Skip to content

fix(deps): update non-major python dependencies - #20

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-python-dependencies
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/non-major-python-dependencies

Conversation

@renovate

@renovate renovate Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
fastmcp >=3.4.2,<4 → >=3.4.8,<4 age confidence
pre-commit >=4.6.0 → >=4.6.2 age confidence
pydantic (changelog) >=2.13.4 → >=2.14.0 age confidence
pydantic-settings (changelog) >=2.14.1 → >=2.15.0 age confidence
pytest (changelog) >=9.0.3 → >=9.1.1 age confidence
python-semantic-release (changelog) >=10.5.3 → >=10.7.0 age confidence
ruff (source, changelog) >=0.15.16 → >=0.17.0 age confidence

Release Notes

PrefectHQ/fastmcp (fastmcp)

v3.4.8: : Long Arm of the Patch

Compare Source

This release contains important security and bug fixes. All users are encouraged to upgrade. Thanks to our 2 contributors.

What's Changed

Security 🔒
Docs 📚

Full Changelog: PrefectHQ/fastmcp@v3.4.7...v3.4.8

v3.4.7: : Know Your Audience

Compare Source

FastMCP 3.4.7 restores CIMD private_key_jwt authentication for OAuthProxy deployments at a bare origin. Client assertions are now validated against the exact token endpoint advertised in authorization server metadata, eliminating the doubled-slash audience mismatch.

What's Changed

Security 🔒
Docs 📚

Full Changelog: PrefectHQ/fastmcp@v3.4.6...v3.4.7

v3.4.6: : Trust, but Proxy

Compare Source

FastMCP 3.4.6 backports trusted-proxy support for SSRF-protected OAuth metadata and JWKS fetches. Deployments can now route these requests through a mandated corporate proxy while preserving custom CA certificates; FastMCP refuses the fetch when no proxy is configured instead of risking an unprotected direct request.

What's Changed

Fixes 🐞
Docs 📚

Full Changelog: PrefectHQ/fastmcp@v3.4.5...v3.4.6

v3.4.5: : Key Change

Compare Source

FastMCP 3.4.5 collects five fixes for the 3.x line. The one that prompted it: a single Ed25519 key in a JWKS — which Rauthy, Ory Hydra, and some Keycloak configurations publish by default — made JWTVerifier reject every token, including ones correctly signed by supported keys in the same set.

What's Changed

Fixes 🐞
Docs 📚

New Contributors

Full Changelog: PrefectHQ/fastmcp@v3.4.4...v3.4.5

pre-commit/pre-commit (pre-commit)

v4.6.2

Compare Source

==================

Fixes

v4.6.1

Compare Source

==================

Fixes
pydantic/pydantic (pydantic)

v2.14.0

Compare Source

GitHub release

What's Changed

The highlights of the v2.14 release are available in the blog post.
Several minor changes (considered non-breaking changes according to our versioning policy)
are also included in this release. Make sure to look into them before upgrading.

This release drops support for Python 3.9 and adds support for Python 3.15.

New Features
Changes
Fixes
New Contributors

v2.13.5: 2026-08-28

Compare Source

v2.13.5 (2026-08-28)

What's Changed
Fixes
pydantic/pydantic-settings (pydantic-settings)

v2.15.0

Compare Source

Highlights

Behavior changes
  • case_sensitive now applies to init kwargs and config-file sources (#​900). InitSettingsSource and the JSON/TOML/YAML config sources previously ignored case_sensitive. Since it defaults to False, case-insensitive matching is now the default for these sources — e.g. Settings(TeSt=...) now populates a test field where it previously did not. Nested keys are still matched case-sensitively.
  • Fields with unresolved forward references now emit a warning (#​901). Settings sources can silently fail to resolve such fields; they now raise IncompleteFieldDefinitionWarning telling you to call model_rebuild(). If you have filterwarnings = error configured, this may surface as a new failure.
  • Non-JSON env values for strict fields now raise ValidationError (#​926) instead of a less specific error.
New features
  • Show environment variable names in CLI help via cli_show_env_vars=True (#​860), so generated --help output doubles as configuration documentation.
  • PYDANTIC_SETTINGS_DEBUG for debugging settings resolution (#​906, #​913). Set it to a truthy value with DEBUG logging enabled to see each source's contribution in priority order, which source won for each value, and which env_file/secret files were probed, loaded, or skipped — the long-standing "why isn't my .env being picked up?" question.
  • toml_table_header for regular TOML files (#​882, #​886, #​887), letting you root settings at a nested table in any TOML file, not just pyproject.toml.
  • Traversable support for JSON/TOML/YAML file sources (#​902), so you can load config packaged inside a distribution — including files inside a zip or wheel — via importlib.resources.files(...) without casting to Path.
  • GCP: project_id can come from an earlier settings source (#​878), rather than only from the constructor or GOOGLE_CLOUD_PROJECT.
Bug fixes
  • Fix env vars not loading on Windows with case_sensitive=True (#​894). Windows upper-cases os.environ keys, so fields raised Field required instead of picking up their values.
  • Read secret files as UTF-8 instead of the platform locale encoding (#​917). On Windows code pages such as cp1252 this silently corrupted non-ASCII secrets.
  • Fix AliasPath on nested model fields not JSON-decoding env values (#​898).
  • Fix case-insensitive matching for optional nested models (#​905).
  • Fix dotenv extras being wrongly claimed by a complex field sharing a name prefix (#​912) — e.g. dbx_token being swallowed by a db: dict field.
  • Fix nested_model_default_partial_update=True corrupting discriminated unions (#​876).
  • Fix Secret subclasses crashing when loaded from the environment (#​920).
  • Fix enum names not parsing through nested annotations such as Optional[Annotated[MyEnum, ...]] with env_parse_enums=True (#​910).
  • An empty yaml_config_section now falls back to defaults instead of raising AttributeError: 'NoneType' object has no attribute 'keys' (#​914).
  • NestedSecretsSettingsSource no longer follows symlinks pointing outside secrets_dir (#​889).
  • GCP: skip the list_secrets call when case_sensitive=True (#​862), lowering the required IAM permissions to just roles/secretmanager.secretAccessor.
  • AWS: types-boto3[secretsmanager] is no longer required at runtime (#​880).
Documentation
  • Document JSON parsing of complex env values, plus a comma-separated-values recipe (#​919).
  • Recommend an async settings loading pattern (#​908).
  • Clarify behavior when an unprefixed value is present in a dotenv file (#​895).
  • Clarify environment variable helper descriptions (#​867) and fix assorted typos (#​904).
All changes (including dependency bumps and internal maintenance)

What's Changed

New Contributors

Full Changelog: pydantic/pydantic-settings@v2.14.1...v2.15.0

pytest-dev/pytest (pytest)

v9.1.1

Compare Source

pytest 9.1.1 (2026-06-19)

Bug fixes

  • #​14220: Fixed a logic bug in pytest.RaisesGroup which would might cause it to display incorrect "It matches FooError() which was paired with BarError" messages.
  • #​14591: Fixed a regression in pytest 9.1.0 which caused overriding a parametrized fixture with an indirect @​pytest.mark.parametrize to fail with "duplicate parametrization of '<fixture name>'".
  • #​14606: Fixed list-item typing errors from mypy in @pytest.mark.parametrize <pytest.mark.parametrize ref> argvalues parameter.
  • #​14608: Fixed a regression in pytest 9.1.0 where conftest.py files located in <invocation dir>/test* were no longer loaded as initial conftests when invoked without arguments.
    This could cause certain hooks (like pytest_addoption) in these files to not fire.

v9.1.0

Compare Source

pytest 9.1.0 (2026-06-13)

Removals and backward incompatible breaking changes

  • #​14533: When using --doctest-modules, autouse fixtures with module, package or session scope that are defined inline in Python test modules (not plugins or conftests) will now possibly execute twice.

    If this is undesirable, move the fixture definition to a conftest.py file if possible.

    Technical explanation for those interested:
    When using --doctest-modules, pytest possibly collects Python modules twice, once as pytest.Module and once as a DoctestModule (depending on the configuration).
    Due to improvements in pytest's fixture implementation, if e.g. the DoctestModule collects a fixture, it is now visible to it only, and not to the Module.
    This means that both need to register the fixtures independently.

Deprecations (removal in next major release)

  • #​10819: Added a deprecation warning for class-scoped fixtures defined as instance methods (without @classmethod). Such fixtures set attributes on a different instance than the test methods use, leading to unexpected behavior. Use @classmethod decorator instead -- by yastcher.

    See 10819 and 14011.

  • #​12882: Calling request.getfixturevalue() <pytest.FixtureRequest.getfixturevalue> during teardown to request a fixture that was not already requested is now deprecated and will become an error in pytest 10.

    See dynamic-fixture-request-during-teardown for details.

  • #​13409: Using non-~collections.abc.Collection iterables (such as generators, iterators, or custom iterable objects) for the argvalues parameter in @pytest.mark.parametrize <pytest.mark.parametrize ref> and metafunc.parametrize <pytest.Metafunc.parametrize> is now deprecated.

    These iterables get exhausted after the first iteration,
    leading to tests getting unexpectedly skipped in cases such as running pytest.main() multiple times,
    using class-level parametrize decorators,
    or collecting tests multiple times.

    See parametrize-iterators for details and suggestions.

  • #​13946: The private config.inicfg attribute is now deprecated.
    Use config.getini() <pytest.Config.getini> to access configuration values instead.

    See config-inicfg for more details.

  • #​14004: Passing baseid to ~pytest.FixtureDef or nodeid strings to fixture registration APIs is now deprecated. These are internal pytest APIs that are used by some plugins.

    Use the node parameter instead for fixture scoping. This enables more robust node-based
    matching instead of string prefix matching.
    If you've used nodeid=None, pass node=session instead.

    This will be removed in pytest 10.

  • #​14335: The method of configuring hooks using markers, deprecated since pytest 7.2, is now scheduled to be removed in pytest 10.
    See hook-markers for more details.

  • #​14434: The --pastebin option is now deprecated.
    The same functionality is now available in an external plugin, pytest-pastebin.
    See pastebin-deprecated for more details.

  • #​14513: The private FixtureDef.has_location attribute is now deprecated and will be removed in pytest 10.
    See fixturedef-has-location-deprecated for details.

  • #​1764: pytest.console_main is now deprecated and will be removed in pytest 10.
    It was never intended for programmatic use; use pytest.main instead.

New features

  • #​12376: Added pytest.register_fixture() to register fixtures using an imperative interface.

    This is an advanced function intended for use by plugins.

    Normally, fixtures should be registered declaratively using the @pytest.fixture <pytest.fixture> decorator.
    Pytest looks for these fixture definitions during the collection phase and registers them automatically.
    For some plugin usecases the declarative interface can be cumbersome or unviable, in which case this imperative interface can be used.

  • #​14023: Added --report-chars long CLI option.

  • #​14371: Added --max-warnings command-line option and max_warnings configuration option to fail the test run when the number of warnings exceeds a given threshold -- by miketheman.

  • #​6757: Added the assertion_text_diff_style configuration option, allowing
    string equality failures to be rendered as separate Left: and Right:
    blocks instead of ndiff output.

  • #​8395: Added support for ~datetime.datetime and ~datetime.timedelta comparisons with pytest.approx. An explicit abs or rel tolerance as a ~datetime.timedelta is required and relative tolerance is not supported for datetime comparisons -- by hamza-mobeen.

Improvements in existing functionality

  • #​11225: pytest.warns now shows "Regex pattern did not match" instead of "DID NOT WARN" when warnings were emitted but the match pattern did not match.

  • #​11295: Improved output of --fixtures-per-test by excluding internal-implementation fixtures generated by @pytest.mark.parametrize and similar.

  • #​13241: pytest.raises, pytest.warns and pytest.deprecated_call now uses ParamSpec for the type hint to the (old and not recommended) callable overload, instead of Any. This allows type checkers to raise errors when passing incorrect function parameters.
    func can now also be passed as a kwarg, which the type hint previously showed as possible but didn't accept.

  • #​13862: Improved the readability of "DID NOT RAISE" error messages by using the exception type's name instead of its repr.

  • #​14026: Added test coverage for compiled regex patterns in pytest.raises match parameter.

  • #​14137: pytest.ScopeName is now public to allow using it in function signatures.

  • #​14342: Marked yield_fixture as deprecated to type checkers using the deprecated decorator. Note it
    has originally been deprecated <yield-fixture-deprecated> in pytest 6.2 already.

  • #​14373: Added type annotations for pytest.approx.

  • #​14430: When using --setup-show, a space is now printed after the test name (and possibly used fixtures), to separate it from the test result.

  • #​14441: Reduced the default number of gc.collect() passes in the unraisableexception plugin from 5 to 1 on CPython, where reference counting makes a single pass sufficient. PyPy retains 5 passes due to object resurrection via __del__. This can noticeably speed up test suites that trigger many pytester runs.

  • #​14461: Improved assertion failure explanations for equality comparisons between mapping objects that are not dict instances.

  • #​14513: The order in which fixture definitions overriding each other are resolved is now determined first by their visibility in the collection tree rather than by the order in which they are registered.

    A fixture defined for a more specific node (e.g. a module or an item) now always takes precedence over one with the same name defined for a more general node (e.g. the session), even when the more general one was registered later.
    Fixtures with non-comparable visibility or the same visibility keep the existing behavior of "last registered wins".
    This change is supposed to only affect plugins which register multiple fixtures programmatically with the same name.

  • #​14524: Add official Python 3.15 support.

  • #​1764: Improved argparse program name to show pytest, python -m pytest, or pytest.main() based on how pytest was invoked, making help and error messages clearer.

  • #​8265: Emit a PytestCollectionWarning when a module-level __getattr__ returns None for pytestmark instead of raising AttributeError.

    Previously this caused a cryptic TypeError: got None instead of Mark error.
    Now pytest issues a helpful warning and continues collecting the module normally.

Bug fixes

  • #​13192: Fixed | (pipe) not being treated as a regex meta-character that needs escaping in pytest.raises(match=...) <pytest.raises>.

  • #​13484: Fixed -W option values being duplicated in Config.known_args_namespace.

  • #​13626: Fixed function-scoped fixture values being kept alive after a test was interrupted by KeyboardInterrupt or early exit,
    allowing them to potentially be released more promptly.

  • #​13784: Fixed capteesys producing doubled output when used with --capture=no (-s).

  • #​13817: Fixed a secondary AttributeError masking the original error when an option argument fails to initialize.

  • #​13884: Fixed rare internal IndexError caused by builtins.compile being overridden in client code.

  • #​13885: Fixed autouse fixtures defined inside a unittest.TestCase class running even when the class is decorated with unittest.skip or unittest.skipIf -- regression since pytest 8.1.0.

  • #​13917: unittest.SkipTest is no longer considered an interactive exception, i.e. pytest_exception_interact is no longer called for it.

  • #​13963: Fixed subtests running with pytest-xdist when their contexts contain objects that are not JSON-serializable.

    Fixes pytest-dev/pytest-xdist#1273.

  • #​14004: Fixed conftest.py fixture scoping when testpaths points outside of the rootdir <rootdir>.

    Previously, fixtures from nested conftest.py files would incorrectly leak to sibling directories
    when using a relative testpaths like ../tests/sdk.

    Conftest fixtures are now parsed during Directory <pytest.Directory> collection, using the Directory node for proper scoping.

  • #​14050: Display dictionary differences in assertion failures using the original key insertion order instead of sorted order.

  • #​14080: fix missing type annotations on Pytester.makepyfile and Pytester.maketxtfile methods.

  • #​14114: An exception from pytest_fixture_post_finalizer no longer prevents fixtures from being torn down, causing additional errors in the following tests.

  • #​14161: Fixed monkeypatch.setattr() <pytest.MonkeyPatch.setattr> leaving a stale entry on the undo stack when the underlying setattr() call fails (e.g. on immutable targets), causing an AttributeError crash during teardown.

  • #​14214: Fixed -v hint in pytest.raises match diff not working because assertion verbosity was not propagated.

  • #​14234: Allow pytest.HIDDEN_PARAM <hidden-param> in @pytest.mark.parametrize(ids=...) <pytest.mark.parametrize ref> typing.

  • #​14248: Fixed direct parametrization causing the static fixture closure (as reflected in request.fixturenames <pytest.FixtureRequest.fixturenames>) to omit fixtures that are requested transitively from overridden fixtures.

  • #​14263: Unraisable exceptions from finalizers are now collected during pytest_unconfigure, before pytest tears down the warning filters installed for the session. Previously the collection ran from a cleanup callback whose order relative to other plugins' cleanups was not guaranteed, so an active error filter could be removed before the exception surfaced and a late resource leak would pass silently. A -W error filter, or any filter matching pytest.PytestUnraisableExceptionWarning, now promotes these exceptions to failures regardless of plugin cleanup order.

  • #​14377: Fixed crash in Config.get_terminal_writer when an assertion fails with the terminalreporter plugin disabled.

  • #​14381: Fixed -V (short form of --version) to properly display the current version.

  • #​14389: Improved pytest.raises(..., match=...) <pytest.raises> failures to suppress the mismatched exception as a cause of the resulting AssertionError.

  • #​14392: Fixed a bug in pytest.raises(match=...) <pytest.raises> "fully escaped" detection, causing the regex diff display to be shown in some instances when the raw string diff display should be shown instead.

  • #​14442: Fixed a regression in pytest 9.0 where --strict-markers and --strict-config specified through addopts were silently ignored.

    Note that when targeting pytest >= 9.0, it's nicer to use strict_markers and strict_config, or strict mode <strict mode>.

  • #​14456: Fixed pytest.approx not recognizing types with __array_interface__ as numpy-like arrays.

  • #​14474: Fixed a regression where -k and -m expressions containing both backslash characters in identifiers and string literal arguments would incorrectly raise a SyntaxError about escaping.

  • #​14483: Fixed JUnit XML report incorrectly escaping high Unicode codepoints (supplementary plane characters like emoji) in test failure messages. -- by EternalRights

  • #​14492: Fixed Code.getargs() incorrectly including local variable names in the returned argument tuple for functions with *args and/or **kwargs. The method was using co_flags bitmask values (4 and 8) directly as counts instead of converting them to 1 via bool(), and was not accounting fo

❗ Important

✂ PR body was truncated to here.

@renovate
renovate Bot requested a review from z23 as a code owner September 15, 2026 00:12
@github-actions

github-actions Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Vulnerability Scan: Failed — blocking vulnerabilities detected

Image: netbox-mcp-server:scan

Source Library CVE Severity Installed Fixed Title
netbox-mcp-server:scan (alpine 3.23.4) zlib CVE-2026-85091 🟡 MEDIUM 1.3.2-r0 1.3.2-r1 zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ...
Python PyJWT CVE-2026-102268 🔴 CRITICAL 2.13.0 2.14.0 PyJWT is a Python implementation of JSON Web Token standards. Prior to ...
Python PyJWT CVE-2026-102266 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Authentication bypass via empty HMAC key acceptance
Python PyJWT CVE-2026-102267 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Verification key substitution via unvalidated JWKS redirects
Python PyJWT CVE-2026-102271 🟠 HIGH 2.13.0 2.14.0 pyjwt: PyJWT: Authentication bypass via acceptance of DER public keys as HMAC se
Python PyJWT CVE-2026-102272 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Token forgery via improper Unicode byte-order mark handling
Python PyJWT CVE-2026-102273 🟠 HIGH 2.13.0 2.14.0 pyjwt: pyjwt: Token forgery via acceptance of public JWK containers as HMAC secr
Python PyJWT CVE-2026-101917 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: PyJWT: Denial of Service via outbound request amplification on unknown ke
Python PyJWT CVE-2026-101918 🟡 MEDIUM 2.13.0 2.15.0 pyjwt: PyJWT: Denial of Service via deeply nested JSON token payload
Python PyJWT CVE-2026-102265 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: pyjwt: Denial of Service via deeply nested token headers
Python PyJWT CVE-2026-102269 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: PyJWT: Token revocation bypass via non-canonical signature decoding
Python PyJWT CVE-2026-102270 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: pyjwt: Denial of Service via regular expression backtracking in is_pem_fo
Python PyJWT CVE-2026-102274 🟡 MEDIUM 2.13.0 2.14.0 pyjwt: pyjwt: Denial of Service via malformed RSA key in JWK set
Python PyJWT CVE-2026-102275 🟡 MEDIUM 2.13.0 2.15.0 pyjwt: PyJWT: Token verification bypass via mismatched OKP key components
Python anyio CVE-2026-63374 🔴 CRITICAL 4.12.1 4.14.2 anyio: AnyIO: TLS certificate spoofing via improper internationalized domain nam
Python anyio CVE-2026-64847 🟡 MEDIUM 4.12.1 4.14.2 anyio: AnyIO: Denial of Service due to undrained stderr in process-pool workers
Python cryptography CVE-2026-69247 🟠 HIGH 49.0.0 50.0.0 python-cryptography: python-cryptography: PKCS#7 EnvelopedData decryption expose
Python pip CVE-2026-13346 🟡 MEDIUM 26.1.2 26.2.0 pip: pip: Arbitrary file installation via malicious package indexes

Commit: 801d371

@renovate
renovate Bot force-pushed the renovate/non-major-python-dependencies branch from f3832a9 to 5e7ae07 Compare September 20, 2026 02:56
@renovate
renovate Bot force-pushed the renovate/non-major-python-dependencies branch 2 times, most recently from 8d6c118 to ace5238 Compare October 6, 2026 07:42
@renovate
renovate Bot force-pushed the renovate/non-major-python-dependencies branch from ace5238 to 2467781 Compare October 9, 2026 04:11
@renovate
renovate Bot force-pushed the renovate/non-major-python-dependencies branch from 2467781 to 66677c0 Compare October 10, 2026 15:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants