fix(deps): update all non-major dependencies - autoclosed #59

Merged
renovate[bot] merged 1 commit from renovate/all-minor-patch into main 2026-09-04 08:16:12 +00:00
renovate[bot] commented 2026-07-19 18:07:46 +00:00 (Migrated from github.com)

This PR contains the following updates:

Package Change Age Confidence Type Update
aiohttp ==3.14.1 → ==3.14.3 age confidence project.dependencies patch
fastapi (changelog) ==0.139.2 → ==0.141.1 age confidence project.dependencies minor
lxml (source, changelog) ==6.1.1 → ==6.1.3 age confidence project.dependencies patch
orjson (changelog) ==3.11.9 → ==3.12.0 age confidence project.dependencies minor
pydantic (changelog) ==2.13.4 → ==2.13.5 age confidence project.dependencies patch
pydantic-settings (changelog) ==2.14.2 → ==2.15.0 age confidence project.dependencies minor
pypa/gh-action-pypi-publish v1.14.0 → v1.14.2 age confidence action patch
uvicorn (changelog) ==0.51.0 → ==0.52.4 age confidence project.dependencies minor

Release Notes

aio-libs/aiohttp (aiohttp)

v3.14.3

Compare Source

===================

Bug fixes

  • Fixed the client dropping only the first Authorization, Cookie and
    Proxy-Authorization header when a redirect crossed an origin -- by :user:arshsmith1.

    Related issues and pull requests on GitHub:
    :issue:13180.

  • Fixed error message construction in the C HTTP parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:13222.


v3.14.2

Compare Source

===================

Bug fixes

  • Fixed :py:attr:~aiohttp.web.StreamResponse.last_modified rounding a
    :class:datetime.datetime with a fractional second down.

    Related issues and pull requests on GitHub:
    :issue:5303.

  • Fixed resolving localhost on Windows to fall back without AI_ADDRCONFIG
    when the first lookup fails, so localhost still works without an active
    network.

    Related issues and pull requests on GitHub:
    :issue:5357.

  • Rejected multipart body parts whose Content-Length header is not a
    plain sequence of digits (e.g. +5, -1, 1_0), matching the
    strictness of the main request parser per :rfc:9110#section-8.6
    -- by :user:dxbjavid.

    Related issues and pull requests on GitHub:
    :issue:12794.

  • Fixed GunicornWebWorker endlessly reloading when app fails during startup -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12879.

  • Fixed some inconsistent case sensitivity on request methods -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12931.

  • Fixed IndexError: string index out of range in parse_content_disposition
    when a header parameter has an empty value (e.g. filename=).
    -- by :user:JSap0914.

    Related issues and pull requests on GitHub:
    :issue:12948.

  • Fixed the sock_read timeout being re-armed on a keep-alive connection after
    it had been returned to the pool. An idle pooled connection could be left with a
    pending read timeout that fired and poisoned it, so the next request reusing the
    connection failed immediately with :exc:aiohttp.SocketTimeoutError. The read
    timeout is now only rescheduled when resuming a transport that was actually
    paused -- by :user:daragok.

    Related issues and pull requests on GitHub:
    :issue:12953, :issue:12954.

  • Fixed the client decompressing frames when permessage-deflate was not negotiated -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12976.

  • Fixed DigestAuthMiddleware raising an IndexError on empty domain -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12983.

  • Fixed :class:~aiohttp.DigestAuthMiddleware corrupting the Digest
    challenge when a WWW-Authenticate response offered more than one
    authentication scheme -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12984.

  • Fixed client not closing cleanly after an exception -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12985.

  • Fixed control frames breaking fragmented WebSocket messages -- by :user:arshsmith1.

    Related issues and pull requests on GitHub:
    :issue:12988.

  • Fixed parse_content_disposition rejecting otherwise-valid
    Content-Disposition header values that contain optional whitespace (OWS)
    around the disposition type (e.g. "form-data ; name=\"field\"").
    The disposition type is now stripped before token validation, consistent with
    how parameter keys are already handled -- by :user:JSap0914.

    Related issues and pull requests on GitHub:
    :issue:12996.

  • Fixed an :exc:IndexError in the pure-Python HTTP parser -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13001.

  • Fixed parsing optional whitespace in Content-Disposition -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13002.

  • Fixed request body not being read on rejected WebSocket upgrades -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13016.

  • Fixed :exc:LookupError (and an unguarded :exc:UnicodeDecodeError) escaping
    Content-Disposition parsing when a multipart part supplies an extended
    parameter with an unknown charset
    -- by :user:arshsmith1.

    Related issues and pull requests on GitHub:
    :issue:13042.

  • Fixed escape_quotes in the Digest authentication middleware not escaping
    backslashes, so a WWW-Authenticate challenge value containing a backslash
    could break out of its quoted-string in the generated Authorization header
    -- by :user:dxbjavid.

    Related issues and pull requests on GitHub:
    :issue:13054.

  • Fixed Python parser not rejecting a bare LF in the request line -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13136.

  • Fixed the C HTTP parser folding the fragment into the query string for an
    origin-form request target with an empty query (e.g. /path?#frag),
    which diverged from the pure-Python parser -- by :user:GiulioDER.

    Related issues and pull requests on GitHub:
    :issue:13171.

  • Fixed the C parser reporting newer HTTP methods such as QUERY as <unknown>;
    the method table is now derived from the vendored llhttp instead of a hand-maintained count
    -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13174.

Packaging updates and notes for downstreams

  • Upgraded llhttp to v9.4.2 -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12956.

Contributor-facing changes

  • Added admin documentation on incident response and on running reproducer code
    safely, covering security vulnerability handling and supply-chain, account, and
    CI/infrastructure compromise -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12914.


fastapi/fastapi (fastapi)

v0.141.1

Compare Source

Fixes
  • 🐛 Fix support for background tasks and headers from dependencies in app.frontend(). PR #​16105 by @​tiangolo.
Docs

v0.141.0

Compare Source

Features
  • ✨ Add app.frontend(check_dir="auto"), to make local development more convenient with fastapi dev. PR #​16102 by @​tiangolo.

v0.140.13

Compare Source

Fixes
Docs

v0.140.12

Compare Source

Fixes

v0.140.11

Compare Source

v0.140.10

Compare Source

Fixes
Internal

v0.140.9

Compare Source

Fixes
  • 🐛 Fix exclude_defaults not propagated to dict keys and values in jsonable_encoder. PR #​16043 by @​MBGrao.
Internal

v0.140.8

Compare Source

Fixes

v0.140.7

Compare Source

Refactors
Internal

v0.140.6

Compare Source

Refactors
  • ⚡️ Avoid flattening dependencies for request parameters, mainly for OpenAPI. PR #​16073 by @​tiangolo.

v0.140.5

Compare Source

Refactors

v0.140.4

Compare Source

v0.140.3

Compare Source

Refactors

v0.140.2

Compare Source

Refactors
Internal

v0.140.1

Compare Source

Refactors
  • ♻️ Update the lru_cache limit for dependencies to account for large apps. PR #​16062 by @​tiangolo.

v0.140.0

Compare Source

Refactors
Docs
Internal
lxml/lxml (lxml)

v6.1.3

Compare Source

v6.1.2

Compare Source

==================

  • GH#526: Some build files were missing in the sdist.
    Patch by Nicola Soranzo.

  • Some minor corrections for error handling cases.

Other changes

  • Built with Cython 3.2.9.
ijl/orjson (orjson)

v3.12.0

Compare Source

Changed
  • Serialization implementation substantially rewritten.
  • Publish PyPI wheels for Python 3.15. For Python 3.15 and later,
    manylinux_2_39 (2024) is targeted instead of manylinux_2_17 (2012).
  • No longer publish PyPI wheels for ppc64le and s390x.
pydantic/pydantic (pydantic)

v2.13.5

Compare Source

pydantic/pydantic-settings (pydantic-settings)

v2.15.0

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/pydantic/pydantic-settings/compare/v2.14.1...v2.15.0

pypa/gh-action-pypi-publish (pypa/gh-action-pypi-publish)

v1.14.2

Compare Source

This one probably won't touch you visibly so just bookmark @webknjaz's EuroPython 2026 “AI” slop rant for when it's published on YouTube or encourage him to come back with more to share next year!

🛠️ Urgh… Another release!? Again? Explain yourself!

Looking at the diff, you'll only witness updates across the dependency tree. That's it! It's not a security fix or anything like that even, no. But you'll want this update.

[!tip]
So what most people will find useful is @​takluyver💰's update of Twine to v7 that we use internally (#​416). This version will let them upload their sdists and wheels containing core packaging metadata v2.5 to (Test)PyPI.

🧐 Tell me why..

The rest of the updates bump things related to pypi-attestations and sigstore, which has the most interesting backstory here. @​facutuesca💰 sent a patch in #​417 but a bunch more helped out.

TL;DR non-pure-python projects with C-extensions tend to have dozens (sometimes hundreds) wheels to upload to PyPI per release. They are often quite big and take time to transfer over the network. People started noticing problems and coming up with DIY sharding workarounds like aio-libs/aiohttp#13226 around July 23.
On this date, projects with a good amount of bytes to publish would start getting timeouts 5 minutes after the PyPI publishing job begun. The same job that worked just fine before.

I had to start pinging upstream library and ecosystem people, on GitHub and privately, to start making sense of what was happening. Eventually, we collectively concluded that GitHub must've shortened the lifetime of their OIDC identity — it seems to have used to be 10 minutes long (at some point in the past) and is now 5 minutes, apparently. It's not documented clearly, and we have not been able to get any clarity by attempting to contact GitHub through private channels, using personal connections.

Over the course of investigation, @​facutuesca💰 found and fixed a related underlying cache invalidation bug in sigstore/sigstore-python#1838, which he then coordinated propagation through the dependency chain updates in sigstore-python, pypi-attestations, gh-action-pypi-publish and gh-action-sigstore-python.

Mike's also discovered that Sigstore's Rekor slowdown seems to have become the main contributing cause of the last week's incident. He's collected some data to support this claim: https://publishing-five-minute-timeout.tiiny.site.

Edge Cake XKCD feels just like this release

🫶 New Contributors

🪞 Full Diff: https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

🙏 Special Thanks to @​davidbrochart💰 and @​Dreamsorcerer💰 for turning my attention (in #​415 and in private) to the newly surfaced corner case in GitHub's behavior that only affected a narrow category of projects while many others remained blissfully unaware. @​bdraco💰 came up with a DIY sharding workaround for aiohttp that served as a demo for other projects. @​miketheman💰 confirmed the Warehouse-side details. Also, @​jku💰 and @​woodruffw💰 helped work through, review and release the Sigstore ecosystem upstream libs.

💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.

GH Sponsors badge

v1.14.1

Compare Source

This release was cut at EuroPython 2026 Sprints

🛠️ Internal Dependencies

@​adisivaprasad💰 helped get rid of the GitHub Actions runner warning about the old Node 20 runtime being used by updating actions/setup-python from v5.6.0 to v6.2.0 in #​408.

💪 New Contributors

🪞 Full Diff: https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.0...v1.14.1

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

🙏 Special Thanks to @​jylenhof💰 for reminding me to work on this release!

💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.

GH Sponsors badge

Kludex/uvicorn (uvicorn)

v0.52.4: Version 0.52.4

Compare Source

Fixed
  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#​3078)

Full Changelog: https://github.com/Kludex/uvicorn/compare/0.52.3...0.52.4

v0.52.3: Version 0.52.3

Compare Source

Changed
  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#​3067)

Full Changelog: https://github.com/Kludex/uvicorn/compare/0.52.2...0.52.3

v0.52.2: Version 0.52.2

Compare Source

Fixed
  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#​3063)

Full Changelog: https://github.com/Kludex/uvicorn/compare/0.52.1...0.52.2

v0.52.1: Version 0.52.1

Compare Source

Fixed
  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#​3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#​3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#​3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#​3041)

Full Changelog: https://github.com/Kludex/uvicorn/compare/0.52.0...0.52.1

v0.52.0: Version 0.52.0

Compare Source

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added
  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#​2979)
Fixed
  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#​3036)

Full Changelog: https://github.com/Kludex/uvicorn/compare/0.51.0...0.52.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | Type | Update | |---|---|---|---|---|---| | [aiohttp](https://redirect.github.com/aio-libs/aiohttp) | `==3.14.1` → `==3.14.3` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/aiohttp/3.14.3?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/aiohttp/3.14.1/3.14.3?slim=true) | project.dependencies | patch | | [fastapi](https://redirect.github.com/fastapi/fastapi) ([changelog](https://fastapi.tiangolo.com/release-notes/)) | `==0.139.2` → `==0.141.1` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/fastapi/0.141.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/fastapi/0.139.2/0.141.1?slim=true) | project.dependencies | minor | | [lxml](https://lxml.de/) ([source](https://redirect.github.com/lxml/lxml), [changelog](https://git.launchpad.net/lxml/plain/CHANGES.txt)) | `==6.1.1` → `==6.1.3` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/lxml/6.1.3?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/lxml/6.1.1/6.1.3?slim=true) | project.dependencies | patch | | [orjson](https://redirect.github.com/ijl/orjson) ([changelog](https://redirect.github.com/ijl/orjson/blob/master/CHANGELOG.md)) | `==3.11.9` → `==3.12.0` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/orjson/3.12.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/orjson/3.11.9/3.12.0?slim=true) | project.dependencies | minor | | [pydantic](https://redirect.github.com/pydantic/pydantic) ([changelog](https://docs.pydantic.dev/latest/changelog/)) | `==2.13.4` → `==2.13.5` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/pydantic/2.13.5?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/pydantic/2.13.4/2.13.5?slim=true) | project.dependencies | patch | | [pydantic-settings](https://redirect.github.com/pydantic/pydantic-settings) ([changelog](https://redirect.github.com/pydantic/pydantic-settings/releases)) | `==2.14.2` → `==2.15.0` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/pydantic-settings/2.15.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/pydantic-settings/2.14.2/2.15.0?slim=true) | project.dependencies | minor | | [pypa/gh-action-pypi-publish](https://redirect.github.com/pypa/gh-action-pypi-publish) | `v1.14.0` → `v1.14.2` | ![age](https://developer.mend.io/api/mc/badges/age/github-tags/pypa%2fgh-action-pypi-publish/v1.14.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/github-tags/pypa%2fgh-action-pypi-publish/v1.14.0/v1.14.2?slim=true) | action | patch | | [uvicorn](https://redirect.github.com/Kludex/uvicorn) ([changelog](https://uvicorn.dev/release-notes)) | `==0.51.0` → `==0.52.4` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/uvicorn/0.52.4?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/uvicorn/0.51.0/0.52.4?slim=true) | project.dependencies | minor | --- ### Release Notes <details> <summary>aio-libs/aiohttp (aiohttp)</summary> ### [`v3.14.3`](https://redirect.github.com/aio-libs/aiohttp/blob/HEAD/CHANGES.rst#3143-2026-07-22) [Compare Source](https://redirect.github.com/aio-libs/aiohttp/compare/v3.14.2...v3.14.3) \=================== ## Bug fixes - Fixed the client dropping only the first `Authorization`, `Cookie` and `Proxy-Authorization` header when a redirect crossed an origin -- by :user:`arshsmith1`. *Related issues and pull requests on GitHub:* :issue:`13180`. - Fixed error message construction in the C HTTP parser -- by :user:`bdraco`. *Related issues and pull requests on GitHub:* :issue:`13222`. *** ### [`v3.14.2`](https://redirect.github.com/aio-libs/aiohttp/blob/HEAD/CHANGES.rst#3142-2026-07-20) [Compare Source](https://redirect.github.com/aio-libs/aiohttp/compare/v3.14.1...v3.14.2) \=================== ## Bug fixes - Fixed :py:attr:`~aiohttp.web.StreamResponse.last_modified` rounding a :class:`datetime.datetime` with a fractional second down. *Related issues and pull requests on GitHub:* :issue:`5303`. - Fixed resolving `localhost` on Windows to fall back without `AI_ADDRCONFIG` when the first lookup fails, so `localhost` still works without an active network. *Related issues and pull requests on GitHub:* :issue:`5357`. - Rejected multipart body parts whose `Content-Length` header is not a plain sequence of digits (e.g. `+5`, `-1`, `1_0`), matching the strictness of the main request parser per :rfc:`9110#section-8.6` \-- by :user:`dxbjavid`. *Related issues and pull requests on GitHub:* :issue:`12794`. - Fixed `GunicornWebWorker` endlessly reloading when app fails during startup -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`12879`. - Fixed some inconsistent case sensitivity on request methods -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`12931`. - Fixed `IndexError: string index out of range` in `parse_content_disposition` when a header parameter has an empty value (e.g. `filename=`). \-- by :user:`JSap0914`. *Related issues and pull requests on GitHub:* :issue:`12948`. - Fixed the `sock_read` timeout being re-armed on a keep-alive connection after it had been returned to the pool. An idle pooled connection could be left with a pending read timeout that fired and poisoned it, so the next request reusing the connection failed immediately with :exc:`aiohttp.SocketTimeoutError`. The read timeout is now only rescheduled when resuming a transport that was actually paused -- by :user:`daragok`. *Related issues and pull requests on GitHub:* :issue:`12953`, :issue:`12954`. - Fixed the client decompressing frames when `permessage-deflate` was not negotiated -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`12976`. - Fixed `DigestAuthMiddleware` raising an `IndexError` on empty domain -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`12983`. - Fixed :class:`~aiohttp.DigestAuthMiddleware` corrupting the `Digest` challenge when a `WWW-Authenticate` response offered more than one authentication scheme -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`12984`. - Fixed client not closing cleanly after an exception -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`12985`. - Fixed control frames breaking fragmented WebSocket messages -- by :user:`arshsmith1`. *Related issues and pull requests on GitHub:* :issue:`12988`. - Fixed `parse_content_disposition` rejecting otherwise-valid `Content-Disposition` header values that contain optional whitespace (OWS) around the disposition type (e.g. `"form-data ; name=\"field\""`). The disposition type is now stripped before token validation, consistent with how parameter keys are already handled -- by :user:`JSap0914`. *Related issues and pull requests on GitHub:* :issue:`12996`. - Fixed an :exc:`IndexError` in the pure-Python HTTP parser -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13001`. - Fixed parsing optional whitespace in Content-Disposition -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13002`. - Fixed request body not being read on rejected WebSocket upgrades -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13016`. - Fixed :exc:`LookupError` (and an unguarded :exc:`UnicodeDecodeError`) escaping `Content-Disposition` parsing when a multipart part supplies an extended parameter with an unknown charset \-- by :user:`arshsmith1`. *Related issues and pull requests on GitHub:* :issue:`13042`. - Fixed `escape_quotes` in the Digest authentication middleware not escaping backslashes, so a `WWW-Authenticate` challenge value containing a backslash could break out of its quoted-string in the generated `Authorization` header \-- by :user:`dxbjavid`. *Related issues and pull requests on GitHub:* :issue:`13054`. - Fixed Python parser not rejecting a bare `LF` in the request line -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13136`. - Fixed the C HTTP parser folding the fragment into the query string for an origin-form request target with an empty query (e.g. `/path?