Skip to content

Bump the all-deps group with 4 updates - #1871

Merged
slangeveld merged 1 commit into
mainfrom
dependabot/uv/all-deps-96df4442c2
Oct 2, 2026
Merged

slangeveld merged 1 commit into
mainfrom
dependabot/uv/all-deps-96df4442c2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-deps group with 4 updates: filelock, multidict, pyparsing and starlette.

Updates filelock from 4.0.0 to 4.0.1

Release notes

Sourced from filelock's releases.

4.0.1

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.0...4.0.1

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.0.7 (2026-09-29)


  • File locks now raise ValueError at construction when mode denies the owner read or write, such as mode=0o444, instead of failing on a later acquire and staying broken until someone deletes the lock file. :pr:760

4.0.6 (2026-09-28)


  • Reject negative blocking timeouts other than -1 before reentrant ReadWriteLock and SoftReadWriteLock acquisition. Preserve unlimited waits and nonblocking acquisition. :pr:756

4.0.5 (2026-09-28)


  • Fix MarkerSoftFileLock acquisition and prevent contenders from evicting live protocol-2 owners after two seconds. Reclaim recognized records after owner death; preserve unknown contracts. :pr:749
  • Honor instance timeout and blocking settings in sync and async ReadWriteLock acquisition, including waits between tasks on one instance. Preserve explicit per-call overrides. :pr:750
  • Skip access-denial checks when the process can read mode-0o000 files. Keep mode-bit checks enabled for privileged processes on filesystems that support POSIX permissions. :pr:753
  • Skip vanished StrictSoftFileLock claims after a read-permission retry expires. Recheck the directory before raising a protocol error so concurrent removal does not turn a stale claim listing into an acquisition failure. :pr:754
  • Reject negative timeouts other than -1 in blocking AsyncReadWriteLock and AsyncSoftReadWriteLock acquisitions. Keep -1 as an unlimited wait and ignore timeouts when blocking=False. :pr:755

4.0.4 (2026-09-26)


  • Hostnames that still differ after their first 253 escaped characters now publish distinct owners, so a soft lock no longer takes another such host's live holder for its own and reclaims its marker. :pr:748

4.0.3 (2026-09-23)


  • Importing filelock on CPython 3.10 or 3.11 no longer makes new threads fail with RuntimeError: Cannot install a trace function while another trace function is being installed under coverage or a debugger. filelock skips its fork-safety

... (truncated)

Commits

Updates multidict from 6.8.0 to 6.9.1

Release notes

Sourced from multidict's releases.

6.9.1

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:~multidict.MultiDict.update, :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict constructors, a [key, value] item inside any iterable handed to them, or a list tested with in against :py:meth:~multidict.MultiDict.items, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub: #1437.

  • Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free get()/getone()/ __getitem__() read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub: #1481.

  • Fixed a free-threaded build bug where two threads calling update(), merge(), or __setitem__() on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has released its critical section, so the window can no longer open. setdefault() had an unrelated instance of the same blind spot (it could insert a duplicate rather than recognizing an in-flight key), fixed alongside it -- by :user:asvetlov.

    Related issues and pull requests on GitHub: #1483.

  • Fixed a free-threaded build bug where getall() and the items()/ keys()/values() equality path could raise KeyError or report a present, never-deleted key as missing. A concurrent update()/extend()/ __setitem__() call can have its critical section transiently suspended (a decref triggering a blocking allocator call) while an entry is marked as part of its own bookkeeping; a reader landing in that window used to treat the mark as "not found" instead of "still there, in flight" -- by :user:asvetlov.

    Related issues and pull requests on GitHub:

... (truncated)

Changelog

Sourced from multidict's changelog.

6.9.1

(2026-09-21)

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:~multidict.MultiDict.update, :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict constructors, a [key, value] item inside any iterable handed to them, or a list tested with in against :py:meth:~multidict.MultiDict.items, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub: :issue:1437.

  • Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free get()/getone()/ __getitem__() read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub: :issue:1481.

  • Fixed a free-threaded build bug where two threads calling update(), merge(), or __setitem__() on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has released its critical section, so the window can no longer open. setdefault() had an unrelated instance of the same blind spot (it could insert a duplicate rather than recognizing an in-flight key), fixed alongside it -- by :user:asvetlov.

    Related issues and pull requests on GitHub: :issue:1483.

  • Fixed a free-threaded build bug where getall() and the items()/ keys()/values() equality path could raise KeyError or report a present, never-deleted key as missing. A concurrent update()/extend()/ __setitem__() call can have its critical section transiently suspended (a decref triggering a blocking allocator call) while an entry is marked as

... (truncated)

Commits
  • 0a1770c Release 6.9.1 (#1504)
  • d220522 Upload release assets one at a time to avoid the secondary rate limit (#1503)
  • 30cd596 Stop a GIL-releasing del from segfaulting the standard C extension build ...
  • d1c331a Recheck the reader gate after taking the retired list (#1502)
  • b37f07c Allocate deferred decrefs in fixed-size blocks (#1501)
  • 563f667 Run CodSpeed benchmarks on Python 3.14 and loop the smallest ones (#1498)
  • 157c87c Cancel superseded CI runs on pull requests (#1500)
  • d43adfe Drop -I from the ASan test command so PYTHONMALLOC takes effect (#1499)
  • 2a68472 Stop items() iteration from reading a freed entry in CIMultiDict (#1496)
  • cd528d6 Rename GHSA-54p9-h82j-f925 changelog fragment to the merged commit (#1495)
  • Additional commits viewable in compare view

Updates pyparsing from 3.3.2 to 3.3.3

Changelog

Sourced from pyparsing's changelog.

Version 3.3.3 - in development

  • Added support for Python 3.15.

  • Parse actions that return a tuple value for a named expression formerly saved just the first value of the tuple. Now they return the entire tuple. Partially fixes Issue #401, PR #640 submitted by Vincent Gao et AI.

  • Fixed CI unit test jobs selecting a tox environment with no test commands. The matrix and fallback now select py-unit, as diagnosed and proposed by glaziermag in issue #662; submitted by Neal Lin et AI.

  • Fixed Dict returning an empty nested ParseResults.as_dict() as [] instead of {}. Incorporates partial solution submitted in PR #635 submitted by Leo Ji.

    Additional fixes found as part of this work:

    • Removed vestigial unused ParseResults._modal attribute.

    • Fixed incidental bug when Dict tries to create a dict with a ParseResults value for a key (not hashable).

  • Fixed Word(..., max=n) raising instead of matching up to max characters when the character set contained whitespace - Word(nums, max=3) and Word(nums + " ", max=3) gave opposite results on the same input. Now both forms match up to max and leave the rest for the next parser. PR #646 submitted by Andrew Chen et AI.

  • Fixed QuotedString stripping whitespace that is part of a multi-character quote delimiter, e.g. the leading newline in QuotedString("\n;", multiline=True). The delimiter was silently collapsed to ";", so the newline was ignored when matching. QuotedString now only rejects quote_char/end_quote_char values that are empty or entirely whitespace, and preserves any surrounding whitespace that is part of a valid delimiter. Reported in issue #492.

  • Fixed pyparsing_common.as_datetime raising Invalid date/time: microsecond must be in 0..999999 for valid ISO-8601 timestamps whose fractional seconds round up to a full second (e.g. 2021-06-15T12:30:59.9999995, common in nanosecond-precision timestamps). The rounded microseconds are now added via timedelta so the value carries into the next second instead of overflowing the datetime microsecond argument. PR submitted by Andrew Chen et AI.

