chore(deps): bump the pip group across 1 directory with 21 updates - #69
chore(deps): bump the pip group across 1 directory with 21 updates#69dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [fastapi](https://github.com/fastapi/fastapi), [uvicorn](https://github.com/Kludex/uvicorn), [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy), [alembic](https://github.com/sqlalchemy/alembic), [apscheduler](https://github.com/agronholm/apscheduler), [pytz](https://github.com/stub42/pytz), [twilio](https://github.com/twilio/twilio-python), [pydantic-settings](https://github.com/pydantic/pydantic-settings), [python-dotenv](https://github.com/theskumar/python-dotenv), [cryptography](https://github.com/pyca/cryptography), [python-json-logger](https://github.com/nhairs/python-json-logger), [pytest](https://github.com/pytest-dev/pytest), [coverage](https://github.com/coveragepy/coveragepy), [isort](https://github.com/PyCQA/isort), [mypy](https://github.com/python/mypy), [pylint](https://github.com/pylint-dev/pylint), [ipython](https://github.com/ipython/ipython), [pre-commit](https://github.com/pre-commit/pre-commit), [mkdocs-material](https://github.com/squidfunk/mkdocs-material), [faker](https://github.com/joke2k/faker) and [responses](https://github.com/getsentry/responses) to permit the latest version. Updates `fastapi` from 0.136.3 to 0.141.1 - [Release notes](https://github.com/fastapi/fastapi/releases) - [Commits](fastapi/fastapi@0.136.3...0.141.1) Updates `uvicorn` from 0.49.0 to 0.52.4 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.49.0...0.52.4) Updates `sqlalchemy` from 2.0.50 to 2.0.52 - [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases) - [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst) - [Commits](https://github.com/sqlalchemy/sqlalchemy/commits) Updates `alembic` from 1.18.4 to 1.19.1 - [Release notes](https://github.com/sqlalchemy/alembic/releases) - [Changelog](https://github.com/sqlalchemy/alembic/blob/main/CHANGES) - [Commits](https://github.com/sqlalchemy/alembic/commits) Updates `apscheduler` from 3.11.2 to 3.11.3 - [Release notes](https://github.com/agronholm/apscheduler/releases) - [Commits](agronholm/apscheduler@3.11.2...3.11.3) Updates `pytz` from 2026.2 to 2026.3.post1 - [Release notes](https://github.com/stub42/pytz/releases) - [Commits](stub42/pytz@release_2026.2...release_2026.3.post1) Updates `twilio` from 9.10.9 to 9.11.0 - [Release notes](https://github.com/twilio/twilio-python/releases) - [Changelog](https://github.com/twilio/twilio-python/blob/main/CHANGES.md) - [Commits](twilio/twilio-python@9.10.9...9.11.0) Updates `pydantic-settings` from 2.14.1 to 2.15.0 - [Release notes](https://github.com/pydantic/pydantic-settings/releases) - [Commits](pydantic/pydantic-settings@v2.14.1...v2.15.0) Updates `python-dotenv` from 1.2.2 to 1.2.3 - [Release notes](https://github.com/theskumar/python-dotenv/releases) - [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md) - [Commits](theskumar/python-dotenv@v1.2.2...v1.2.3) Updates `cryptography` to 50.0.1 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@48.0.1...50.0.1) Updates `python-json-logger` from 4.1.0 to 4.2.0 - [Release notes](https://github.com/nhairs/python-json-logger/releases) - [Changelog](https://github.com/nhairs/python-json-logger/blob/main/docs/changelog.md) - [Commits](nhairs/python-json-logger@v4.1.0...v4.2.0) Updates `pytest` from 9.0.3 to 9.1.1 - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst) - [Commits](pytest-dev/pytest@9.0.3...9.1.1) Updates `coverage` from 7.14.1 to 7.15.4 - [Release notes](https://github.com/coveragepy/coveragepy/releases) - [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst) - [Commits](coveragepy/coveragepy@7.14.1...7.15.4) Updates `isort` from 8.0.1 to 9.0.0 - [Release notes](https://github.com/PyCQA/isort/releases) - [Changelog](https://github.com/PyCQA/isort/blob/main/CHANGELOG.md) - [Commits](PyCQA/isort@8.0.1...9.0.0) Updates `mypy` from 2.1.0 to 2.3.1 - [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md) - [Commits](python/mypy@v2.1.0...v2.3.1) Updates `pylint` from 4.0.5 to 4.0.7 - [Release notes](https://github.com/pylint-dev/pylint/releases) - [Commits](pylint-dev/pylint@v4.0.5...v4.0.7) Updates `ipython` from 9.14.1 to 9.16.1 - [Release notes](https://github.com/ipython/ipython/releases) - [Commits](ipython/ipython@9.14.1...9.16.1) Updates `pre-commit` from 4.6.0 to 4.6.2 - [Release notes](https://github.com/pre-commit/pre-commit/releases) - [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md) - [Commits](pre-commit/pre-commit@v4.6.0...v4.6.2) Updates `mkdocs-material` from 9.7.6 to 9.7.7 - [Release notes](https://github.com/squidfunk/mkdocs-material/releases) - [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG) - [Commits](squidfunk/mkdocs-material@9.7.6...9.7.7) Updates `faker` from 40.23.0 to 40.37.0 - [Release notes](https://github.com/joke2k/faker/releases) - [Changelog](https://github.com/joke2k/faker/blob/master/CHANGELOG.md) - [Commits](joke2k/faker@v40.23.0...v40.37.0) Updates `responses` from 0.26.1 to 0.26.3 - [Release notes](https://github.com/getsentry/responses/releases) - [Changelog](https://github.com/getsentry/responses/blob/master/CHANGES) - [Commits](getsentry/responses@0.26.1...0.26.3) --- updated-dependencies: - dependency-name: fastapi dependency-version: 0.141.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: uvicorn dependency-version: 0.52.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: sqlalchemy dependency-version: 2.0.52 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: pip - dependency-name: alembic dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: apscheduler dependency-version: 3.11.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: pip - dependency-name: pytz dependency-version: 2026.3.post1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: twilio dependency-version: 9.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: pydantic-settings dependency-version: 2.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: python-dotenv dependency-version: 1.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: pip - dependency-name: cryptography dependency-version: 50.0.1 dependency-type: direct:production dependency-group: pip - dependency-name: python-json-logger dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: pytest dependency-version: 9.1.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: pip - dependency-name: coverage dependency-version: 7.15.4 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: pip - dependency-name: isort dependency-version: 9.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: pip - dependency-name: mypy dependency-version: 2.3.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: pip - dependency-name: pylint dependency-version: 4.0.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: pip - dependency-name: ipython dependency-version: 9.16.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: pip - dependency-name: pre-commit dependency-version: 4.6.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: pip - dependency-name: mkdocs-material dependency-version: 9.7.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: pip - dependency-name: faker dependency-version: 40.37.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: pip - dependency-name: responses dependency-version: 0.26.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com>
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Duplication | ✅ 0 (≤ 5 duplication) |
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
There was a problem hiding this comment.
Pull Request Overview
This PR updates 21 Python dependencies, most notably addressing a critical security vulnerability in the cryptography library (CVE-2026-69247). While the updates are necessary, the PR introduces two major version jumps—cryptography (48.x to 50.x) and isort (9.0.0)—which carry high risks of breaking changes.
Specifically, the isort update is likely to cause CI linting failures if the codebase is not re-formatted, and the cryptography update may impact sensitive encryption/decryption paths. Since these are bundled with 19 other updates, isolating regressions will be difficult. It is recommended to verify these major updates individually or execute the suggested re-formatting prompts before merging.
About this PR
- This PR bundles 21 dependency updates, including major version jumps for
cryptographyandisort. Bundling major releases with a large number of minor/patch updates increases the risk of regression and complicates the identification of the root cause if the CI pipeline or production environment fails.
Test suggestions
- Verify application startup and basic request routing with FastAPI 0.141.1 and Uvicorn 0.52.4.
- Confirm database migration and ORM compatibility with SQLAlchemy 2.0.52 and Alembic 1.19.1.
- Validate at-rest encryption and decryption functionality using the updated cryptography 50.0.1 library.
- Execute static analysis and linting (MyPy, Pylint, isort) to ensure compatibility with updated dev tool versions.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify application startup and basic request routing with FastAPI 0.141.1 and Uvicorn 0.52.4.
2. Confirm database migration and ORM compatibility with SQLAlchemy 2.0.52 and Alembic 1.19.1.
3. Validate at-rest encryption and decryption functionality using the updated cryptography 50.0.1 library.
4. Execute static analysis and linting (MyPy, Pylint, isort) to ensure compatibility with updated dev tool versions.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
| # Security | ||
| argon2-cffi==25.1.0 # Argon2id password hashing (OWASP 2025 recommended) | ||
| cryptography>=48.0.1,<49 # Fernet + PBKDF2 for at-rest encryption of Twilio auth tokens (WHO-43); floor bumped past CVE-flagged ranges (CodeRabbit) | ||
| cryptography>=50.0.1,<51 # Fernet + PBKDF2 for at-rest encryption of Twilio auth tokens (WHO-43); floor bumped past CVE-flagged ranges (CodeRabbit) |
There was a problem hiding this comment.
🟡 MEDIUM RISK
This update performs a major version jump for cryptography (48.x to 50.x), skipping version 49. Major releases in this library can introduce breaking changes or deprecate ciphers. It is safer to update this package separately and verify that the Twilio auth token encryption/decryption logic remains functional. Try running the following prompt in your coding agent: > Review the cryptography 50.x release notes for breaking changes related to Fernet and PBKDF2, then run the test suite to verify Twilio token encryption/decryption.
| isort==8.0.1 # Import sorting | ||
| mypy==2.1.0 # Type checking - Updated for Python 3.12 | ||
| pylint==4.0.5 # Advanced linting | ||
| isort==9.0.0 # Import sorting |
There was a problem hiding this comment.
🟡 MEDIUM RISK
Suggestion: Bumping to a new major version of isort (9.0.0) often introduces changes to sorting logic. If the codebase has not been re-formatted with this new version, linting checks in CI are likely to fail. Try running the following prompt in your coding agent: > Re-format the entire codebase using isort 9.0.0 and black 26.5.1 to ensure compliance with the updated rules and verify CI passes.
Updates the requirements on fastapi, uvicorn, sqlalchemy, alembic, apscheduler, pytz, twilio, pydantic-settings, python-dotenv, cryptography, python-json-logger, pytest, coverage, isort, mypy, pylint, ipython, pre-commit, mkdocs-material, faker and responses to permit the latest version.
Updates
fastapifrom 0.136.3 to 0.141.1Release notes
Sourced from fastapi's releases.
... (truncated)
Commits
95f8322🔖 Release version 0.141.1 (#16106)f137944📝 Update release notesd623544🐛 Fix support for background tasks and headers from dependencies in `app.fron...1d211b9📝 Update release notes8a1f876📝 DocumentFASTAPI_ENVin FastAPI CLI guide (#16104)c7e7b65🔖 Release version 0.141.0 (#16103)6bceb84📝 Update release notes5429fed✨ Addapp.frontend(check_dir="auto"), to make local development more conven...628663f🔖 Release version 0.140.13 (#16096)0b54fd0📝 Update release notesUpdates
uvicornfrom 0.49.0 to 0.52.4Release notes
Sourced from uvicorn's releases.
... (truncated)
Changelog
Sourced from uvicorn's changelog.
... (truncated)
Commits
8988c23Stabilize macOS Python 3.13 signal shutdown tests (#3084)898ddcaUpdate PyPI publish action to version 1.14.2 (#3083)3869f8aRestore Mermaid diagram rendering (#3080)64148a9Version 0.52.4 (#3079)9e9e569docs: correct release example PR number (#3072)b783dacRemove duplicate Date header from SansIO WebSocket handshakes (#3078)27019b2chore(deps): bump the python-packages group across 1 directory with 11 update...1b64273Fix a typo in index.md (#3006)a68da60Version 0.52.3 (#3068)6e3bb4cUse zttp 0.0.24 fast receive path (#3067)Updates
sqlalchemyfrom 2.0.50 to 2.0.52Release notes
Sourced from sqlalchemy's releases.
... (truncated)
Commits
Updates
alembicfrom 1.18.4 to 1.19.1Release notes
Sourced from alembic's releases.
... (truncated)
Commits
Updates
apschedulerfrom 3.11.2 to 3.11.3Release notes
Sourced from apscheduler's releases.
Commits
4308ec9Added the release versionff68780Added a note about weekday numbers in CronTrigger.from_crontab()36936e9Updated actionsc0ff7e4Fixed Pyside6 tests failing on Python 3.9 and 3.81b782c9Fixed fixturecoreappnot founddc3dde4Test against PySide6 on all Python versions18a6f6bFixed imported jobs missing their scheduler and job store links1693db4Fix interval jobs stalling across DST spring-forward with ZoneInfo (#1114)0636bf4Added Python 3.14 to the test matrix3eb3de8Fixed bad use of pytest.raises()Updates
pytzfrom 2026.2 to 2026.3.post1Commits
661bca9Bump version numbers to 2026.3.post1 for python2 fix1e31a16Log python version running tests, force python2b3ca7c3Unix line endingsb55039aReplace non-ASCII character in comment to fix build with Python 25420ee2Replace non-ASCII character in comment2c139e8Merge branch 'fix/localize-overflow-at-datetime-extremes' of https://github.c...c843864Run zdump tests quietly518500cReduce noise when collecting zdump info dumps081f935Merge branch 'kytta-fix-dst' into 2026c8c9d69bMerge branch 'master' into 2026cUpdates
twiliofrom 9.10.9 to 9.11.0Release notes
Sourced from twilio's releases.
... (truncated)
Changelog
Sourced from twilio's changelog.
... (truncated)
Commits
306691eFix tag validation regex in deploy.yml (#954)a7c1450Update Python version matrix in deploy.yml (#953)eba3466[Librarian] Regenerated @ f443c9dfa233e41d0e61c9ed6ca2b162467a08b5 89762bc866...fbdfe4eUpdate deployment trigger to all tags (#950)3a5e24dComment out docs generation verification step (#952)89689b2handle-blank-response-202 (#949)3b82ae1Remove assistant apis cluster test (#948)184b583fix: updates to release process (#941)becbfc5removed oauth beta maturity from readme (#943)ecf51acAdd test and release gate workflow (#940)Updates
pydantic-settingsfrom 2.14.1 to 2.15.0Release notes
Sourced from pydantic-settings's releases.
... (truncated)
Commits
f725ca1Prepare release 2.15.0 (#930)28f35c2Bump the python-packages group with 4 updates (#929)9056db0test: move function-local imports to the top of test modules (#927)f077e3afix: raise ValidationError for non-JSON env values on strict fields (#926)ae25d70fix: treat Secret subclasses as non-complex fields (#716) (#920)798dceaBump the python-packages group with 4 updates (#924)a190041Bump the github-actions group with 4 updates (#925)5d93332Bump the python-packages group with 4 updates (#921)d2fdedafix: read secret files as UTF-8 instead of the locale encoding (#917)2256a4eBump the python-packages group with 3 updates (#915)Updates
python-dotenvfrom 1.2.2 to 1.2.3Release notes
Sourced from python-dotenv's releases.
Changelog
Sourced from python-dotenv's changelog.
Commits
49515afBump version: 1.2.2 → 1.2.38ac846fchore: add release runbook (RELEASING.md) and make release targetbb31c94docs: add 1.2.3 release notes (#606, #638, #680)f7b18d9fix: round-trip backslashes through set_key (#680)751f8c1ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...f1937b6chore(deps): update mkdocs-include-markdown-plugin requirement from >=6.0.0 t...45b9372chore(deps): update pytest requirement from >=3.9 to >=9.0.3 (#653)72896e9docs: fix broken mkdocs link in CONTRIBUTING.md (#636)72754a1ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...078325eci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...Updates
cryptographyto 50.0.1Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
ffde75abump for 50.0.1 + changelog (#15520)dcb7050Prepare for 50.0.0 release (#15372)53fccd9Don't leak how PKCS#7 encryptedKey decryption failed (#15369)d472f97Addfrom __future__ import annotationsto all src/ Python files (#15371)908773dBump downstream dependencies in CI (#15368)2cc07ccBump BoringSSL, OpenSSL, AWS-LC in CI (#15367)c94ede9chore(deps): bump ruff from 0.16.0 to 0.16.1 (#15366)67a8308chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (#15365)95018ffRelease the GIL in one-shot AEAD encrypt/decrypt (#15361)6954733Release the GIL during DH and DSA parameter generation (#15364)Updates
python-json-loggerfrom 4.1.0 to 4.2.0Release notes
Sourced from python-json-logger's releases.
Changelog
Sourced from python-json-logger's changelog.
Commits
806dba9Release 4.2.0010b730[core] Fixup doc-strings, remove outdated commentsb865bd3Description has been truncated