#frag`), which diverged from the pure-Python parser -- by :user:`GiulioDER`. *Related issues and pull requests on GitHub:* :issue:`13171`. - Fixed the C parser reporting newer HTTP methods such as `QUERY` as `<unknown>`; the method table is now derived from the vendored llhttp instead of a hand-maintained count \-- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`13174`. ## Packaging updates and notes for downstreams - Upgraded `llhttp` to v9.4.2 -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`12956`. ## Contributor-facing changes - Added admin documentation on incident response and on running reproducer code safely, covering security vulnerability handling and supply-chain, account, and CI/infrastructure compromise -- by :user:`Dreamsorcerer`. *Related issues and pull requests on GitHub:* :issue:`12914`. *** </details> <details> <summary>fastapi/fastapi (fastapi)</summary> ### [`v0.141.1`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.141.1) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.141.0...0.141.1) ##### Fixes - 🐛 Fix support for background tasks and headers from dependencies in `app.frontend()`. PR [#&#8203;16105](https://redirect.github.com/fastapi/fastapi/pull/16105) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ##### Docs - 📝 Document `FASTAPI_ENV` in FastAPI CLI guide. PR [#&#8203;16104](https://redirect.github.com/fastapi/fastapi/pull/16104) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ### [`v0.141.0`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.141.0) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.13...0.141.0) ##### Features - ✨ Add `app.frontend(check_dir="auto")`, to make local development more convenient with `fastapi dev`. PR [#&#8203;16102](https://redirect.github.com/fastapi/fastapi/pull/16102) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ### [`v0.140.13`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.13) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.12...0.140.13) ##### Fixes - 🐛 Fix `status_code` being ignored for SSE and JSONL streaming endpoints. PR [#&#8203;15937](https://redirect.github.com/fastapi/fastapi/pull/15937) by [@&#8203;SAURABHSALVE](https://redirect.github.com/SAURABHSALVE). ##### Docs - 📝 Fix `format_sse_event` docstring rendering of `\n\n` terminator. PR [#&#8203;15613](https://redirect.github.com/fastapi/fastapi/pull/15613) by [@&#8203;AshNicolus](https://redirect.github.com/AshNicolus). - 📝 Add API reference page for fastapi.sse. PR [#&#8203;15930](https://redirect.github.com/fastapi/fastapi/pull/15930) by [@&#8203;SAURABHSALVE](https://redirect.github.com/SAURABHSALVE). ### [`v0.140.12`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.12) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.11...0.140.12) ##### Fixes - 🐛 Fix line splitting in `format_sse_event` to comply with SSE spec. PR [#&#8203;15515](https://redirect.github.com/fastapi/fastapi/pull/15515) by [@&#8203;Zawwarsami16](https://redirect.github.com/Zawwarsami16). ### [`v0.140.11`](https://redirect.github.com/fastapi/fastapi/compare/0.140.10...0.140.11) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.10...0.140.11) ### [`v0.140.10`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.10) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.9...0.140.10) ##### Fixes - 🐛 Fix handling sequences with nested Annotated types. PR [#&#8203;14874](https://redirect.github.com/fastapi/fastapi/pull/14874) by [@&#8203;YuriiMotov](https://redirect.github.com/YuriiMotov). ##### Internal - 🐛 Accept any base test failure as regression. PR [#&#8203;16092](https://redirect.github.com/fastapi/fastapi/pull/16092) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). - 🐛 Preserve pytest exit code in regression check. PR [#&#8203;16091](https://redirect.github.com/fastapi/fastapi/pull/16091) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). - ✅ Test PR regressions against base code. PR [#&#8203;16090](https://redirect.github.com/fastapi/fastapi/pull/16090) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ### [`v0.140.9`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.9) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.8...0.140.9) ##### Fixes - 🐛 Fix `exclude_defaults` not propagated to dict keys and values in `jsonable_encoder`. PR [#&#8203;16043](https://redirect.github.com/fastapi/fastapi/pull/16043) by [@&#8203;MBGrao](https://redirect.github.com/MBGrao). ##### Internal - ⬆ Bump gitpython from 3.1.50 to 3.1.54. PR [#&#8203;16047](https://redirect.github.com/fastapi/fastapi/pull/16047) by [@&#8203;dependabot\[bot\]](https://redirect.github.com/apps/dependabot). - ⬆ Bump pymdown-extensions from 10.21.3 to 11.0. PR [#&#8203;16048](https://redirect.github.com/fastapi/fastapi/pull/16048) by [@&#8203;dependabot\[bot\]](https://redirect.github.com/apps/dependabot). - ⬆ Bump pyasn1 from 0.6.3 to 0.6.4. PR [#&#8203;16045](https://redirect.github.com/fastapi/fastapi/pull/16045) by [@&#8203;dependabot\[bot\]](https://redirect.github.com/apps/dependabot). ### [`v0.140.8`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.8) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.7...0.140.8) ##### Fixes - 🐛 Fix stream item type lost when using `include_router()`. PR [#&#8203;15077](https://redirect.github.com/fastapi/fastapi/pull/15077) by [@&#8203;alex-raw](https://redirect.github.com/alex-raw). ### [`v0.140.7`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.7) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.6...0.140.7) ##### Refactors - ⚡️ Avoid flattening dependencies for OpenAPI. PR [#&#8203;16076](https://redirect.github.com/fastapi/fastapi/pull/16076) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ##### Internal - ⬆️ Upgrade latest-changes to 0.7.1. PR [#&#8203;16077](https://redirect.github.com/fastapi/fastapi/pull/16077) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). - 👷 Add OpenAPI dependency benchmarks. PR [#&#8203;16075](https://redirect.github.com/fastapi/fastapi/pull/16075) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ### [`v0.140.6`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.6) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.5...0.140.6) ##### Refactors - ⚡️ Avoid flattening dependencies for request parameters, mainly for OpenAPI. PR [#&#8203;16073](https://redirect.github.com/fastapi/fastapi/pull/16073) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ### [`v0.140.5`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.5) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.4...0.140.5) ##### Refactors - ⚡️ Avoid flattening dependencies for body fields. PR [#&#8203;16071](https://redirect.github.com/fastapi/fastapi/pull/16071) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ### [`v0.140.4`](https://redirect.github.com/fastapi/fastapi/compare/0.140.3...0.140.4) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.3...0.140.4) ### [`v0.140.3`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.3) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.2...0.140.3) ##### Refactors - ⚡️ Avoid repeated dependency flattening in OpenAPI. PR [#&#8203;16067](https://redirect.github.com/fastapi/fastapi/pull/16067) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ### [`v0.140.2`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.2) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.1...0.140.2) ##### Refactors - ⚡️ Stop retaining flat dependency trees. PR [#&#8203;16065](https://redirect.github.com/fastapi/fastapi/pull/16065) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ##### Internal - 👷 Add new memory benchmark. PR [#&#8203;16064](https://redirect.github.com/fastapi/fastapi/pull/16064) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ### [`v0.140.1`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.1) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.140.0...0.140.1) ##### Refactors - ♻️ Update the lru\_cache limit for dependencies to account for large apps. PR [#&#8203;16062](https://redirect.github.com/fastapi/fastapi/pull/16062) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ### [`v0.140.0`](https://redirect.github.com/fastapi/fastapi/releases/tag/0.140.0) [Compare Source](https://redirect.github.com/fastapi/fastapi/compare/0.139.2...0.140.0) ##### Refactors - ⚡️ Reduce memory usage in dependencies. PR [#&#8203;16049](https://redirect.github.com/fastapi/fastapi/pull/16049) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ##### Docs - 📝 Fix links in docs. PR [#&#8203;15967](https://redirect.github.com/fastapi/fastapi/pull/15967) by [@&#8203;YuriiMotov](https://redirect.github.com/YuriiMotov). - 📝 Add Library Skills documentation. PR [#&#8203;16041](https://redirect.github.com/fastapi/fastapi/pull/16041) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). - 📝 Update docs to use uv projects by default. PR [#&#8203;16032](https://redirect.github.com/fastapi/fastapi/pull/16032) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). - 📝 Restructure FastAPI People and related pages. PR [#&#8203;16015](https://redirect.github.com/fastapi/fastapi/pull/16015) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). ##### Internal - 👷 Add CI memory benchmark. PR [#&#8203;16046](https://redirect.github.com/fastapi/fastapi/pull/16046) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). - 👥 Update FastAPI People - Sponsors. PR [#&#8203;16027](https://redirect.github.com/fastapi/fastapi/pull/16027) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). - 🔥 Remove now-obsolete scripts to generate data for FastAPI People. PR [#&#8203;16016](https://redirect.github.com/fastapi/fastapi/pull/16016) by [@&#8203;tiangolo](https://redirect.github.com/tiangolo). </details> <details> <summary>lxml/lxml (lxml)</summary> ### [`v6.1.3`](https://redirect.github.com/lxml/lxml/compare/lxml-6.1.2...lxml-6.1.3) [Compare Source](https://redirect.github.com/lxml/lxml/compare/lxml-6.1.2...lxml-6.1.3) ### [`v6.1.2`](https://redirect.github.com/lxml/lxml/blob/HEAD/CHANGES.txt#612-2026-08-18) [Compare Source](https://redirect.github.com/lxml/lxml/compare/lxml-6.1.1...lxml-6.1.2) \================== - [GH#526](https://redirect.github.com/GH/lxml/issues/526): Some build files were missing in the sdist. Patch by Nicola Soranzo. - Some minor corrections for error handling cases. ## Other changes - Built with Cython 3.2.9. </details> <details> <summary>ijl/orjson (orjson)</summary> ### [`v3.12.0`](https://redirect.github.com/ijl/orjson/blob/HEAD/CHANGELOG.md#3120---2026-08-14) [Compare Source](https://redirect.github.com/ijl/orjson/compare/3.11.9...3.12.0) ##### Changed - Serialization implementation substantially rewritten. - Publish PyPI wheels for Python 3.15. For Python 3.15 and later, `manylinux_2_39` (2024) is targeted instead of `manylinux_2_17` (2012). - No longer publish PyPI wheels for ppc64le and s390x. </details> <details> <summary>pydantic/pydantic (pydantic)</summary> ### [`v2.13.5`](https://redirect.github.com/pydantic/pydantic/compare/v2.13.4...v2.13.5) [Compare Source](https://redirect.github.com/pydantic/pydantic/compare/v2.13.4...v2.13.5) </details> <details> <summary>pydantic/pydantic-settings (pydantic-settings)</summary> ### [`v2.15.0`](https://redirect.github.com/pydantic/pydantic-settings/releases/tag/v2.15.0) [Compare Source](https://redirect.github.com/pydantic/pydantic-settings/compare/v2.14.2...v2.15.0) #### What's Changed - Update documentation link for Pydantic settings by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;863](https://redirect.github.com/pydantic/pydantic-settings/pull/863) - Bump the python-packages group with 4 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;865](https://redirect.github.com/pydantic/pydantic-settings/pull/865) - docs: clarify environment variable helper descriptions by [@&#8203;vip892766gma](https://redirect.github.com/vip892766gma) in [#&#8203;867](https://redirect.github.com/pydantic/pydantic-settings/pull/867) - Bump the python-packages group with 4 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;870](https://redirect.github.com/pydantic/pydantic-settings/pull/870) - Bump the python-packages group with 4 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;875](https://redirect.github.com/pydantic/pydantic-settings/pull/875) - Skip list\_secrets call when case\_sensitive=True by [@&#8203;ecerulm](https://redirect.github.com/ecerulm) in [#&#8203;862](https://redirect.github.com/pydantic/pydantic-settings/pull/862) - GoogleSecretManagerSettingsSource: read project\_id from previous sources by [@&#8203;ecerulm](https://redirect.github.com/ecerulm) in [#&#8203;878](https://redirect.github.com/pydantic/pydantic-settings/pull/878) - Bump the python-packages group with 3 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;883](https://redirect.github.com/pydantic/pydantic-settings/pull/883) - fix: move SecretsManagerClient type import under TYPE\_CHECKING by [@&#8203;gavin913-lss](https://redirect.github.com/gavin913-lss) in [#&#8203;880](https://redirect.github.com/pydantic/pydantic-settings/pull/880) - Skip partial update merging for discriminated union fields by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;876](https://redirect.github.com/pydantic/pydantic-settings/pull/876) - Support using a table header as root when reading a TOML file by [@&#8203;whyscream](https://redirect.github.com/whyscream) in [#&#8203;882](https://redirect.github.com/pydantic/pydantic-settings/pull/882) - Bump the python-packages group with 4 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;885](https://redirect.github.com/pydantic/pydantic-settings/pull/885) - Don't complain about missing table headers in a TOML file that isn't there by [@&#8203;whyscream](https://redirect.github.com/whyscream) in [#&#8203;886](https://redirect.github.com/pydantic/pydantic-settings/pull/886) - Address issues in toml table header implementation by [@&#8203;whyscream](https://redirect.github.com/whyscream) in [#&#8203;887](https://redirect.github.com/pydantic/pydantic-settings/pull/887) - Bump the python-packages group with 2 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;888](https://redirect.github.com/pydantic/pydantic-settings/pull/888) - Prevent NestedSecretsSettingsSource from following symlinks outside secrets\_dir by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;889](https://redirect.github.com/pydantic/pydantic-settings/pull/889) - Add 'Part of the Pydantic Stack' footer to README by [@&#8203;strawgate](https://redirect.github.com/strawgate) in [#&#8203;891](https://redirect.github.com/pydantic/pydantic-settings/pull/891) - Bump the python-packages group with 3 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;893](https://redirect.github.com/pydantic/pydantic-settings/pull/893) - Add support for showing environment variable names in CLI help text by [@&#8203;brad-alexander](https://redirect.github.com/brad-alexander) in [#&#8203;860](https://redirect.github.com/pydantic/pydantic-settings/pull/860) - Fix loading env vars on Windows with case\_sensitive=True by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;894](https://redirect.github.com/pydantic/pydantic-settings/pull/894) - Bump the github-actions group with 3 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;896](https://redirect.github.com/pydantic/pydantic-settings/pull/896) - Bump the python-packages group with 3 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;897](https://redirect.github.com/pydantic/pydantic-settings/pull/897) - Add explicit callout for the case where the unprefixed value is in dotenv by [@&#8203;martinky24](https://redirect.github.com/martinky24) in [#&#8203;895](https://redirect.github.com/pydantic/pydantic-settings/pull/895) - Fix AliasPath on nested model fields not decoding env values ([#&#8203;670](https://redirect.github.com/pydantic/pydantic-settings/issues/670)) by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;898](https://redirect.github.com/pydantic/pydantic-settings/pull/898) - Support case\_sensitive in InitSettingsSource and config file sources by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;900](https://redirect.github.com/pydantic/pydantic-settings/pull/900) - Warn when using fields not fully resolved at instantiation by [@&#8203;Viicos](https://redirect.github.com/Viicos) in [#&#8203;901](https://redirect.github.com/pydantic/pydantic-settings/pull/901) - Support Traversable for json/toml/yaml config file sources ([#&#8203;299](https://redirect.github.com/pydantic/pydantic-settings/issues/299)) by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;902](https://redirect.github.com/pydantic/pydantic-settings/pull/902) - docs: fix typos in docs and source comments by [@&#8203;maxtaran2010](https://redirect.github.com/maxtaran2010) in [#&#8203;904](https://redirect.github.com/pydantic/pydantic-settings/pull/904) - Apply case-insensitive field matching to optional nested models ([#&#8203;903](https://redirect.github.com/pydantic/pydantic-settings/issues/903)) by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;905](https://redirect.github.com/pydantic/pydantic-settings/pull/905) - Bump boto3 from 1.43.36 to 1.43.40 in the python-packages group by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;907](https://redirect.github.com/pydantic/pydantic-settings/pull/907) - Add PYDANTIC\_SETTINGS\_DEBUG for debugging settings sources ([#&#8203;538](https://redirect.github.com/pydantic/pydantic-settings/issues/538)) by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;906](https://redirect.github.com/pydantic/pydantic-settings/pull/906) - docs: recommend async settings loading pattern by [@&#8203;w3lld1](https://redirect.github.com/w3lld1) in [#&#8203;908](https://redirect.github.com/pydantic/pydantic-settings/pull/908) - fix: parse enum names through nested annotations by [@&#8203;Sanjays2402](https://redirect.github.com/Sanjays2402) in [#&#8203;910](https://redirect.github.com/pydantic/pydantic-settings/pull/910) - Fix dotenv extras being claimed by complex fields sharing a name prefix by [@&#8203;ritsth](https://redirect.github.com/ritsth) in [#&#8203;912](https://redirect.github.com/pydantic/pydantic-settings/pull/912) - Add debug logging for env\_file and secret file resolution by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;913](https://redirect.github.com/pydantic/pydantic-settings/pull/913) - docs: document JSON parsing of complex env values + comma-separated recipe by [@&#8203;hrithvikakb](https://redirect.github.com/hrithvikakb) in [#&#8203;919](https://redirect.github.com/pydantic/pydantic-settings/pull/919) - fix: coerce empty yaml\_config\_section to an empty mapping instead of crashing by [@&#8203;chuenchen309](https://redirect.github.com/chuenchen309) in [#&#8203;914](https://redirect.github.com/pydantic/pydantic-settings/pull/914) - Bump the python-packages group with 3 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;915](https://redirect.github.com/pydantic/pydantic-settings/pull/915) - fix: read secret files as UTF-8 instead of the locale encoding by [@&#8203;dchaudhari7177](https://redirect.github.com/dchaudhari7177) in [#&#8203;917](https://redirect.github.com/pydantic/pydantic-settings/pull/917) - Bump the python-packages group with 4 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;921](https://redirect.github.com/pydantic/pydantic-settings/pull/921) - Bump the github-actions group with 4 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;925](https://redirect.github.com/pydantic/pydantic-settings/pull/925) - Bump the python-packages group with 4 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;924](https://redirect.github.com/pydantic/pydantic-settings/pull/924) - fix: treat Secret subclasses as non-complex fields ([#&#8203;716](https://redirect.github.com/pydantic/pydantic-settings/issues/716)) by [@&#8203;Rony-ZenAlden](https://redirect.github.com/Rony-ZenAlden) in [#&#8203;920](https://redirect.github.com/pydantic/pydantic-settings/pull/920) - fix: raise ValidationError for non-JSON env values on strict fields by [@&#8203;shuvamk](https://redirect.github.com/shuvamk) in [#&#8203;926](https://redirect.github.com/pydantic/pydantic-settings/pull/926) - test: move function-local imports to the top of test modules by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;927](https://redirect.github.com/pydantic/pydantic-settings/pull/927) - Bump the python-packages group with 4 updates by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in [#&#8203;929](https://redirect.github.com/pydantic/pydantic-settings/pull/929) - Prepare release 2.15.0 by [@&#8203;hramezani](https://redirect.github.com/hramezani) in [#&#8203;930](https://redirect.github.com/pydantic/pydantic-settings/pull/930) #### New Contributors - [@&#8203;vip892766gma](https://redirect.github.com/vip892766gma) made their first contribution in [#&#8203;867](https://redirect.github.com/pydantic/pydantic-settings/pull/867) - [@&#8203;ecerulm](https://redirect.github.com/ecerulm) made their first contribution in [#&#8203;862](https://redirect.github.com/pydantic/pydantic-settings/pull/862) - [@&#8203;gavin913-lss](https://redirect.github.com/gavin913-lss) made their first contribution in [#&#8203;880](https://redirect.github.com/pydantic/pydantic-settings/pull/880) - [@&#8203;whyscream](https://redirect.github.com/whyscream) made their first contribution in [#&#8203;882](https://redirect.github.com/pydantic/pydantic-settings/pull/882) - [@&#8203;strawgate](https://redirect.github.com/strawgate) made their first contribution in [#&#8203;891](https://redirect.github.com/pydantic/pydantic-settings/pull/891) - [@&#8203;brad-alexander](https://redirect.github.com/brad-alexander) made their first contribution in [#&#8203;860](https://redirect.github.com/pydantic/pydantic-settings/pull/860) - [@&#8203;martinky24](https://redirect.github.com/martinky24) made their first contribution in [#&#8203;895](https://redirect.github.com/pydantic/pydantic-settings/pull/895) - [@&#8203;maxtaran2010](https://redirect.github.com/maxtaran2010) made their first contribution in [#&#8203;904](https://redirect.github.com/pydantic/pydantic-settings/pull/904) - [@&#8203;w3lld1](https://redirect.github.com/w3lld1) made their first contribution in [#&#8203;908](https://redirect.github.com/pydantic/pydantic-settings/pull/908) - [@&#8203;Sanjays2402](https://redirect.github.com/Sanjays2402) made their first contribution in [#&#8203;910](https://redirect.github.com/pydantic/pydantic-settings/pull/910) - [@&#8203;ritsth](https://redirect.github.com/ritsth) made their first contribution in [#&#8203;912](https://redirect.github.com/pydantic/pydantic-settings/pull/912) - [@&#8203;hrithvikakb](https://redirect.github.com/hrithvikakb) made their first contribution in [#&#8203;919](https://redirect.github.com/pydantic/pydantic-settings/pull/919) - [@&#8203;chuenchen309](https://redirect.github.com/chuenchen309) made their first contribution in [#&#8203;914](https://redirect.github.com/pydantic/pydantic-settings/pull/914) - [@&#8203;dchaudhari7177](https://redirect.github.com/dchaudhari7177) made their first contribution in [#&#8203;917](https://redirect.github.com/pydantic/pydantic-settings/pull/917) - [@&#8203;Rony-ZenAlden](https://redirect.github.com/Rony-ZenAlden) made their first contribution in [#&#8203;920](https://redirect.github.com/pydantic/pydantic-settings/pull/920) - [@&#8203;shuvamk](https://redirect.github.com/shuvamk) made their first contribution in [#&#8203;926](https://redirect.github.com/pydantic/pydantic-settings/pull/926) **Full Changelog**: <https://github.com/pydantic/pydantic-settings/compare/v2.14.1...v2.15.0> </details> <details> <summary>pypa/gh-action-pypi-publish (pypa/gh-action-pypi-publish)</summary> ### [`v1.14.2`](https://redirect.github.com/pypa/gh-action-pypi-publish/releases/tag/v1.14.2) [Compare Source](https://redirect.github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2) <p align="right"><i>This one probably won't touch you visibly so just bookmark <a href="https://ep2026.europython.eu/session/defending-open-source-from-ai-slop-a-maintainer-s-practical-guide">@webknjaz's EuroPython 2026 “AI” slop rant for when it's published on YouTube</a> or <a href="https://redirect.github.com/sponsors/webknjaz">encourage him to come back with more to share next year</a>!</i></p> #### 🛠️ Urgh… Another release!? Again? Explain yourself! Looking at the diff, you'll only witness updates across the dependency tree. That's it! It's not a security fix or anything like that even, no. But you'll want this update. > \[!tip] > So what *most* people will find useful is [@&#8203;takluyver](https://redirect.github.com/takluyver)[💰](https://redirect.github.com/sponsors/takluyver)'s update of Twine to v7 that we use internally ([#&#8203;416](https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416)). This version will let them upload their sdists and wheels containing core packaging metadata v2.5 to (Test)PyPI. #### 🧐 Tell me why.. <details> <summary> The rest of the updates bump things related to <code>pypi-attestations</code> and <code>sigstore</code>, which has the most interesting backstory here. @&#8203;facutuesca<a href="https://redirect.github.com/sponsors/facutuesca">💰</a> sent a patch in #&#8203;417 but a bunch more helped out. </summary> TL;DR non-pure-python projects with C-extensions tend to have dozens (sometimes hundreds) wheels to upload to PyPI per release. They are often quite big and take time to transfer over the network. People started noticing problems and coming up with DIY sharding workarounds like [aio-libs/aiohttp#13226](https://redirect.github.com/aio-libs/aiohttp/pull/13226) around July 23. On this date, projects with a good amount of bytes to publish would start getting timeouts 5 minutes after the PyPI publishing job begun. The same job that worked just fine before. I had to start pinging upstream library and ecosystem people, on GitHub and privately, to start making sense of what was happening. Eventually, we collectively concluded that GitHub must've shortened the lifetime of their OIDC identity — it seems to have used to be 10 minutes long (at some point in the past) and is now 5 minutes, apparently. It's not documented clearly, and we have not been able to get any clarity by attempting to contact GitHub through private channels, using personal connections. Over the course of investigation, [@&#8203;facutuesca](https://redirect.github.com/facutuesca)[💰](https://redirect.github.com/sponsors/facutuesca) found and fixed a related underlying cache invalidation bug in [sigstore/sigstore-python#1838](https://redirect.github.com/sigstore/sigstore-python/pull/1838), which he then coordinated propagation through the dependency chain updates in sigstore-python, pypi-attestations, gh-action-pypi-publish and gh-action-sigstore-python. Mike's also discovered that Sigstore's Rekor slowdown seems to have become the main contributing cause of the last week's incident. He's collected some data to support this claim: <https://publishing-five-minute-timeout.tiiny.site>. <center> <a href="https://xkcd.com/2549/"> <img src="https://imgs.xkcd.com/comics/edge_cake_2x.png" alt="Edge Cake XKCD feels just like this release"> </a> </center> </details> #### 🫶 New Contributors - [@&#8203;davidbrochart](https://redirect.github.com/davidbrochart) made their first contribution in [#&#8203;415](https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415) - [@&#8203;takluyver](https://redirect.github.com/takluyver) made their first contribution in [#&#8203;416](https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416) **🪞 Full Diff**: <https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2> **🧔‍♂️ Release Manager:** [@&#8203;webknjaz](https://redirect.github.com/sponsors/webknjaz) [🇺🇦](https://stand-with-ukraine.pp.ua) **🙏 Special Thanks** to [@&#8203;davidbrochart](https://redirect.github.com/davidbrochart)[💰](https://redirect.github.com/sponsors/davidbrochart) and [@&#8203;Dreamsorcerer](https://redirect.github.com/Dreamsorcerer)[💰](https://redirect.github.com/sponsors/Dreamsorcerer) for turning my attention (in [#&#8203;415](https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415) and in private) to the newly surfaced corner case in GitHub's behavior that only affected a narrow category of projects while many others remained blissfully unaware. [@&#8203;bdraco](https://redirect.github.com/bdraco)[💰](https://redirect.github.com/sponsors/bdraco) came up with a DIY sharding workaround for aiohttp that served as a demo for other projects. [@&#8203;miketheman](https://redirect.github.com/miketheman)[💰](https://redirect.github.com/sponsors/miketheman) confirmed the Warehouse-side details. Also, [@&#8203;jku](https://redirect.github.com/jku)[💰](https://redirect.github.com/sponsors/jku) and [@&#8203;woodruffw](https://redirect.github.com/woodruffw)[💰](https://redirect.github.com/sponsors/woodruffw) helped work through, review and release the Sigstore ecosystem upstream libs. **💬 Discuss** [on Bluesky 🦋](https://bsky.app/profile/did:plc:ve6s3mxkefjaxty3m4fdqumn/post/3mrsqy2xba22j), [on Mastodon 🐘](https://mastodon.social/@webknjaz/117005132816750073) and [on GitHub][release discussion]. [![GH Sponsors badge]][GH Sponsors URL] [GH Sponsors badge]: https://img.shields.io/badge/%40webknjaz-transparent?logo=githubsponsors&logoColor=%23EA4AAA&label=Sponsor&color=2a313c [GH Sponsors URL]: https://redirect.github.com/sponsors/webknjaz [release discussion]: https://redirect.github.com/pypa/gh-action-pypi-publish/discussions/419 ### [`v1.14.1`](https://redirect.github.com/pypa/gh-action-pypi-publish/releases/tag/v1.14.1) [Compare Source](https://redirect.github.com/pypa/gh-action-pypi-publish/compare/v1.14.0...v1.14.1) <p align="right"><i>This release was cut at <a href="https://ep2026.europython.eu/sprints/">EuroPython 2026 Sprints</a></i></p> #### 🛠️ Internal Dependencies [@&#8203;adisivaprasad](https://redirect.github.com/adisivaprasad)[💰](https://redirect.github.com/sponsors/adisivaprasad) helped get rid of the GitHub Actions runner warning about the old Node 20 runtime being used by updating `actions/setup-python` from v5.6.0 to v6.2.0 in [#&#8203;408](https://redirect.github.com/pypa/gh-action-pypi-publish/issues/408). #### 💪 New Contributors - [@&#8203;adisivaprasad](https://redirect.github.com/adisivaprasad) made their first contribution in [#&#8203;408](https://redirect.github.com/pypa/gh-action-pypi-publish/issues/408) - [@&#8203;jylenhof](https://redirect.github.com/jylenhof)[💰](https://redirect.github.com/sponsors/jylenhof) followed up and reminded us to actually cut this release in [#&#8203;413](https://redirect.github.com/pypa/gh-action-pypi-publish/issues/413) **🪞 Full Diff**: <https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.0...v1.14.1> **🧔‍♂️ Release Manager:** [@&#8203;webknjaz](https://redirect.github.com/sponsors/webknjaz) [🇺🇦](https://stand-with-ukraine.pp.ua) **🙏 Special Thanks** to [@&#8203;jylenhof](https://redirect.github.com/jylenhof)[💰](https://redirect.github.com/sponsors/jylenhof) for reminding me to work on this release! **💬 Discuss** [on Bluesky 🦋](https://bsky.app/profile/did:plc:ve6s3mxkefjaxty3m4fdqumn/post/3mrd7jpnxc22d), [on Mastodon 🐘](https://mastodon.social/@webknjaz/116970132515797444) and [on GitHub][release discussion]. [![GH Sponsors badge]][GH Sponsors URL] [GH Sponsors badge]: https://img.shields.io/badge/%40webknjaz-transparent?logo=githubsponsors&logoColor=%23EA4AAA&label=Sponsor&color=2a313c [GH Sponsors URL]: https://redirect.github.com/sponsors/webknjaz [release discussion]: https://redirect.github.com/pypa/gh-action-pypi-publish/discussions/414 </details> <details> <summary>Kludex/uvicorn (uvicorn)</summary> ### [`v0.52.4`](https://redirect.github.com/Kludex/uvicorn/releases/tag/0.52.4): Version 0.52.4 [Compare Source](https://redirect.github.com/Kludex/uvicorn/compare/0.52.3...0.52.4) ##### Fixed - Remove duplicate `Date` headers from accepted WebSocket handshakes with `websockets-sansio` ([#&#8203;3078](https://redirect.github.com/Kludex/uvicorn/pull/3078)) **Full Changelog**: <https://github.com/Kludex/uvicorn/compare/0.52.3...0.52.4> ### [`v0.52.3`](https://redirect.github.com/Kludex/uvicorn/releases/tag/0.52.3): Version 0.52.3 [Compare Source](https://redirect.github.com/Kludex/uvicorn/compare/0.52.2...0.52.3) ##### Changed - Update `zttp` to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance ([#&#8203;3067](https://redirect.github.com/Kludex/uvicorn/issues/3067)) **Full Changelog**: <https://github.com/Kludex/uvicorn/compare/0.52.2...0.52.3> ### [`v0.52.2`](https://redirect.github.com/Kludex/uvicorn/releases/tag/0.52.2): Version 0.52.2 [Compare Source](https://redirect.github.com/Kludex/uvicorn/compare/0.52.1...0.52.2) ##### Fixed - Update `zttp` to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance ([#&#8203;3063](https://redirect.github.com/Kludex/uvicorn/issues/3063)) **Full Changelog**: <https://github.com/Kludex/uvicorn/compare/0.52.1...0.52.2> ### [`v0.52.1`](https://redirect.github.com/Kludex/uvicorn/releases/tag/0.52.1): Version 0.52.1 [Compare Source](https://redirect.github.com/Kludex/uvicorn/compare/0.52.0...0.52.1) ##### Fixed - Complete the closing handshake on server-initiated WebSocket closes in the `websockets-sansio` and `wsproto` implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection ([#&#8203;3053](https://redirect.github.com/Kludex/uvicorn/issues/3053)) - Add missing write flow control to the `websockets-sansio` implementation, preventing data truncation on server-initiated closes with large in-flight payloads ([#&#8203;3048](https://redirect.github.com/Kludex/uvicorn/issues/3048)) - Handle connection loss while a WebSocket write is waiting on backpressure ([#&#8203;3050](https://redirect.github.com/Kludex/uvicorn/issues/3050)) - Remove duplicate `Content-Type` and `Content-Length` headers from WebSocket denial responses on the `websockets-sansio` implementation, and deliver non-UTF-8 denial bodies intact ([#&#8203;3041](https://redirect.github.com/Kludex/uvicorn/issues/3041)) **Full Changelog**: <https://github.com/Kludex/uvicorn/compare/0.52.0...0.52.1> ### [`v0.52.0`](https://redirect.github.com/Kludex/uvicorn/releases/tag/0.52.0): Version 0.52.0 [Compare Source](https://redirect.github.com/Kludex/uvicorn/compare/0.51.0...0.52.0) This release adds an experimental HTTP/1.1 implementation backed by [zttp](https://zttp.marcelotryle.com/), a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing. It is still **experimental**, so don't put it in front of production traffic yet. Try it with `--http zttp`, and please send any feedback to the [issue tracker](https://redirect.github.com/Kludex/uvicorn/issues). ##### Added - Add an experimental `zttp` HTTP/1.1 implementation, selectable with `--http zttp` ([#&#8203;2979](https://redirect.github.com/Kludex/uvicorn/issues/2979)) ##### Fixed - Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 ([#&#8203;3036](https://redirect.github.com/Kludex/uvicorn/issues/3036)) **Full Changelog**: <https://github.com/Kludex/uvicorn/compare/0.51.0...0.52.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/sarumaj/local-flight-map). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjU3LjMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->
Sign in to join this conversation.
No description provided.