  • Fixed debug output corruption when a parsed line contains a carriage return or other control character. set_debug() printed the source line verbatim, so a stray \r returned the terminal cursor to column 0 and overwrote the "Match ... at loc" text. Control characters in the debug line are now shown escaped, and the marker caret stays aligned with the match location. Issue #496, reported by Matthew Rowles.

... (truncated)

Commits
  • d90d38b Update flit version and exclusion of generated railroad diagrams from source ...
  • 4220992 Updated CI to execute unit tests, PR #663; update test_unit.py to add test ca...
  • e266043 Reworked internal recursive implementations to use local stack vars or iterat...
  • See full diff in compare view

Updates starlette from 1.6.0 to 1.7.0

Release notes

Sourced from starlette's releases.

Version 1.7.0

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING] OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

Full changelog: 1.6.0...1.7.0

Changelog

Sourced from starlette's changelog.

1.7.0 (September 23, 2026)

This release adds experimental OpenTelemetry tracing and requires AnyIO 4.

!!! warning "OpenTelemetryMiddleware is experimental" Its API and emitted telemetry may change in minor releases without a deprecation period #3574.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.
Commits
  • 2269e9a Version 1.7.0 (#3575)
  • 4fe55eb Preserve FileResponse status for range requests (#3568)
  • 1f08daf Mark OpenTelemetryMiddleware as experimental (#3574)
  • 57de5fa Support HTTP response trailers in TestClient (#3563)
  • 03f12b7 Allow HTTPException to use non-standard status codes (#3545)
  • 76fd00f Reject WebSocket requests to StaticFiles (#3532)
  • f03f65c docs: fix 'its not available' and 'This ensure' wording (#3526)
  • 485aca4 docs: the test client is built on httpx2, not httpx (#3525)
  • fd662b1 Implement identity on SimpleUser and UnauthenticatedUser (#3271)
  • 41db6a7 Stabilize CodSpeed upload buffer allocations (#3524)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 30, 2026
@slangeveld
slangeveld force-pushed the dependabot/uv/all-deps-96df4442c2 branch from 4add2ec to e2a3769 Compare October 2, 2026 06:10
@codecov-commenter

codecov-commenter commented Oct 2, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.67%. Comparing base (19d2f14) to head (ec1fdf6).
⚠️ Report is 2 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1871   +/-   ##
=======================================
  Coverage   97.67%   97.67%           
=======================================
  Files          59       59           
  Lines        3748     3748           
=======================================
  Hits         3661     3661           
  Misses         87       87           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Bumps the all-deps group with 4 updates: [filelock](https://github.com/tox-dev/py-filelock), [multidict](https://github.com/aio-libs/multidict), [pyparsing](https://github.com/pyparsing/pyparsing) and [starlette](https://github.com/Kludex/starlette).


Updates `filelock` from 4.0.0 to 4.0.1
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@4.0.0...4.0.1)

Updates `multidict` from 6.8.0 to 6.9.1
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v6.8.0...v6.9.1)

Updates `pyparsing` from 3.3.2 to 3.3.3
- [Release notes](https://github.com/pyparsing/pyparsing/releases)
- [Changelog](https://github.com/pyparsing/pyparsing/blob/master/CHANGES)
- [Commits](pyparsing/pyparsing@3.3.2...3.3.3)

Updates `starlette` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.6.0...1.7.0)

---
updated-dependencies:
- dependency-name: filelock
  dependency-version: 4.0.1
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: all-deps
- dependency-name: multidict
  dependency-version: 6.9.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: all-deps
- dependency-name: pyparsing
  dependency-version: 3.3.3
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: all-deps
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: all-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@slangeveld
slangeveld force-pushed the dependabot/uv/all-deps-96df4442c2 branch from e2a3769 to ec1fdf6 Compare October 2, 2026 06:13
@slangeveld
slangeveld merged commit 3adb6f4 into main Oct 2, 2026
14 checks passed
@slangeveld
slangeveld deleted the dependabot/uv/all-deps-96df4442c2 branch October 2, 2026 06:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants