Skip to content

chore(deps): bump the minor-and-patch group across 1 directory with 5 updates - #17

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/backend/minor-and-patch-9aa22053c6
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/backend/minor-and-patch-9aa22053c6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown

Bumps the minor-and-patch group with 5 updates in the /backend directory:

Package From To
pydantic 2.13.4 2.13.5
pydantic-settings 2.14.2 2.15.0
groq 1.6.0 1.7.0
fastembed 0.8.0 0.8.1
ruff 0.16.1 0.16.8

Updates pydantic from 2.13.4 to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates pydantic-settings from 2.14.2 to 2.15.0

Release notes

Sourced from pydantic-settings's releases.

v2.15.0

Highlights

Behavior changes

  • case_sensitive now applies to init kwargs and config-file sources (#900). InitSettingsSource and the JSON/TOML/YAML config sources previously ignored case_sensitive. Since it defaults to False, case-insensitive matching is now the default for these sources — e.g. Settings(TeSt=...) now populates a test field where it previously did not. Nested keys are still matched case-sensitively.
  • Fields with unresolved forward references now emit a warning (#901). Settings sources can silently fail to resolve such fields; they now raise IncompleteFieldDefinitionWarning telling you to call model_rebuild(). If you have filterwarnings = error configured, this may surface as a new failure.
  • Non-JSON env values for strict fields now raise ValidationError (#926) instead of a less specific error.

New features

  • Show environment variable names in CLI help via cli_show_env_vars=True (#860), so generated --help output doubles as configuration documentation.
  • PYDANTIC_SETTINGS_DEBUG for debugging settings resolution (#906, #913). Set it to a truthy value with DEBUG logging enabled to see each source's contribution in priority order, which source won for each value, and which env_file/secret files were probed, loaded, or skipped — the long-standing "why isn't my .env being picked up?" question.
  • toml_table_header for regular TOML files (#882, #886, #887), letting you root settings at a nested table in any TOML file, not just pyproject.toml.
  • Traversable support for JSON/TOML/YAML file sources (#902), so you can load config packaged inside a distribution — including files inside a zip or wheel — via importlib.resources.files(...) without casting to Path.
  • GCP: project_id can come from an earlier settings source (#878), rather than only from the constructor or GOOGLE_CLOUD_PROJECT.

Bug fixes

  • Fix env vars not loading on Windows with case_sensitive=True (#894). Windows upper-cases os.environ keys, so fields raised Field required instead of picking up their values.
  • Read secret files as UTF-8 instead of the platform locale encoding (#917). On Windows code pages such as cp1252 this silently corrupted non-ASCII secrets.
  • Fix AliasPath on nested model fields not JSON-decoding env values (#898).
  • Fix case-insensitive matching for optional nested models (#905).
  • Fix dotenv extras being wrongly claimed by a complex field sharing a name prefix (#912) — e.g. dbx_token being swallowed by a db: dict field.
  • Fix nested_model_default_partial_update=True corrupting discriminated unions (#876).
  • Fix Secret subclasses crashing when loaded from the environment (#920).
  • Fix enum names not parsing through nested annotations such as Optional[Annotated[MyEnum, ...]] with env_parse_enums=True (#910).
  • An empty yaml_config_section now falls back to defaults instead of raising AttributeError: 'NoneType' object has no attribute 'keys' (#914).
  • NestedSecretsSettingsSource no longer follows symlinks pointing outside secrets_dir (#889).
  • GCP: skip the list_secrets call when case_sensitive=True (#862), lowering the required IAM permissions to just roles/secretmanager.secretAccessor.
  • AWS: types-boto3[secretsmanager] is no longer required at runtime (#880).

Documentation

  • Document JSON parsing of complex env values, plus a comma-separated-values recipe (#919).
  • Recommend an async settings loading pattern (#908).
  • Clarify behavior when an unprefixed value is present in a dotenv file (#895).
  • Clarify environment variable helper descriptions (#867) and fix assorted typos (#904).

What's Changed

... (truncated)

Commits
  • f725ca1 Prepare release 2.15.0 (#930)
  • 28f35c2 Bump the python-packages group with 4 updates (#929)
  • 9056db0 test: move function-local imports to the top of test modules (#927)
  • f077e3a fix: raise ValidationError for non-JSON env values on strict fields (#926)
  • ae25d70 fix: treat Secret subclasses as non-complex fields (#716) (#920)
  • 798dcea Bump the python-packages group with 4 updates (#924)
  • a190041 Bump the github-actions group with 4 updates (#925)
  • 5d93332 Bump the python-packages group with 4 updates (#921)
  • d2fdeda fix: read secret files as UTF-8 instead of the locale encoding (#917)
  • 2256a4e Bump the python-packages group with 3 updates (#915)
  • Additional commits viewable in compare view

Updates groq from 1.6.0 to 1.7.0

Release notes

Sourced from groq's releases.

v1.7.0

1.7.0 (2026-08-25)

Full Changelog: v1.6.0...v1.7.0

Features

  • chat: add Qwen3.8 reasoning guidance (5d65203)

Bug Fixes

  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (26fdd4f)
  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (01f00ea)

Chores

  • deps: update lock files to fix known vulnerabilities (GC1-104) (#280) (9620fde)
  • GitHub Terraform: Create/Update .github/workflows/code-freeze-bypass.yaml [skip ci] (85b6cce)
  • internal: allow the mock server port to be set with STAINLESS_MOCK_PORT (4e10497)
Changelog

Sourced from groq's changelog.

1.7.0 (2026-08-25)

Full Changelog: v1.6.0...v1.7.0

Features

  • chat: add Qwen3.8 reasoning guidance (5d65203)

Bug Fixes

  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (26fdd4f)
  • GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci] (01f00ea)

Chores

  • deps: update lock files to fix known vulnerabilities (GC1-104) (#280) (9620fde)
  • GitHub Terraform: Create/Update .github/workflows/code-freeze-bypass.yaml [skip ci] (85b6cce)
  • internal: allow the mock server port to be set with STAINLESS_MOCK_PORT (4e10497)
Commits
  • ac18a8c release: 1.7.0 (#283)
  • 9620fde chore(deps): update lock files to fix known vulnerabilities (GC1-104) (#280)
  • 26fdd4f fix: GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci]
  • 01f00ea fix: GitHub Terraform: Create/Update .github/workflows/stale.yaml [skip ci]
  • 85b6cce chore: GitHub Terraform: Create/Update .github/workflows/code-freeze-bypass.y...
  • See full diff in compare view

Updates fastembed from 0.8.0 to 0.8.1

Release notes

Sourced from fastembed's releases.

v0.8.1

Changelog

Features 🏎️

  • #592 - add google/embeddinggemma-300m by @​joein
  • #651 - add nomic-ai/nomic-embed-vision-v1.5 and nomic-ai/nomic-embed-vision-v1.5-Q, which share an embedding space with nomic-ai/nomic-embed-text-v1.5 for text-to-image search by @​Dylancouzon
  • #652 - add inference-free SPLADE opensearch-project/opensearch-neural-sparse-encoding-doc-v3-gte, which runs the model on documents only and encodes queries without inference by @​joein
  • #678, #680 - add Qwen/Qwen3-Embedding-0.6B and Qwen/Qwen3-Embedding-0.6B-Q (the quantized model requires onnxruntime>=1.23), plus PoolingType.LAST_TOKEN for custom models by @​joein
  • #683 - add google/siglip2-base-patch16-224 to TextEmbedding and ImageEmbedding by @​joein
  • #692 - add Model2Vec static models minishlab/potion-base-8M, minishlab/potion-retrieval-32M, and minishlab/potion-multilingual-128M by @​stephantul @​Dylancouzon

Fixes 🔧

  • #593, #707 - use canonical Hugging Face repo IDs for BAAI/bge-base-en-v1.5 and BAAI/bge-small-en-v1.5 to avoid a redirect that broke downloads behind some proxies (see Upgrade Notes) by @​Harnas @​rastagan-git @​joein
  • #623 - run the fp32 version of jinaai/jina-embeddings-v2-base-de instead of fp16, which fails on onnxruntime>=1.23 (the download grows from 0.32 GB to 0.64 GB) by @​joein
  • #624 - check that model files exist before using a cached model, so several variants of one repo (for example fp32 and quantized) can share a cache dir by @​joein
  • #629 - add a timeout to downloads from Google Cloud Storage (GCS), so a stalled connection fails instead of hanging indefinitely by @​joein
  • #645 - fix a KeyError when loading a custom text model with different casing than it was registered with by @​CODING-DARSH @​joein
  • #647 - fix a path traversal vulnerability in model archive extraction that could write files outside the cache dir by @​he-yufeng @​joein
  • #682 - fix normalization of batched (N, C, H, W) image arrays, which ran along the wrong axis by @​serhiizghama @​joein
  • #693 - make config.json and special_tokens_map.json optional when loading a tokenizer by @​libaojiang @​joein
  • #697 - fix the Resize transform swapping height and width for non-square sizes by @​Ramnath0521 @​joein
  • #714 - fix custom text embedding and cross-encoder models (add_custom_model) failing when parallel is set by @​joein @​S0rryHorizon
  • #716, #717 - always pad a batch to its longest sequence, fixing a ValueError on mixed-length batches for models whose tokenizer ships a fixed padding length, such as thenlper/gte-base (regression in 0.8.0) by @​joein @​mohmedmm
  • #718 - stage each GCS download in its own temporary dir, so a failed or concurrent download can't delete files from other downloads by @​joein

Upgrade Notes

  • BAAI/bge-small-en-v1.5 (the default model) and BAAI/bge-base-en-v1.5 now resolve to Qdrant/bge-small-en-v1.5-onnx-Q and Qdrant/bge-base-en-v1.5-onnx-Q. The cache dir name follows the repo ID's casing, so on case-sensitive filesystems (typically Linux) the existing cache isn't reused and both models download again once. Offline setups (HF_HUB_OFFLINE=1 or local_files_only=True) need to refresh their cache before upgrading. You can delete the old models--qdrant--bge-*-onnx-q dirs afterwards.
  • jinaai/jina-embeddings-v2-base-de now loads onnx/model.onnx instead of onnx/model_fp16.onnx, so offline setups need to download it first.

Thanks to everyone who contributed to this release @​CODING-DARSH @​Dylancouzon @​Harnas @​he-yufeng @​libaojiang @​mohmedmm @​Ramnath0521 @​rastagan-git @​S0rryHorizon @​serhiizghama @​stephantul @​joein

Commits
  • 8de28b8 fix: fix mypy (#720)
  • a2bef98 bump version to v0.8.1
  • fb68e86 fix: stage GCS downloads instead of deleting the caller's cache dir (#718)
  • 0c63b6a fix: block unsafe tar extraction paths (#647)
  • cbe60bf fix(image): normalize batched (N, C, H, W) input along the channel axis (#682)
  • 40cca63 fix: make tokenizer metadata files optional (#693)
  • 5c4d9b0 fix: pass (width, height) to Pillow in the Resize transform (#697)
  • a3a798f fix: preserve pad_to_multiple_of when normalizing padding (#717)
  • bdf6816 fix: normalize tokenizer padding to batch-longest (#716)
  • 5dc53eb chore(deps-dev): bump the security-updates group across 1 directory with 2 up...
  • Additional commits viewable in compare view

Updates ruff from 0.16.1 to 0.16.8

Release notes

Sourced from ruff's releases.

0.16.8

Release Notes

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

Install ruff 0.16.8

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh | sh
</tr></table> 

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

0.16.7

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)

... (truncated)

Commits
  • 62914c4 Bump version to 0.16.8 (#28648)
  • c47e0cd [ty] Bound aliased intersection expansion during inference (#28546)
  • ff4747b renovate: update uv hashes correctly with setup-uv (#28621)
  • 94efeaa [ty] Compact reachable binding and declaration histories (#28349)
  • 50020fb [ty] Avoid storing constraint nodes twice (#28375)
  • 446bb68 [ty] Compare bound-method receivers before signatures (#28384)
  • 304ab86 [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on 3.15+ (`...
  • d940b24 [ty] Watch script dependencies in CLI watch mode (#28125)
  • fe9f065 [flake8-tidy-imports] Add extend-banned-api (#28644)
  • 31131db [ty] Support type[A & B] (#27124)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… updates

Bumps the minor-and-patch group with 5 updates in the /backend directory:

| Package | From | To |
| --- | --- | --- |
| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |
| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |
| [groq](https://github.com/groq/groq-python) | `1.6.0` | `1.7.0` |
| [fastembed](https://github.com/qdrant/fastembed) | `0.8.0` | `0.8.1` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.1` | `0.16.8` |



Updates `pydantic` from 2.13.4 to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.13.4...v2.13.5)

Updates `pydantic-settings` from 2.14.2 to 2.15.0
- [Release notes](https://github.com/pydantic/pydantic-settings/releases)
- [Commits](pydantic/pydantic-settings@v2.14.2...v2.15.0)

Updates `groq` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/groq/groq-python/releases)
- [Changelog](https://github.com/groq/groq-python/blob/main/CHANGELOG.md)
- [Commits](groq/groq-python@v1.6.0...v1.7.0)

Updates `fastembed` from 0.8.0 to 0.8.1
- [Release notes](https://github.com/qdrant/fastembed/releases)
- [Changelog](https://github.com/qdrant/fastembed/blob/main/RELEASE.md)
- [Commits](qdrant/fastembed@v0.8.0...v0.8.1)

Updates `ruff` from 0.16.1 to 0.16.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.1...0.16.8)

---
updated-dependencies:
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: pydantic-settings
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: groq
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: fastembed
  dependency-version: 0.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 27, 2026
@vercel

vercel Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
winchat Ready Ready Preview Sep 27, 2026 6:15pm UTC

@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 4, 2026
@dependabot
dependabot Bot deleted the dependabot/uv/backend/minor-and-patch-9aa22053c6 branch October 4, 2026 18:13

This branch had an error being deployed

1 failed and 1 active deployments
Preview — 1066b1e4 Deployed Sep 27, 2026 by vercel[bot]
prod — 1066b1e4 Deployed Sep 27, 2026 by dependabot[bot] via eval #17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants