chore(deps): bump the uv group across 1 directory with 19 updates - #870
Open
dependabot[bot] wants to merge 1 commit into
Open
chore(deps): bump the uv group across 1 directory with 19 updates#870dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
|
PR author is not in the allowed authors list. |
|
2027 auto-runs evals against preview deployments of your docs. To enable this, install one of:
Once a preview is deployed, open a new PR and we'll run the eval automatically. Evaluating agent experience using 2027.dev · View dashboard |
dependabot
Bot
force-pushed
the
dependabot/uv/uv-826e3ecf5c
branch
from
July 28, 2026 13:59
4a58d28 to
69c8fcb
Compare
Member
dependabot
Bot
force-pushed
the
dependabot/uv/uv-826e3ecf5c
branch
from
August 7, 2026 17:32
69c8fcb to
50dcc9f
Compare
--- updated-dependencies: - dependency-name: aiohttp dependency-version: 3.14.1 dependency-type: direct:production - dependency-name: authlib dependency-version: 1.6.12 dependency-type: indirect - dependency-name: bleach dependency-version: 6.4.0 dependency-type: indirect - dependency-name: cryptography dependency-version: 48.0.1 dependency-type: direct:production - dependency-name: httplib2 dependency-version: 0.32.0 dependency-type: indirect - dependency-name: idna dependency-version: '3.15' dependency-type: indirect - dependency-name: json-repair dependency-version: 0.60.1 dependency-type: direct:production - dependency-name: jupyter-server dependency-version: 2.20.0 dependency-type: indirect - dependency-name: jupyterlab dependency-version: 4.5.10 dependency-type: indirect - dependency-name: langsmith dependency-version: 0.8.18 dependency-type: indirect - dependency-name: mistune dependency-version: 3.3.0 dependency-type: indirect - dependency-name: pillow dependency-version: 12.3.0 dependency-type: direct:production - dependency-name: pyasn1 dependency-version: 0.6.4 dependency-type: indirect - dependency-name: pypdf dependency-version: 6.14.2 dependency-type: indirect - dependency-name: setuptools dependency-version: 83.0.0 dependency-type: indirect - dependency-name: soupsieve dependency-version: 2.8.4 dependency-type: indirect - dependency-name: starlette dependency-version: 1.3.1 dependency-type: indirect - dependency-name: tornado dependency-version: 6.5.7 dependency-type: indirect - dependency-name: urllib3 dependency-version: 2.7.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/uv/uv-826e3ecf5c
branch
from
August 18, 2026 12:55
50dcc9f to
46fe336
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the uv group with 19 updates in the / directory:
11.3.012.3.046.0.250.0.03.11.183.14.30.57.10.60.11.6.61.6.126.2.06.4.00.31.00.32.03.103.152.17.02.20.04.4.94.5.100.4.320.8.183.1.43.3.00.6.20.6.46.6.26.15.080.9.083.0.02.82.8.40.49.11.3.16.5.26.5.72.6.32.7.0Updates
pillowfrom 11.3.0 to 12.3.0Release notes
Sourced from pillow's releases.
... (truncated)
Commits
bb1d8e812.3.0 version bumpe63fc48Add release notes for SBOM and performance improvements (#9747)13b701bAdd release notes for #96795564ca7List methodsa0920fdSpeed up ImageChops operations (#9738)07e9a6cSpeed upImage.filter()(#9736)a94578cSpeed upImage.getchannel(),Image.merge(),Image.putalpha()and `Image...53e02c4Speed upImage.fill(),Image.linear_gradient()and `Image.radial_gradient...af03747Speed upImage.resample()(#9739)5c9ca56Speed upalpha_composite,matrix,negative,quantize(#9740)Updates
cryptographyfrom 46.0.2 to 50.0.0Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
dcb7050Prepare for 50.0.0 release (#15372)53fccd9Don't leak how PKCS#7 encryptedKey decryption failed (#15369)d472f97Addfrom __future__ import annotationsto all src/ Python files (#15371)908773dBump downstream dependencies in CI (#15368)2cc07ccBump BoringSSL, OpenSSL, AWS-LC in CI (#15367)c94ede9chore(deps): bump ruff from 0.16.0 to 0.16.1 (#15366)67a8308chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (#15365)95018ffRelease the GIL in one-shot AEAD encrypt/decrypt (#15361)6954733Release the GIL during DH and DSA parameter generation (#15364)6893b94Import _serialization instead of serialization in x509/extensions (#15363)Updates
aiohttpfrom 3.11.18 to 3.14.3Updates
json-repairfrom 0.57.1 to 0.60.1Release notes
Sourced from json-repair's releases.
... (truncated)
Commits
63992e9Fix circular schema ref handling7cd8391Fix #198 support low smart quote spans in strings46be950update ANGENTS guidance0015c74Fix README example for #197d7f2a3bFix #195 keep balanced braces in strings4206302Fix top-level comma-separated object repair9c9db65Fix #195 preserve LaTeX escapes after prose commasdbec25aBump version to 0.59.7397fbe0Fix #195 preserve escaped brace groupsb8cd2e2Fix #194 line comments with bracketsUpdates
authlibfrom 1.6.6 to 1.6.12Release notes
Sourced from authlib's releases.
Changelog
Sourced from authlib's changelog.
Commits
e46e515chore: bump to 1.6.129babc13fix: redirecting to unvalidated redirect_uri on InvalidScopeError in OIDC grants0dc0e5bchore: bump to 1.6.11aa7b8e4Merge commit from fork401a770fix: CSRF issue with starlette clientef09aebchore: release 1.6.103be0846fix: redirecting to unvalidated redirect_uri on UnsupportedResponseTypeError9266eaachore: release 1.6.9b9bb2b2fix(oidc): fail close at validating c_hash and at_hash1b0a1d9fix(jose): generate random cek when cek length doesn't matchUpdates
bleachfrom 6.2.0 to 6.4.0Changelog
Sourced from bleach's changelog.
... (truncated)
Commits
f0355a7fix: fix last release date in CHANGESae4e8a2chore: bleach 6.4.0 and final release970df58fix: uri-sanitization in formaction attributes7c4867cfix: xss bypass in allowed protocol test using unicode invisible characters913ab75fix: reduce redundancy in workflow jobs218c15afix: rework pip caching4f0b097fix: fix tox platform restrictionse95a79dchore: update pytest91539d4Bump actions/cache from 5.0.3 to 5.0.4cd47b4cfix: handle left-angle-bracket that's not a tag (#733)Updates
httplib2from 0.31.0 to 0.32.0Changelog
Sourced from httplib2's changelog.
Commits
ba9bf50v0.32.0 release87581addecompression limited by size and ratio; require python 3.8+a99a11fv0.31.2 release370010adep-compat: pp.DelimitedList (camel case) only available in pyparsing>=3.16d2ea32v0.31.1 released1b0ce3auth: use pyparsing v3 PEP8-compliant method names3288ba7chore: harden publishing. use github attestationsUpdates
idnafrom 3.10 to 3.15Changelog
Sourced from idna's changelog.
... (truncated)
Commits
af30a09Release 3.1530314d4Pre-release 3.15rc005d4b21Merge pull request #237 from kjd/convert-docs-to-markdown2987fdbConvert README and HISTORY from reStructuredText to Markdown59fa800Merge pull request #236 from kjd/dependabot/github_actions/actions-f3e34333eadef6983Merge branch 'master' into dependabot/github_actions/actions-f3e34333eabbd8004Merge pull request #234 from StanFromIreland/patch-1edd07c0Bump github/codeql-action from 3.35.2 to 4.35.2 in the actions group5557db0Merge branch 'master' into patch-1f11746cMerge pull request #235 from StanFromIreland/patch-2Updates
jupyter-serverfrom 2.17.0 to 2.20.0Release notes
Sourced from jupyter-server's releases.
... (truncated)
Changelog
Sourced from jupyter-server's changelog.
... (truncated)
Commits
05a78adPublish 2.20.06cbee8dMerge commit from fork333e700Fixtest_authorizerhaving a spurious comma in params (#1664)cccd543Fix CI: explicitly pass base-setup inputs to avoid strict validation failurescd16d71Align docs for curve encryption with latest JEP version (#1660)e458061Add a toggle to enable curve encryption for all kernels that support it (#1638)0ceeb4fAdd note in RELEASE.mdb13f8a2Markdown does not work.e885b10Add GHSA reminder in prep-release0e28c90Exclude problematicpywinpty3.0.4 version (#1658)Updates
jupyterlabfrom 4.4.9 to 4.5.10Release notes
Sourced from jupyterlab's releases.
... (truncated)
Commits
af5f5b3[ci skip] Publish 4.5.10be9303fBackport of security patches to4.5.xbranch (#19186)a555fe1Reconfigure 4.5.x branch (4.6.x is new stable) (#19060)8d8cb6dBackport PR #19029 on branch 4.5.x (Split external link checks and only run i...dd65403[ci skip] Publish 4.5.92693672Backport PR #18992: Fix hidden cells after moving collapsed headings (#19016)360c176Backport PR #18998 on branch 4.5.x (Fix toolbar popup row clipping in Safari)...e9db010Fixjupyter labextension buildcrash onwebpack ≥ 5.107(#19021)3b8428cBackport PR #19013 on branch 4.5.x (Forbid relative URLs in extensionmanager)...3c84a84Backport PR #19003 on branch 4.5.x (Fix XSS in extension manager's `homepage_...Updates
langsmithfrom 0.4.32 to 0.8.18Release notes
Sourced from langsmith's releases.