https://github.com/ionelmc/pytest-benchmark/compare/v5.1.0...v5.3.0)

Updates `hypothesis` from 6.131.0 to 6.167.1
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](https://github.com/HypothesisWorks/hypothesis/compare/hypothesis-python-6.131.0...v6.167.1)

Updates `black` from 26.3.1 to 26.5.1
- [Release notes](https://github.com/psf/black/releases)
- [Changelog](https://github.com/psf/black/blob/main/CHANGES.md)
- [Commits](https://github.com/psf/black/compare/26.3.1...26.5.1)

Updates `ruff` from 0.9.0 to 0.16.6
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.9.0...0.16.6)

Updates `pylint` from 4.0.5 to 4.0.8
- [Release notes](https://github.com/pylint-dev/pylint/releases)
- [Commits](https://github.com/pylint-dev/pylint/compare/v4.0.5...v4.0.8)

Updates `bandit` from 1.8.6 to 1.9.4
- [Release notes](https://github.com/PyCQA/bandit/releases)
- [Commits](https://github.com/PyCQA/bandit/compare/1.8.6...1.9.4)

Updates `semgrep` from 1.92.0 to 1.176.0
- [Release notes](https://github.com/semgrep/semgrep/releases)
- [Changelog](https://github.com/semgrep/semgrep/blob/develop/CHANGELOG.md)
- [Commits](https://github.com/semgrep/semgrep/compare/v1.92.0...v1.176.0)

Updates `pip-audit` from 2.8.0 to 2.10.1
- [Release notes](https://github.com/pypa/pip-audit/releases)
- [Changelog](https://github.com/pypa/pip-audit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/pypa/pip-audit/compare/v2.8.0...v2.10.1)

Updates `autogen` from 0.5.0 to 0.14.1
- [Commits](https://github.com/ag2ai/ag2classic/commits)

Updates `aiohappyeyeballs` from 2.6.1 to 2.7.1
- [Release notes](https://github.com/aio-libs/aiohappyeyeballs/releases)
- [Changelog](https://github.com/aio-libs/aiohappyeyeballs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aio-libs/aiohappyeyeballs/compare/v2.6.1...v2.7.1)

Updates `annotated-doc` from 0.0.4 to 0.0.5
- [Release notes](https://github.com/fastapi/annotated-doc/releases)
- [Changelog](https://github.com/fastapi/annotated-doc/blob/main/release-notes.md)
- [Commits](https://github.com/fastapi/annotated-doc/compare/0.0.4...0.0.5)

Updates `annotated-types` from 0.7.0 to 0.8.0
- [Release notes](https://github.com/annotated-types/annotated-types/releases)
- [Commits](https://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0)

Updates `anyio` from 4.9.0 to 4.15.0
- [Release notes](https://github.com/agronholm/anyio/releases)
- [Commits](https://github.com/agronholm/anyio/compare/4.9.0...4.15.0)

Updates `arq` from 0.27.0 to 0.28.0
- [Release notes](https://github.com/python-arq/arq/releases)
- [Changelog](https://github.com/python-arq/arq/blob/main/HISTORY.rst)
- [Commits](https://github.com/python-arq/arq/compare/v0.27.0...v0.28.0)

Updates `asgiref` from 3.11.1 to 3.12.1
- [Changelog](https://github.com/django/asgiref/blob/main/CHANGELOG.txt)
- [Commits](https://github.com/django/asgiref/compare/3.11.1...3.12.1)

Updates `astroid` from 4.0.4 to 4.3.1
- [Release notes](https://github.com/pylint-dev/astroid/releases)
- [Changelog](https://github.com/pylint-dev/astroid/blob/v4.3.1/ChangeLog)
- [Commits](https://github.com/pylint-dev/astroid/compare/v4.0.4...v4.3.1)

Updates `bidict` from 0.23.1 to 0.24.1
- [Release notes](https://github.com/jab/bidict/releases)
- [Changelog](https://github.com/jab/bidict/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/jab/bidict/compare/v0.23.1...v0.24.1)

Updates `boto3` from 1.42.64 to 1.43.88
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.42.64...1.43.88)

Updates `botocore` from 1.42.64 to 1.43.88
- [Commits](https://github.com/boto/botocore/compare/1.42.64...1.43.88)

Updates `build` from 1.3.0 to 1.6.0
- [Release notes](https://github.com/pypa/build/releases)
- [Changelog](https://github.com/pypa/build/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pypa/build/compare/1.3.0...1.6.0)

Updates `cffi` from 2.0.0 to 2.1.1
- [Release notes](https://github.com/python-cffi/cffi/releases)
- [Commits](https://github.com/python-cffi/cffi/compare/v2.0.0...v2.1.1)

Updates `charset-normalizer` from 3.4.2 to 3.5.1
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](https://github.com/jawah/charset_normalizer/compare/3.4.2...3.5.1)

Updates `coverage` from 7.13.4 to 7.16.0
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](https://github.com/coveragepy/coveragepy/compare/7.13.4...7.16.0)

Updates `cross-web` from 0.4.1 to 0.7.0
- [Release notes](https://github.com/usecross/cross-web/releases)
- [Changelog](https://github.com/usecross/cross-web/blob/main/CHANGELOG.md)
- [Commits](https://github.com/usecross/cross-web/compare/0.4.1...0.7.0)

Updates `decorator` from 5.2.1 to 5.3.1
- [Release notes](https://github.com/micheles/decorator/releases)
- [Changelog](https://github.com/micheles/decorator/blob/master/CHANGES.md)
- [Commits](https://github.com/micheles/decorator/compare/5.2.1...5.3.1)

Updates `deprecated` from 1.2.18 to 1.3.1
- [Release notes](https://github.com/laurent-laporte-pro/deprecated/releases)
- [Changelog](https://github.com/laurent-laporte-pro/deprecated/blob/master/CHANGELOG-1.2.rst)
- [Commits](https://github.com/laurent-laporte-pro/deprecated/compare/v1.2.18...v1.3.1)

Updates `docstring-parser` from 0.17.0 to 0.18.0
- [Changelog](https://github.com/rr-/docstring_parser/blob/master/CHANGELOG.md)
- [Commits](https://github.com/rr-/docstring_parser/compare/0.17.0...0.18.0)

Updates `fabric` from 3.2.2 to 3.2.3
- [Commits](https://github.com/fabric/fabric/compare/3.2.2...3.2.3)

Updates `fakeredis` from 2.33.0 to 2.37.1
- [Release notes](https://github.com/cunla/fakeredis-py/releases)
- [Commits](https://github.com/cunla/fakeredis-py/compare/v2.33.0...v2.37.1)

Updates `filelock` from 3.20.3 to 3.32.5
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](https://github.com/tox-dev/py-filelock/compare/3.20.3...3.32.5)

Updates `flask-cors` from 6.0.1 to 6.0.5
- [Release notes](https://github.com/corydolphin/flask-cors/releases)
- [Changelog](https://github.com/corydolphin/flask-cors/blob/main/CHANGELOG.md)
- [Commits](https://github.com/corydolphin/flask-cors/compare/6.0.1...6.0.5)

Updates `flask-socketio` from 5.5.1 to 5.6.1
- [Release notes](https://github.com/miguelgrinberg/flask-socketio/releases)
- [Changelog](https://github.com/miguelgrinberg/Flask-SocketIO/blob/main/CHANGES.md)
- [Commits](https://github.com/miguelgrinberg/flask-socketio/compare/v5.5.1...v5.6.1)

Updates `flatbuffers` from 25.2.10 to 25.12.19
- [Release notes](https://github.com/google/flatbuffers/releases)
- [Changelog](https://github.com/google/flatbuffers/blob/master/CHANGELOG.md)
- [Commits](https://github.com/google/flatbuffers/compare/v25.2.10...v25.12.19)

Updates `fonttools` from 4.60.2 to 4.64.0
- [Release notes](https://github.com/fonttools/fonttools/releases)
- [Changelog](https://github.com/fonttools/fonttools/blob/main/NEWS.rst)
- [Commits](https://github.com/fonttools/fonttools/compare/4.60.2...4.64.0)

Updates `frozenlist` from 1.7.0 to 1.8.0
- [Release notes](https://github.com/aio-libs/frozenlist/releases)
- [Changelog](https://github.com/aio-libs/frozenlist/blob/master/CHANGES.rst)
- [Commits](https://github.com/aio-libs/frozenlist/compare/v1.7.0...v1.8.0)

Updates `fsspec` from 2026.3.0 to 2026.7.0
- [Commits](https://github.com/fsspec/filesystem_spec/compare/2026.3.0...2026.7.0)

Updates `geographiclib` from 2.0 to 2.1
- [Commits](https://github.com/geographiclib/geographiclib-python/compare/v2.0...v2.1)

Updates `geopy` from 2.4.1 to 2.5.0
- [Release notes](https://github.com/geopy/geopy/releases)
- [Changelog](https://github.com/geopy/geopy/blob/master/docs/changelog_2xx.rst)
- [Commits](https://github.com/geopy/geopy/compare/2.4.1...2.5.0)

Updates `google-auth` from 2.40.3 to 2.57.1
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-python/commits/google-auth-v2.57.1)

Updates `googleapis-common-protos` from 1.70.0 to 1.75.3
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-python/compare/googleapis-common-protos-v1.70.0...googleapis-common-protos-v1.75.3)

Updates `greenlet` from 3.3.2 to 3.5.5
- [Changelog](https://github.com/python-greenlet/greenlet/blob/master/CHANGES.rst)
- [Commits](https://github.com/python-greenlet/greenlet/compare/3.3.2...3.5.5)

Updates `grpcio` from 1.74.0 to 1.83.1
- [Release notes](https://github.com/grpc/grpc/releases)
- [Commits](https://github.com/grpc/grpc/compare/v1.74.0...v1.83.1)

Updates `hiredis` from 3.3.0 to 3.4.1
- [Release notes](https://github.com/redis/hiredis-py/releases)
- [Changelog](https://github.com/redis/hiredis-py/blob/master/CHANGELOG.md)
- [Commits](https://github.com/redis/hiredis-py/compare/v3.3.0...v3.4.1)

Updates `httptools` from 0.6.4 to 0.8.0
- [Release notes](https://github.com/MagicStack/httptools/releases)
- [Commits](https://github.com/MagicStack/httptools/compare/v0.6.4...v0.8.0)

Updates `idna` from 3.10 to 3.19
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](https://github.com/kjd/idna/compare/v3.10...v3.19)

Updates `iniconfig` from 2.1.0 to 2.3.0
- [Release notes](https://github.com/pytest-dev/iniconfig/releases)
- [Changelog](https://github.com/pytest-dev/iniconfig/blob/main/CHANGELOG)
- [Commits](https://github.com/pytest-dev/iniconfig/compare/v2.1.0...v2.3.0)

Updates `jaraco-context` from 6.1.0 to 6.1.2
- [Release notes](https://github.com/jaraco/jaraco.context/releases)
- [Changelog](https://github.com/jaraco/jaraco.context/blob/main/NEWS.rst)
- [Commits](https://github.com/jaraco/jaraco.context/compare/v6.1.0...v6.1.2)

Updates `jiter` from 0.10.0 to 0.16.0
- [Release notes](https://github.com/pydantic/jiter/releases)
- [Commits](https://github.com/pydantic/jiter/compare/v0.10.0...v0.16.0)

Updates `joblib` from 1.5.1 to 1.6.0
- [Release notes](https://github.com/joblib/joblib/releases)
- [Changelog](https://github.com/joblib/joblib/blob/main/CHANGES.rst)
- [Commits](https://github.com/joblib/joblib/compare/1.5.1...1.6.0)

Updates `jsonpointer` from 3.0.0 to 3.1.1
- [Commits](https://github.com/stefankoegl/python-json-pointer/compare/v3.0.0...v3.1.1)

Updates `jsonschema` from 4.25.0 to 4.26.0
- [Release notes](https://github.com/python-jsonschema/jsonschema/releases)
- [Changelog](https://github.com/python-jsonschema/jsonschema/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/python-jsonschema/jsonschema/compare/v4.25.0...v4.26.0)

Updates `jsonschema-specifications` from 2025.4.1 to 2025.9.1
- [Release notes](https://github.com/python-jsonschema/jsonschema-specifications/releases)
- [Commits](https://github.com/python-jsonschema/jsonschema-specifications/compare/v2025.4.1...v2025.9.1)

Updates `kiwisolver` from 1.4.8 to 1.5.1
- [Release notes](https://github.com/nucleic/kiwi/releases)
- [Changelog](https://github.com/nucleic/kiwi/blob/main/releasenotes.rst)
- [Commits](https://github.com/nucleic/kiwi/compare/1.4.8...1.5.1)

Updates `mako` from 1.3.12 to 1.4.1
- [Release notes](https://github.com/sqlalchemy/mako/releases)
- [Changelog](https://github.com/sqlalchemy/mako/blob/main/CHANGES)
- [Commits](https://github.com/sqlalchemy/mako/commits)

Updates `markupsafe` from 3.0.2 to 3.0.3
- [Release notes](https://github.com/pallets/markupsafe/releases)
- [Changelog](https://github.com/pallets/markupsafe/blob/main/CHANGES.rst)
- [Commits](https://github.com/pallets/markupsafe/compare/3.0.2...3.0.3)

Updates `mmh3` from 5.2.0 to 5.3.0
- [Release notes](https://github.com/hajimes/mmh3/releases)
- [Changelog](https://github.com/hajimes/mmh3/blob/master/CHANGELOG.md)
- [Commits](https://github.com/hajimes/mmh3/compare/v5.2.0...v5.3.0)

Updates `mpmath` from 1.3.0 to 1.4.1
- [Release notes](https://github.com/mpmath/mpmath/releases)
- [Changelog](https://github.com/mpmath/mpmath/blob/master/CHANGES)
- [Commits](https://github.com/mpmath/mpmath/compare/1.3.0...1.4.1)

Updates `msgpack` from 1.1.2 to 1.2.2
- [Release notes](https://github.com/msgpack/msgpack-python/releases)
- [Changelog](https://github.com/msgpack/msgpack-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/msgpack/msgpack-python/compare/v1.1.2...v1.2.2)

Updates `multidict` from 6.6.3 to 6.7.1
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](https://github.com/aio-libs/multidict/compare/v6.6.3...v6.7.1)

Updates `narwhals` from 2.0.1 to 2.25.0
- [Release notes](https://github.com/narwhals-dev/narwhals/releases)
- [Commits](https://github.com/narwhals-dev/narwhals/compare/v2.0.1...v2.25.0)

Updates `orjson` from 3.11.7 to 3.12.0
- [Release notes](https://github.com/ijl/orjson/releases)
- [Changelog](https://github.com/ijl/orjson/blob/master/CHANGELOG.md)
- [Commits](https://github.com/ijl/orjson/compare/3.11.7...3.12.0)

Updates `pathspec` from 1.1.0 to 1.1.1
- [Release notes](https://github.com/cpburnz/python-pathspec/releases)
- [Changelog](https://github.com/cpburnz/python-pathspec/blob/master/CHANGES.rst)
- [Commits](https://github.com/cpburnz/python-pathspec/compare/v1.1.0...v1.1.1)

Updates `pip-tools` from 7.5.3 to 7.6.1
- [Release notes](https://github.com/jazzband/pip-tools/releases)
- [Changelog](https://github.com/jazzband/pip-tools/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jazzband/pip-tools/compare/v7.5.3...v7.6.1)

Updates `platformdirs` from 4.9.4 to 4.11.7
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](https://github.com/tox-dev/platformdirs/compare/4.9.4...4.11.7)

Updates `prompt-toolkit` from 3.0.52 to 3.0.53
- [Release notes](https://github.com/prompt-toolkit/python-prompt-toolkit/releases)
- [Changelog](https://github.com/prompt-toolkit/python-prompt-toolkit/blob/main/CHANGELOG)
- [Commits](https://github.com/prompt-toolkit/python-prompt-toolkit/compare/3.0.52...3.0.53)

Updates `propcache` from 0.3.2 to 0.5.2
- [Release notes](https://github.com/aio-libs/propcache/releases)
- [Changelog](https://github.com/aio-libs/propcache/blob/master/CHANGES.rst)
- [Commits](https://github.com/aio-libs/propcache/compare/v0.3.2...v0.5.2)

Updates `pyasn1` from 0.6.3 to 0.6.4
- [Release notes](https://github.com/pyasn1/pyasn1/releases)
- [Changelog](https://github.com/pyasn1/pyasn1/blob/main/CHANGES.rst)
- [Commits](https://github.com/pyasn1/pyasn1/compare/v0.6.3...v0.6.4)

Updates `pybase64` from 1.4.2 to 1.5.0
- [Release notes](https://github.com/mayeut/pybase64/releases)
- [Commits](https://github.com/mayeut/pybase64/compare/v1.4.2...v1.5.0)

Updates `pydeck` from 0.9.1 to 0.9.3
- [Release notes](https://github.com/visgl/deck.gl/releases)
- [Changelog](https://github.com/visgl/deck.gl/blob/master/CHANGELOG.md)
- [Commits](https://github.com/visgl/deck.gl/commits)

Updates `pygithub` from 2.9.0 to 2.10.0
- [Release notes](https://github.com/pygithub/pygithub/releases)
- [Changelog](https://github.com/PyGithub/PyGithub/blob/main/doc/changes.rst)
- [Commits](https://github.com/pygithub/pygithub/compare/v2.9.0...v2.10.0)

Updates `pygments` from 2.20.0 to 2.21.0
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](https://github.com/pygments/pygments/compare/2.20.0...2.21.0)

Updates `pyparsing` from 3.2.3 to 3.3.2
- [Release notes](https://github.com/pyparsing/pyparsing/releases)
- [Changelog](https://github.com/pyparsing/pyparsing/blob/master/CHANGES)
- [Commits](https://github.com/pyparsing/pyparsing/compare/3.2.3...3.3.2)

Updates `pypika` from 0.48.9 to 0.51.1
- [Release notes](https://github.com/kayak/pypika/releases)
- [Changelog](https://github.com/kayak/pypika/blob/master/CHANGELOG.md)
- [Commits](https://github.com/kayak/pypika/compare/v0.48.9...v0.51.1)

Updates `pyreadline3` from 3.5.4 to 3.5.6
- [Release notes](https://github.com/pyreadline3/pyreadline3/releases)
- [Changelog](https://github.com/pyreadline3/pyreadline3/blob/master/doc/ChangeLog)
- [Commits](https://github.com/pyreadline3/pyreadline3/compare/v3.5.4...v3.5.6)

Updates `python-levenshtein` from 0.27.3 to 0.27.4
- [Release notes](https://github.com/rapidfuzz/python-Levenshtein/releases)
- [Commits](https://github.com/rapidfuzz/python-Levenshtein/compare/v0.27.3...v0.27.4)

Updates `referencing` from 0.36.2 to 0.37.0
- [Release notes](https://github.com/python-jsonschema/referencing/releases)
- [Changelog](https://github.com/python-jsonschema/referencing/blob/main/docs/changes.rst)
- [Commits](https://github.com/python-jsonschema/referencing/compare/v0.36.2...v0.37.0)

Updates `ruamel-yaml` from 0.18.14 to 0.19.1

Updates `ruamel-yaml-clib` from 0.2.12 to 0.2.15

Updates `rustworkx` from 0.17.1 to 0.18.1
- [Release notes](https://github.com/Qiskit/rustworkx/releases)
- [Commits](https://github.com/Qiskit/rustworkx/compare/0.17.1...0.18.1)

Updates `s3transfer` from 0.16.0 to 0.19.2
- [Changelog](https://github.com/boto/s3transfer/blob/develop/CHANGELOG.rst)
- [Commits](https://github.com/boto/s3transfer/compare/0.16.0...0.19.2)

Updates `safehttpx` from 0.1.6 to 0.1.7
- [Commits](https://github.com/gradio-app/safehttpx/commits)

Updates `smmap` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/gitpython-developers/smmap/releases)
- [Commits](https://github.com/gitpython-developers/smmap/compare/v5.0.2...v5.0.3)

Updates `soupsieve` from 2.7 to 2.9.2
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](https://github.com/facelessuser/soupsieve/compare/2.7...2.9.2)

Updates `stevedore` from 5.4.1 to 5.9.1

Updates `tomlkit` from 0.13.3 to 0.15.1
- [Release notes](https://github.com/python-poetry/tomlkit/releases)
- [Changelog](https://github.com/python-poetry/tomlkit/blob/master/CHANGELOG.md)
- [Commits](https://github.com/python-poetry/tomlkit/compare/0.13.3...0.15.1)

Updates `tornado` from 6.5.5 to 6.5.8
- [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
- [Commits](https://github.com/tornadoweb/tornado/compare/v6.5.5...v6.5.8)

Updates `tqdm` from 4.67.1 to 4.70.0
- [Release notes](https://github.com/tqdm/tqdm/releases)
- [Commits](https://github.com/tqdm/tqdm/compare/v4.67.1...v4.70.0)

Updates `types-requests` from 2.32.4.20260107 to 2.33.0.20260712
- [Commits](https://github.com/python/typeshed/commits)

Updates `typing-inspection` from 0.4.2 to 0.4.4
- [Release notes](https://github.com/pydantic/typing-inspection/releases)
- [Changelog](https://github.com/pydantic/typing-inspection/blob/main/HISTORY.md)
- [Commits](https://github.com/pydantic/typing-inspection/compare/v0.4.2...v0.4.4)

Updates `typing-extensions` from 4.14.1 to 4.16.0
- [Release notes](https://github.com/python/typing_extensions/releases)
- [Changelog](https://github.com/python/typing_extensions/blob/main/CHANGELOG.md)
- [Commits](https://github.com/python/typing_extensions/compare/4.14.1...4.16.0)

Updates `tzlocal` from 5.3.1 to 5.4.4
- [Changelog](https://github.com/regebro/tzlocal/blob/master/CHANGES.txt)
- [Commits](https://github.com/regebro/tzlocal/compare/5.3.1...5.4.4)

Updates `uuid-utils` from 0.14.1 to 0.17.0
- [Release notes](https://github.com/aminalaee/uuid-utils/releases)
- [Commits](https://github.com/aminalaee/uuid-utils/compare/0.14.1...0.17.0)

Updates `watchfiles` from 1.1.0 to 1.2.0
- [Release notes](https://github.com/samuelcolvin/watchfiles/releases)
- [Commits](https://github.com/samuelcolvin/watchfiles/compare/v1.1.0...v1.2.0)

Updates `wcwidth` from 0.5.3 to 0.8.3
- [Release notes](https://github.com/jquast/wcwidth/releases)
- [Commits](https://github.com/jquast/wcwidth/compare/0.5.3...0.8.3)

Updates `websocket-client` from 1.8.0 to 1.9.2
- [Release notes](https://github.com/websocket-client/websocket-client/releases)
- [Changelog](https://github.com/websocket-client/websocket-client/blob/master/ChangeLog)
- [Commits](https://github.com/websocket-client/websocket-client/compare/v1.8.0...v1.9.2)

Updates `werkzeug` from 3.1.6 to 3.1.8
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](https://github.com/pallets/werkzeug/compare/3.1.6...3.1.8)

Updates `wheel` from 0.46.2 to 0.48.0
- [Release notes](https://github.com/pypa/wheel/releases)
- [Changelog](https://github.com/pypa/wheel/blob/main/docs/news.rst)
- [Commits](https://github.com/pypa/wheel/compare/0.46.2...0.48.0)

Updates `wsproto` from 1.2.0 to 1.3.2
- [Changelog](https://github.com/python-hyper/wsproto/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/python-hyper/wsproto/compare/1.2.0...1.3.2)

Updates `yarl` from 1.20.1 to 1.24.5
- [Changelog](https://github.com/aio-libs/yarl/blob/master/CHANGES.rst)
- [Commits](https://github.com/aio-libs/yarl/compare/v1.20.1...v1.24.5)

Updates `safety` from 3.2.0 to 3.8.1
- [Release notes](https://github.com/pyupio/safety/releases)
- [Changelog](https://github.com/pyupio/safety/blob/main/CHANGELOG.md)
- [Commits](https://github.com/pyupio/safety/compare/3.2.0...3.8.1)

Updates `accelerate` from 1.10.0 to 1.14.0
- [Release notes](https://github.com/huggingface/accelerate/releases)
- [Commits](https://github.com/huggingface/accelerate/compare/v1.10.0...v1.14.0)

Updates `bitsandbytes` from 0.46.1 to 0.50.2
- [Release notes](https://github.com/bitsandbytes-foundation/bitsandbytes/releases)
- [Changelog](https://github.com/bitsandbytes-foundation/bitsandbytes/blob/main/CHANGELOG.md)
- [Commits](https://github.com/bitsandbytes-foundation/bitsandbytes/compare/0.46.1...0.50.2)

Updates `langchain-text-splitters` from 1.1.1 to 1.1.2
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-text-splitters==1.1.1...langchain-text-splitters==1.1.2)

Updates `langsmith` from 0.7.16 to 0.12.1
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases)
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.7.16...v0.12.1)

Updates `nltk` from 3.9.1 to 3.10.3
- [Release notes](https://github.com/nltk/nltk/releases)
- [Changelog](https://github.com/nltk/nltk/blob/develop/ChangeLog)
- [Commits](https://github.com/nltk/nltk/compare/3.9.1...v3.10.3)

Updates `safetensors` from 0.5.3 to 0.8.0
- [Release notes](https://github.com/huggingface/safetensors/releases)
- [Changelog](https://github.com/safetensors/safetensors/blob/main/RELEASE.md)
- [Commits](https://github.com/huggingface/safetensors/compare/v0.5.3...v0.8.0)

Updates `streamlit` from 1.54.0 to 1.63.0
- [Release notes](https://github.com/streamlit/streamlit/releases)
- [Commits](https://github.com/streamlit/streamlit/compare/1.54.0...1.63.0)

Updates `tokenizers` from 0.21.4 to 0.23.2
- [Release notes](https://github.com/huggingface/tokenizers/releases)
- [Changelog](https://github.com/huggingface/tokenizers/blob/main/RELEASE.md)
- [Commits](https://github.com/huggingface/tokenizers/compare/v0.21.4...v0.23.2)

Updates `torch` from 2.8.0 to 2.14.0
- [Release notes](https://github.com/pytorch/pytorch/releases)
- [Changelog](https://github.com/pytorch/pytorch/blob/main/RELEASE.md)
- [Commits](https://github.com/pytorch/pytorch/compare/v2.8.0...v2.14.0)

---
updated-dependencies:
- dependency-name: accelerate
  dependency-version: 1.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: aiohappyeyeballs
  dependency-version: 2.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: alembic
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: annotated-doc
  dependency-version: 0.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: annotated-types
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: anyio
  dependency-version: 4.14.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: apscheduler
  dependency-version: 3.11.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: arq
  dependency-version: 0.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: asgiref
  dependency-version: 3.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: astroid
  dependency-version: 4.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: asyncpg
  dependency-version: 0.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: authlib
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: autogen
  dependency-version: 0.14.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: bandit
  dependency-version: 1.9.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: beautifulsoup4
  dependency-version: 4.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: bidict
  dependency-version: 0.24.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: bitsandbytes
  dependency-version: 0.50.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: black
  dependency-version: 26.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: boto3
  dependency-version: 1.43.86
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: botocore
  dependency-version: 1.43.86
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: build
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: celery
  dependency-version: 5.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: cffi
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: charset-normalizer
  dependency-version: 3.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: chromadb
  dependency-version: 1.5.9
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: click
  dependency-version: 8.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: colorlog
  dependency-version: 6.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: coverage
  dependency-version: 7.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: cross-web
  dependency-version: 0.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: decorator
  dependency-version: 5.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: deprecated
  dependency-version: 1.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: discord-py
  dependency-version: 2.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: docker
  dependency-version: 7.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: docstring-parser
  dependency-version: 0.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: durationpy
  dependency-version: '0.11'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: eth-account
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: eth-keys
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: fabric
  dependency-version: 3.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: fakeredis
  dependency-version: 2.37.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: fastapi
  dependency-version: 0.141.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: feedparser
  dependency-version: 6.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: filelock
  dependency-version: 3.32.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: flask-cors
  dependency-version: 6.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: flask-socketio
  dependency-version: 5.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: flatbuffers
  dependency-version: 25.12.19
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: fonttools
  dependency-version: 4.64.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: frozenlist
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: fsspec
  dependency-version: 2026.7.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump the patch-and-minor group in /backend with 179 updates chore(deps): bump the patch-and-minor group across 1 directory with 179 updates Sep 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/backend/patch-and-minor-0aec07e48f branch from 4bc3594 to 8e2d1ff Compare September 7, 2026 08:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants