Commit Graph
16533 Commits
Author SHA1 Message Date
Nishitha Mandopen-swe[bot] 0854c51ac1 fix(langchain,anthropic): fix batch of near-trivial bugs
Closes #34274
Closes #38718
Closes #36409
Closes #35852
Closes #38465

- LLMToolEmulator: remove redundant double-check when building
  tools_to_emulate, and make model a required keyword argument instead
  of silently defaulting to an Anthropic model that required
  langchain-anthropic to be installed.
- Re-export PIIMatch from langchain.agents.middleware so custom PII
  detector authors don't need the private _redaction module.
- Add a state_schema parameter to wrap_tool_call, matching the other
  middleware decorators.
- Fix the Claude file-tool dispatch in langchain-anthropic to populate
  old_path alongside path, fixing a KeyError on every rename command.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-08-05 23:16:11 +00:00
Nishitha MandDevbyteai 89cc9c5cbb feat(langchain): filter internal middleware model calls from messages projection (#39252)
Closes  #34139 #34382

`SummarizationMiddleware`, `LLMToolEmulator`, and
`LLMToolSelectorMiddleware` make internal model calls for bookkeeping,
but these were indistinguishable from the agent's main model call in the
event stream.

This PR tags internal calls in config metadata and adds an
`InternalCallTransformer` that filters them from `run.messages` and the
raw event log.

Note: If a user wants to stream the internal LLM calls, needs to build a
custom transformer around it

---------

Co-authored-by: Devbyteai <abud6673@gmail.com>
2026-08-05 17:24:15 -04:00
John Kennedy 3e871a148d fix(langchain): sanitize evaluation Git remote tags (#39254)
Evaluation runs currently copy Git remote URLs into every run tag
unchanged, which can fan out credentials embedded in HTTPS or SSH
remotes.

This change strips URL userinfo while preserving repository host/path
identity for HTTPS, SSH, Git, and scp-style remotes. Malformed,
ambiguous, query-bearing, and control-character-bearing values fail
closed and are omitted. Other Git correlation tags remain unchanged.
Sync and async evaluation flows are covered.

## Release note

LangChain evaluation runs now remove credentials from Git remote URL
tags while preserving credential-free repository identity.

This contribution was implemented with AI-agent assistance.
2026-08-05 13:20:25 -07:00
dependabot[bot] 759c5e348a chore: bump langsmith from 0.10.6 to 0.10.16 in /libs/partners/chroma (#39280)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from
0.10.6 to 0.10.16.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's
releases</a>.</em></p>
<blockquote>
<h2>v0.10.16</h2>
<h2>What's Changed</h2>
<ul>
<li>release(js): 0.8.9 by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3316">langchain-ai/langsmith-sdk#3316</a></li>
<li>fix(python): mask metadata after the runtime env merge and via the
anonymizer by <a
href="https://github.com/vladislav-nechakhin"><code>@​vladislav-nechakhin</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3313">langchain-ai/langsmith-sdk#3313</a></li>
<li>fix(js): mask metadata after the runtime env merge and via the
anonymizer by <a
href="https://github.com/vladislav-nechakhin"><code>@​vladislav-nechakhin</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3314">langchain-ai/langsmith-sdk#3314</a></li>
<li>chore(deps-dev): bump types-requests from 2.33.0.20260518 to
2.33.0.20260712 in /python by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3325">langchain-ai/langsmith-sdk#3325</a></li>
<li>chore(deps-dev): bump types-pyyaml from 6.0.12.20260518 to
6.0.12.20260724 in /python by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3324">langchain-ai/langsmith-sdk#3324</a></li>
<li>chore(deps): bump the actions-major group with 2 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3321">langchain-ai/langsmith-sdk#3321</a></li>
<li>chore(deps): bump the actions-minor-and-patch group across 1
directory with 3 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3320">langchain-ai/langsmith-sdk#3320</a></li>
<li>chore(deps): bump the npm_and_yarn group across 3 directories with 3
updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3330">langchain-ai/langsmith-sdk#3330</a></li>
<li>fix(js,py): stamp ls_agent_type on wrap_openai LLM runs by <a
href="https://github.com/ybathula707"><code>@​ybathula707</code></a> in
<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3317">langchain-ai/langsmith-sdk#3317</a></li>
<li>chore(deps): bump aiohttp from 3.14.1 to 3.14.3 in /python by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3329">langchain-ai/langsmith-sdk#3329</a></li>
<li>chore(deps-dev): bump the py-major group in /python with 2 updates
by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3323">langchain-ai/langsmith-sdk#3323</a></li>
<li>chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /python by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3331">langchain-ai/langsmith-sdk#3331</a></li>
<li>fix(js,py): preserve user-supplied ls_agent_type in
openai-agents-sdk integration by <a
href="https://github.com/ybathula707"><code>@​ybathula707</code></a> in
<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3318">langchain-ai/langsmith-sdk#3318</a></li>
<li>fix(js): inherit parent's ls_agent_type in Vercel _getLsAgentType
helper by <a
href="https://github.com/ybathula707"><code>@​ybathula707</code></a> in
<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3319">langchain-ai/langsmith-sdk#3319</a></li>
<li>chore(deps): bump the py-minor-and-patch group across 1 directory
with 25 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3322">langchain-ai/langsmith-sdk#3322</a></li>
<li>fix(profiles): resolve the OAuth token endpoint from deployment
metadata by <a
href="https://github.com/langchain-infra"><code>@​langchain-infra</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3333">langchain-ai/langsmith-sdk#3333</a></li>
<li>fix: avoid resetting compression threads by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3332">langchain-ai/langsmith-sdk#3332</a></li>
<li>docs(sandbox): fix invalid sizing example in JS sandbox README by <a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3335">langchain-ai/langsmith-sdk#3335</a></li>
<li>test(claude-agent-sdk): run subagent in foreground so trace nests
correctly by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3339">langchain-ai/langsmith-sdk#3339</a></li>
<li>release(py): 0.10.16 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3337">langchain-ai/langsmith-sdk#3337</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/vladislav-nechakhin"><code>@​vladislav-nechakhin</code></a>
made their first contribution in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3313">langchain-ai/langsmith-sdk#3313</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.15...v0.10.16">https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.15...v0.10.16</a></p>
<h2>v0.10.15</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(python): apply the caller-supplied session's config to v2
endpoints by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3304">langchain-ai/langsmith-sdk#3304</a></li>
<li>chore: Use a common function for backend detection by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3307">langchain-ai/langsmith-sdk#3307</a></li>
<li>fix: prioritize API key over OAuth profile auth [closes LSDK-414] by
<a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3295">langchain-ai/langsmith-sdk#3295</a></li>
<li>fix(js): apply caller-supplied headers to the v2 endpoints by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3305">langchain-ai/langsmith-sdk#3305</a></li>
<li>chore: deprecate legacy SmithDB-migration SDK methods by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3299">langchain-ai/langsmith-sdk#3299</a></li>
<li>chore: sync langsmith_api by <a
href="https://github.com/langtions-bot"><code>@​langtions-bot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3310">langchain-ai/langsmith-sdk#3310</a></li>
<li>fix: stop supported APIs from emitting nested deprecation warnings
by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3308">langchain-ai/langsmith-sdk#3308</a></li>
<li>chore: deprecate the run-sharing SDK methods by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3312">langchain-ai/langsmith-sdk#3312</a></li>
<li>release(py): 0.10.15 by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3315">langchain-ai/langsmith-sdk#3315</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.14...v0.10.15">https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.14...v0.10.15</a></p>
<h2>v0.10.14</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(sandbox): count an acknowledged reattachment as progress by <a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3301">langchain-ai/langsmith-sdk#3301</a></li>
<li>feat(python): trace raw Gemini Live sessions by <a
href="https://github.com/carolinedivittorio"><code>@​carolinedivittorio</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3291">langchain-ai/langsmith-sdk#3291</a></li>
<li>release(py): 0.10.14 by <a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3302">langchain-ai/langsmith-sdk#3302</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/3f9fe09d8e0698d65aa8bb63ac3316dfcb2ca947"><code>3f9fe09</code></a>
release(py): 0.10.16 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3337">#3337</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/8c5d807dca1f25673bc95492ed9a04f3a6850a2c"><code>8c5d807</code></a>
test(claude-agent-sdk): run subagent in foreground so trace nests
correctly (...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/b34c68e3a87897f082da436d7f0ccd7d82fd5c9f"><code>b34c68e</code></a>
docs(sandbox): fix invalid sizing example in JS sandbox README (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3335">#3335</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/446c78c7481b2d890db78636101aabe1a51acf90"><code>446c78c</code></a>
fix: avoid resetting compression threads (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3332">#3332</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/cc9291a6852f13bdd732f466d61056e5b8a4d0c5"><code>cc9291a</code></a>
fix(profiles): resolve the OAuth token endpoint from deployment metadata
(<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3333">#3333</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/1e70bf5c526a518916bd477f1c4e785a73a9f7d8"><code>1e70bf5</code></a>
chore(deps): bump the py-minor-and-patch group across 1 directory with
25 upd...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/9b047e3ca79bd9b7dd633c2f0d750154713fbe8b"><code>9b047e3</code></a>
fix(js): inherit parent's ls_agent_type in Vercel _getLsAgentType helper
(<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3319">#3319</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/0a6256d636c1b824650e543c529ed46140322b32"><code>0a6256d</code></a>
fix(js,py): preserve user-supplied ls_agent_type in openai-agents-sdk
integra...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/312a9f545764f0456f5d9e803aaa1e7c4bb8d164"><code>312a9f5</code></a>
chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /python (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3331">#3331</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/2a81489e723df8f65593811171cca2d12d4f49df"><code>2a81489</code></a>
chore(deps-dev): bump the py-major group in /python with 2 updates (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3323">#3323</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.6...v0.10.16">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=langsmith&package-manager=uv&previous-version=0.10.6&new-version=0.10.16)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-05 13:18:07 -07:00
dependabot[bot] 1fb3b1a599 chore: bump langsmith from 0.10.6 to 0.10.16 in /libs/partners/fireworks (#39279)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from
0.10.6 to 0.10.16.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's
releases</a>.</em></p>
<blockquote>
<h2>v0.10.16</h2>
<h2>What's Changed</h2>
<ul>
<li>release(js): 0.8.9 by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3316">langchain-ai/langsmith-sdk#3316</a></li>
<li>fix(python): mask metadata after the runtime env merge and via the
anonymizer by <a
href="https://github.com/vladislav-nechakhin"><code>@​vladislav-nechakhin</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3313">langchain-ai/langsmith-sdk#3313</a></li>
<li>fix(js): mask metadata after the runtime env merge and via the
anonymizer by <a
href="https://github.com/vladislav-nechakhin"><code>@​vladislav-nechakhin</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3314">langchain-ai/langsmith-sdk#3314</a></li>
<li>chore(deps-dev): bump types-requests from 2.33.0.20260518 to
2.33.0.20260712 in /python by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3325">langchain-ai/langsmith-sdk#3325</a></li>
<li>chore(deps-dev): bump types-pyyaml from 6.0.12.20260518 to
6.0.12.20260724 in /python by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3324">langchain-ai/langsmith-sdk#3324</a></li>
<li>chore(deps): bump the actions-major group with 2 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3321">langchain-ai/langsmith-sdk#3321</a></li>
<li>chore(deps): bump the actions-minor-and-patch group across 1
directory with 3 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3320">langchain-ai/langsmith-sdk#3320</a></li>
<li>chore(deps): bump the npm_and_yarn group across 3 directories with 3
updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3330">langchain-ai/langsmith-sdk#3330</a></li>
<li>fix(js,py): stamp ls_agent_type on wrap_openai LLM runs by <a
href="https://github.com/ybathula707"><code>@​ybathula707</code></a> in
<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3317">langchain-ai/langsmith-sdk#3317</a></li>
<li>chore(deps): bump aiohttp from 3.14.1 to 3.14.3 in /python by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3329">langchain-ai/langsmith-sdk#3329</a></li>
<li>chore(deps-dev): bump the py-major group in /python with 2 updates
by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3323">langchain-ai/langsmith-sdk#3323</a></li>
<li>chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /python by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3331">langchain-ai/langsmith-sdk#3331</a></li>
<li>fix(js,py): preserve user-supplied ls_agent_type in
openai-agents-sdk integration by <a
href="https://github.com/ybathula707"><code>@​ybathula707</code></a> in
<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3318">langchain-ai/langsmith-sdk#3318</a></li>
<li>fix(js): inherit parent's ls_agent_type in Vercel _getLsAgentType
helper by <a
href="https://github.com/ybathula707"><code>@​ybathula707</code></a> in
<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3319">langchain-ai/langsmith-sdk#3319</a></li>
<li>chore(deps): bump the py-minor-and-patch group across 1 directory
with 25 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3322">langchain-ai/langsmith-sdk#3322</a></li>
<li>fix(profiles): resolve the OAuth token endpoint from deployment
metadata by <a
href="https://github.com/langchain-infra"><code>@​langchain-infra</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3333">langchain-ai/langsmith-sdk#3333</a></li>
<li>fix: avoid resetting compression threads by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3332">langchain-ai/langsmith-sdk#3332</a></li>
<li>docs(sandbox): fix invalid sizing example in JS sandbox README by <a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3335">langchain-ai/langsmith-sdk#3335</a></li>
<li>test(claude-agent-sdk): run subagent in foreground so trace nests
correctly by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3339">langchain-ai/langsmith-sdk#3339</a></li>
<li>release(py): 0.10.16 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3337">langchain-ai/langsmith-sdk#3337</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/vladislav-nechakhin"><code>@​vladislav-nechakhin</code></a>
made their first contribution in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3313">langchain-ai/langsmith-sdk#3313</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.15...v0.10.16">https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.15...v0.10.16</a></p>
<h2>v0.10.15</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(python): apply the caller-supplied session's config to v2
endpoints by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3304">langchain-ai/langsmith-sdk#3304</a></li>
<li>chore: Use a common function for backend detection by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3307">langchain-ai/langsmith-sdk#3307</a></li>
<li>fix: prioritize API key over OAuth profile auth [closes LSDK-414] by
<a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3295">langchain-ai/langsmith-sdk#3295</a></li>
<li>fix(js): apply caller-supplied headers to the v2 endpoints by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3305">langchain-ai/langsmith-sdk#3305</a></li>
<li>chore: deprecate legacy SmithDB-migration SDK methods by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3299">langchain-ai/langsmith-sdk#3299</a></li>
<li>chore: sync langsmith_api by <a
href="https://github.com/langtions-bot"><code>@​langtions-bot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3310">langchain-ai/langsmith-sdk#3310</a></li>
<li>fix: stop supported APIs from emitting nested deprecation warnings
by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3308">langchain-ai/langsmith-sdk#3308</a></li>
<li>chore: deprecate the run-sharing SDK methods by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3312">langchain-ai/langsmith-sdk#3312</a></li>
<li>release(py): 0.10.15 by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3315">langchain-ai/langsmith-sdk#3315</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.14...v0.10.15">https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.14...v0.10.15</a></p>
<h2>v0.10.14</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(sandbox): count an acknowledged reattachment as progress by <a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3301">langchain-ai/langsmith-sdk#3301</a></li>
<li>feat(python): trace raw Gemini Live sessions by <a
href="https://github.com/carolinedivittorio"><code>@​carolinedivittorio</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3291">langchain-ai/langsmith-sdk#3291</a></li>
<li>release(py): 0.10.14 by <a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3302">langchain-ai/langsmith-sdk#3302</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/3f9fe09d8e0698d65aa8bb63ac3316dfcb2ca947"><code>3f9fe09</code></a>
release(py): 0.10.16 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3337">#3337</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/8c5d807dca1f25673bc95492ed9a04f3a6850a2c"><code>8c5d807</code></a>
test(claude-agent-sdk): run subagent in foreground so trace nests
correctly (...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/b34c68e3a87897f082da436d7f0ccd7d82fd5c9f"><code>b34c68e</code></a>
docs(sandbox): fix invalid sizing example in JS sandbox README (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3335">#3335</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/446c78c7481b2d890db78636101aabe1a51acf90"><code>446c78c</code></a>
fix: avoid resetting compression threads (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3332">#3332</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/cc9291a6852f13bdd732f466d61056e5b8a4d0c5"><code>cc9291a</code></a>
fix(profiles): resolve the OAuth token endpoint from deployment metadata
(<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3333">#3333</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/1e70bf5c526a518916bd477f1c4e785a73a9f7d8"><code>1e70bf5</code></a>
chore(deps): bump the py-minor-and-patch group across 1 directory with
25 upd...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/9b047e3ca79bd9b7dd633c2f0d750154713fbe8b"><code>9b047e3</code></a>
fix(js): inherit parent's ls_agent_type in Vercel _getLsAgentType helper
(<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3319">#3319</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/0a6256d636c1b824650e543c529ed46140322b32"><code>0a6256d</code></a>
fix(js,py): preserve user-supplied ls_agent_type in openai-agents-sdk
integra...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/312a9f545764f0456f5d9e803aaa1e7c4bb8d164"><code>312a9f5</code></a>
chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /python (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3331">#3331</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/2a81489e723df8f65593811171cca2d12d4f49df"><code>2a81489</code></a>
chore(deps-dev): bump the py-major group in /python with 2 updates (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3323">#3323</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.6...v0.10.16">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=langsmith&package-manager=uv&previous-version=0.10.6&new-version=0.10.16)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-05 13:17:50 -07:00
dependabot[bot] 8a78a812ec chore: bump cryptography from 48.0.1 to 50.0.0 in /libs/langchain (#39243)
Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.1
to 50.0.0.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst">cryptography's
changelog</a>.</em></p>
<blockquote>
<p>50.0.0 - 2026-07-31</p>
<pre><code>
* **SECURITY ISSUE**:

:func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
and its PEM and S/MIME variants no longer expose distinguishable errors
or
timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which
could
act as a Bleichenbacher oracle for callers that decrypt untrusted
messages.
A random key is now substituted on failure, as described in :rfc:`3218`.
  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
  Everything FFDH is deprecated, including the types in
``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys
or
  parameters with the key loading APIs. Users should migrate to a more
  modern key exchange algorithm.
* Added ``xof()`` class methods to
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
:class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for
constructing
  algorithm instances configured for use with
  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification &lt;cryptography.x509.verification&gt;`
APIs are now
  considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
  chunked-encryption specification
&lt;https://c2sp.org/chunked-encryption&gt;`_ for streaming
authenticated
  encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
carry trailing bytes after the list or after an individual SCT, instead
of
  silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field
type in
  the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a
non-zero
  number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
``GeneralizedTime`` that carries fractional seconds or another non-DER
form,
matching the strict encoding already required for every other X.509 time
  field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
:func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a
request
or response whose ``version`` field is not ``v1``, the only version
defined
by RFC 6960, matching the version validation already performed when
loading
  certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now
supported
  when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported
when
  building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now
supported
  when building against AWS-LC.
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc"><code>dcb7050</code></a>
Prepare for 50.0.0 release (<a
href="https://redirect.github.com/pyca/cryptography/issues/15372">#15372</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"><code>53fccd9</code></a>
Don't leak how PKCS#7 encryptedKey decryption failed (<a
href="https://redirect.github.com/pyca/cryptography/issues/15369">#15369</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8"><code>d472f97</code></a>
Add <code>from __future__ import annotations</code> to all src/ Python
files (<a
href="https://redirect.github.com/pyca/cryptography/issues/15371">#15371</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a"><code>908773d</code></a>
Bump downstream dependencies in CI (<a
href="https://redirect.github.com/pyca/cryptography/issues/15368">#15368</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812"><code>2cc07cc</code></a>
Bump BoringSSL, OpenSSL, AWS-LC in CI (<a
href="https://redirect.github.com/pyca/cryptography/issues/15367">#15367</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66"><code>c94ede9</code></a>
chore(deps): bump ruff from 0.16.0 to 0.16.1 (<a
href="https://redirect.github.com/pyca/cryptography/issues/15366">#15366</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35"><code>67a8308</code></a>
chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (<a
href="https://redirect.github.com/pyca/cryptography/issues/15365">#15365</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596"><code>95018ff</code></a>
Release the GIL in one-shot AEAD encrypt/decrypt (<a
href="https://redirect.github.com/pyca/cryptography/issues/15361">#15361</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02"><code>6954733</code></a>
Release the GIL during DH and DSA parameter generation (<a
href="https://redirect.github.com/pyca/cryptography/issues/15364">#15364</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/6893b94c33e948f6240082461424cfb5da2dacc6"><code>6893b94</code></a>
Import _serialization instead of serialization in x509/extensions (<a
href="https://redirect.github.com/pyca/cryptography/issues/15363">#15363</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pyca/cryptography/compare/48.0.1...50.0.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=cryptography&package-manager=uv&previous-version=48.0.1&new-version=50.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-05 13:17:47 -07:00
dependabot[bot] ff3425ae48 chore: bump aiohttp from 3.14.1 to 3.14.3 in /libs/langchain_v1 (#39242)
Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.14.1 to
3.14.3.

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-05 13:17:41 -07:00
dependabot[bot] eb898e44af chore: bump cryptography from 48.0.1 to 50.0.0 in /libs/langchain_v1 (#39240)
Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.1
to 50.0.0.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst">cryptography's
changelog</a>.</em></p>
<blockquote>
<p>50.0.0 - 2026-07-31</p>
<pre><code>
* **SECURITY ISSUE**:

:func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
and its PEM and S/MIME variants no longer expose distinguishable errors
or
timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which
could
act as a Bleichenbacher oracle for callers that decrypt untrusted
messages.
A random key is now substituted on failure, as described in :rfc:`3218`.
  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
  Everything FFDH is deprecated, including the types in
``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys
or
  parameters with the key loading APIs. Users should migrate to a more
  modern key exchange algorithm.
* Added ``xof()`` class methods to
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
:class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for
constructing
  algorithm instances configured for use with
  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification &lt;cryptography.x509.verification&gt;`
APIs are now
  considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
  chunked-encryption specification
&lt;https://c2sp.org/chunked-encryption&gt;`_ for streaming
authenticated
  encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
carry trailing bytes after the list or after an individual SCT, instead
of
  silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field
type in
  the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a
non-zero
  number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
``GeneralizedTime`` that carries fractional seconds or another non-DER
form,
matching the strict encoding already required for every other X.509 time
  field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
:func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a
request
or response whose ``version`` field is not ``v1``, the only version
defined
by RFC 6960, matching the version validation already performed when
loading
  certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now
supported
  when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported
when
  building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now
supported
  when building against AWS-LC.
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc"><code>dcb7050</code></a>
Prepare for 50.0.0 release (<a
href="https://redirect.github.com/pyca/cryptography/issues/15372">#15372</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"><code>53fccd9</code></a>
Don't leak how PKCS#7 encryptedKey decryption failed (<a
href="https://redirect.github.com/pyca/cryptography/issues/15369">#15369</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8"><code>d472f97</code></a>
Add <code>from __future__ import annotations</code> to all src/ Python
files (<a
href="https://redirect.github.com/pyca/cryptography/issues/15371">#15371</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a"><code>908773d</code></a>
Bump downstream dependencies in CI (<a
href="https://redirect.github.com/pyca/cryptography/issues/15368">#15368</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812"><code>2cc07cc</code></a>
Bump BoringSSL, OpenSSL, AWS-LC in CI (<a
href="https://redirect.github.com/pyca/cryptography/issues/15367">#15367</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66"><code>c94ede9</code></a>
chore(deps): bump ruff from 0.16.0 to 0.16.1 (<a
href="https://redirect.github.com/pyca/cryptography/issues/15366">#15366</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35"><code>67a8308</code></a>
chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (<a
href="https://redirect.github.com/pyca/cryptography/issues/15365">#15365</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596"><code>95018ff</code></a>
Release the GIL in one-shot AEAD encrypt/decrypt (<a
href="https://redirect.github.com/pyca/cryptography/issues/15361">#15361</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02"><code>6954733</code></a>
Release the GIL during DH and DSA parameter generation (<a
href="https://redirect.github.com/pyca/cryptography/issues/15364">#15364</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/6893b94c33e948f6240082461424cfb5da2dacc6"><code>6893b94</code></a>
Import _serialization instead of serialization in x509/extensions (<a
href="https://redirect.github.com/pyca/cryptography/issues/15363">#15363</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pyca/cryptography/compare/48.0.1...50.0.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=cryptography&package-manager=uv&previous-version=48.0.1&new-version=50.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-05 13:17:38 -07:00
dependabot[bot] b00e47589b chore: bump langsmith from 0.10.6 to 0.10.16 in /libs/partners/huggingface (#39281)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from
0.10.6 to 0.10.16.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's
releases</a>.</em></p>
<blockquote>
<h2>v0.10.16</h2>
<h2>What's Changed</h2>
<ul>
<li>release(js): 0.8.9 by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3316">langchain-ai/langsmith-sdk#3316</a></li>
<li>fix(python): mask metadata after the runtime env merge and via the
anonymizer by <a
href="https://github.com/vladislav-nechakhin"><code>@​vladislav-nechakhin</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3313">langchain-ai/langsmith-sdk#3313</a></li>
<li>fix(js): mask metadata after the runtime env merge and via the
anonymizer by <a
href="https://github.com/vladislav-nechakhin"><code>@​vladislav-nechakhin</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3314">langchain-ai/langsmith-sdk#3314</a></li>
<li>chore(deps-dev): bump types-requests from 2.33.0.20260518 to
2.33.0.20260712 in /python by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3325">langchain-ai/langsmith-sdk#3325</a></li>
<li>chore(deps-dev): bump types-pyyaml from 6.0.12.20260518 to
6.0.12.20260724 in /python by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3324">langchain-ai/langsmith-sdk#3324</a></li>
<li>chore(deps): bump the actions-major group with 2 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3321">langchain-ai/langsmith-sdk#3321</a></li>
<li>chore(deps): bump the actions-minor-and-patch group across 1
directory with 3 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3320">langchain-ai/langsmith-sdk#3320</a></li>
<li>chore(deps): bump the npm_and_yarn group across 3 directories with 3
updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3330">langchain-ai/langsmith-sdk#3330</a></li>
<li>fix(js,py): stamp ls_agent_type on wrap_openai LLM runs by <a
href="https://github.com/ybathula707"><code>@​ybathula707</code></a> in
<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3317">langchain-ai/langsmith-sdk#3317</a></li>
<li>chore(deps): bump aiohttp from 3.14.1 to 3.14.3 in /python by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3329">langchain-ai/langsmith-sdk#3329</a></li>
<li>chore(deps-dev): bump the py-major group in /python with 2 updates
by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3323">langchain-ai/langsmith-sdk#3323</a></li>
<li>chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /python by
<a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3331">langchain-ai/langsmith-sdk#3331</a></li>
<li>fix(js,py): preserve user-supplied ls_agent_type in
openai-agents-sdk integration by <a
href="https://github.com/ybathula707"><code>@​ybathula707</code></a> in
<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3318">langchain-ai/langsmith-sdk#3318</a></li>
<li>fix(js): inherit parent's ls_agent_type in Vercel _getLsAgentType
helper by <a
href="https://github.com/ybathula707"><code>@​ybathula707</code></a> in
<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3319">langchain-ai/langsmith-sdk#3319</a></li>
<li>chore(deps): bump the py-minor-and-patch group across 1 directory
with 25 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3322">langchain-ai/langsmith-sdk#3322</a></li>
<li>fix(profiles): resolve the OAuth token endpoint from deployment
metadata by <a
href="https://github.com/langchain-infra"><code>@​langchain-infra</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3333">langchain-ai/langsmith-sdk#3333</a></li>
<li>fix: avoid resetting compression threads by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3332">langchain-ai/langsmith-sdk#3332</a></li>
<li>docs(sandbox): fix invalid sizing example in JS sandbox README by <a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3335">langchain-ai/langsmith-sdk#3335</a></li>
<li>test(claude-agent-sdk): run subagent in foreground so trace nests
correctly by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3339">langchain-ai/langsmith-sdk#3339</a></li>
<li>release(py): 0.10.16 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3337">langchain-ai/langsmith-sdk#3337</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/vladislav-nechakhin"><code>@​vladislav-nechakhin</code></a>
made their first contribution in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3313">langchain-ai/langsmith-sdk#3313</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.15...v0.10.16">https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.15...v0.10.16</a></p>
<h2>v0.10.15</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(python): apply the caller-supplied session's config to v2
endpoints by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3304">langchain-ai/langsmith-sdk#3304</a></li>
<li>chore: Use a common function for backend detection by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3307">langchain-ai/langsmith-sdk#3307</a></li>
<li>fix: prioritize API key over OAuth profile auth [closes LSDK-414] by
<a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3295">langchain-ai/langsmith-sdk#3295</a></li>
<li>fix(js): apply caller-supplied headers to the v2 endpoints by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3305">langchain-ai/langsmith-sdk#3305</a></li>
<li>chore: deprecate legacy SmithDB-migration SDK methods by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3299">langchain-ai/langsmith-sdk#3299</a></li>
<li>chore: sync langsmith_api by <a
href="https://github.com/langtions-bot"><code>@​langtions-bot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3310">langchain-ai/langsmith-sdk#3310</a></li>
<li>fix: stop supported APIs from emitting nested deprecation warnings
by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3308">langchain-ai/langsmith-sdk#3308</a></li>
<li>chore: deprecate the run-sharing SDK methods by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3312">langchain-ai/langsmith-sdk#3312</a></li>
<li>release(py): 0.10.15 by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3315">langchain-ai/langsmith-sdk#3315</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.14...v0.10.15">https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.14...v0.10.15</a></p>
<h2>v0.10.14</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(sandbox): count an acknowledged reattachment as progress by <a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3301">langchain-ai/langsmith-sdk#3301</a></li>
<li>feat(python): trace raw Gemini Live sessions by <a
href="https://github.com/carolinedivittorio"><code>@​carolinedivittorio</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3291">langchain-ai/langsmith-sdk#3291</a></li>
<li>release(py): 0.10.14 by <a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3302">langchain-ai/langsmith-sdk#3302</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/3f9fe09d8e0698d65aa8bb63ac3316dfcb2ca947"><code>3f9fe09</code></a>
release(py): 0.10.16 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3337">#3337</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/8c5d807dca1f25673bc95492ed9a04f3a6850a2c"><code>8c5d807</code></a>
test(claude-agent-sdk): run subagent in foreground so trace nests
correctly (...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/b34c68e3a87897f082da436d7f0ccd7d82fd5c9f"><code>b34c68e</code></a>
docs(sandbox): fix invalid sizing example in JS sandbox README (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3335">#3335</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/446c78c7481b2d890db78636101aabe1a51acf90"><code>446c78c</code></a>
fix: avoid resetting compression threads (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3332">#3332</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/cc9291a6852f13bdd732f466d61056e5b8a4d0c5"><code>cc9291a</code></a>
fix(profiles): resolve the OAuth token endpoint from deployment metadata
(<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3333">#3333</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/1e70bf5c526a518916bd477f1c4e785a73a9f7d8"><code>1e70bf5</code></a>
chore(deps): bump the py-minor-and-patch group across 1 directory with
25 upd...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/9b047e3ca79bd9b7dd633c2f0d750154713fbe8b"><code>9b047e3</code></a>
fix(js): inherit parent's ls_agent_type in Vercel _getLsAgentType helper
(<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3319">#3319</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/0a6256d636c1b824650e543c529ed46140322b32"><code>0a6256d</code></a>
fix(js,py): preserve user-supplied ls_agent_type in openai-agents-sdk
integra...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/312a9f545764f0456f5d9e803aaa1e7c4bb8d164"><code>312a9f5</code></a>
chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /python (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3331">#3331</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/2a81489e723df8f65593811171cca2d12d4f49df"><code>2a81489</code></a>
chore(deps-dev): bump the py-major group in /python with 2 updates (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3323">#3323</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.6...v0.10.16">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=langsmith&package-manager=uv&previous-version=0.10.6&new-version=0.10.16)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-05 13:17:11 -07:00
Mason Daugherty 506ac67ad1 release(anthropic): 1.5.4 (#39277)
Changes since 1.5.3:

- `ChatAnthropic` now exposes a `user_profile_id` convenience attribute
(#39148)
- Fixed `tool_choice` being overridden instead of preserving the
caller's value (#39206)
- Fixed handling of tool schemas with unsupported top-level composition
(#39273)
langchain-anthropic==1.5.4
2026-08-05 14:59:15 -04:00
Mason Daugherty 3af5d06922 fix(anthropic): handle tool schemas with unsupported top-level composition (#39273)
`ChatAnthropic.bind_tools` no longer fails an entire tool-calling
request because one bound tool has an `input_schema` that the Anthropic
API will not accept.

Related #39271

[Related JS PR](https://github.com/langchain-ai/langchainjs/pull/11310)

---

`ChatAnthropic` now preserves tools that use root-level `allOf` schemas
while continuing to filter unsupported root-level `oneOf` and `anyOf`
schemas.

## Why

The MCP specification
[(SEP-2106)](https://modelcontextprotocol.io/seps/2106-json-schema-2020-12)
permits root-level JSON Schema composition in a tool `inputSchema`.
Anthropic accepts root `allOf` as a schema merge, but rejects root
`oneOf` and `anyOf` during tool validation.

An MCP server can therefore emit a spec-compliant tool schema that
Anthropic refuses. Previously, LangChain forwarded that schema
unchanged, so a single incompatible tool prevented every tool in the
request from being used.

## What this does

Any tool whose root `input_schema` carries `oneOf` or `anyOf` is dropped
with a `UserWarning` naming the tool and offending keyword. The
remaining tools bind normally, so one incompatible schema no longer
costs the caller the whole tool list. Root `allOf` schemas are
preserved, as are combinators nested under `properties` and built-in
server-side tools without an `input_schema`.

Dropping is appropriate only when a usable tool remains. Two cases raise
`ValueError` at bind time instead:

- **Every tool was dropped.** Binding a model to an empty tool list
makes tool calling silently unavailable.
- **A forced `tool_choice` can no longer be honored.** A specific
dropped tool, or `tool_choice="any"` after the tool set shrank, can
leave an agent depending on an unreachable tool. This does not apply
when `thinking` is enabled, because the forced choice is already
discarded before the request is sent.

Error messages name the affected tools and distinguish remedies for
schemas the caller controls from third-party MCP schemas. For structured
output, they point to `with_structured_output(...,
method="json_schema")` where appropriate.

`get_num_tokens_from_messages` applies the same `oneOf`/`anyOf`
filtering as `bind_tools`, keeping token counting consistent with
request binding.
2026-08-05 14:53:55 -04:00
Nishitha M ed00a996c7 test(langchain): regression test for shell tool + checkpointer msgpack error (#39267) 2026-08-05 14:50:57 -04:00
Nishitha Mandriunyfir 1bdaf0c133 fix(langchain): handle malformed structured-output responses (#39245)
Fixes #34358

Improves handling of malformed structured-output responses.
`LLMToolSelectorMiddleware` previously crashed with a `KeyError` if the
selection model returned a response missing the expected `tools` key. It
now retries the call (`max_retries`, default `1`) before giving up, and
once retries are exhausted, the fallback behavior is configurable via
`on_parsing_failure`: raise a clear `ValueError` (default), select no
tools, select every available tool, fall back to a fixed list of tool
names, or a custom callable that receives the malformed response and
returns the tool names to use.

### Release Notes
LLMToolSelectorMiddleware and SummarizationMiddleware no longer leak
internal model output into the user-facing stream under
stream_mode="messages", astream_events, or astream_log.
LLMToolSelectorMiddleware also gains max_retries and on_parsing_failure
constructor options to control retry count and fallback behavior when
the selection model returns a malformed response, instead of always
raising a KeyError.
So, if the user was catching KeyError or TypeError before, they should
catch the ValueError now or make use of the built-in retry mechanisms.

Co-authored-by: riunyfir <144903038+riunyfir@users.noreply.github.com>
2026-08-05 13:54:49 -04:00
Nishitha MandTowseef 8f7cee0b52 fix(langchain): prevent orphaned tool_calls in ToolCallLimitMiddleware end behavior (#39258)
Closes #34159

Fixes `ToolCallLimitMiddleware` with `exit_behavior="end"` when parallel
tool calls are present.

Previously, jumping to `"end"` could leave pending tool calls without
matching `ToolMessage`s, causing providers to reject the conversation on
the next turn. Now every pending call receives a `ToolMessage` before
ending, while none of the calls are executed.

The thread-level count is also restored to its pre-batch value, since
calls skipped by `"end"` should not consume the thread's quota.

---------

Co-authored-by: Towseef <baba.tauseef41@gmail.com>
2026-08-05 11:52:38 -04:00
langchain-oss-model-profiles[bot]andmdrxy dc8287c213 chore(model-profiles): refresh model profile data (#39256)
Automated refresh of model profile data for all in-monorepo partner
integrations via `langchain-profiles refresh`.

🤖 Generated by the [`refresh_model_profiles`
workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml).

## Summary of changes

**2 added · 2 removed · 0 changed** across 1 provider(s).

### groq

**➕ 2 added**
- `allam-2-7b` — 4,096 ctx, 4,096 out
- `qwen/qwen3.6-27b` — 131,072 ctx, 16,384 out, text+image in,
reasoning, tools

**➖ 2 removed**
- `meta-llama/llama-4-scout-17b-16e-instruct`
- `qwen/qwen3-32b`

Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com>
2026-08-05 10:54:19 -04:00
ccurme 599483fbac fix(langchain): add aliases for bedrock mantle chat models (#39260) 2026-08-05 10:38:25 -04:00
ccurme 51ddac1d53 feat(langchain): add LangSmith provider to init_chat_model (#39224) 2026-08-05 10:20:01 -04:00
Nishitha MandKai Jiang 479be6910c fix(langchain): clear stale structured_response between checkpointed turns (#39248)
Closes #36957

---

With a checkpointer, `_build_commands` only wrote `structured_response`
into state when the model call produced one, so a value persisted from a
prior turn stuck around in the checkpoint. The routing edges
(`_make_model_to_tools_edge`, `_make_model_to_model_edge`) only checked
`"structured_response" in state` (key presence), so a turn whose first
model call failed structured-output validation and needed a retry would
exit the loop early using the previous turn's stale value instead of
continuing to retry.

`_build_commands` now explicitly clears `structured_response` to `None`
when the agent has a `response_format` configured but the current call
didn't produce one, and the routing edges check
`state.get("structured_response") is not None` for freshness rather than
mere key presence.

---------

Co-authored-by: Kai Jiang <167662354+Kcstring@users.noreply.github.com>
2026-08-05 00:10:14 -04:00
Nishitha MandYigtwxx 59098912b1 fix(langchain): stop HITL approval gates from silently failing open (#39247)
Closes #38838

Related: #37093

---

Fixes an issue in `HumanInTheLoopMiddleware` where an invalid
`allowed_decisions` config (missing, empty, or misspelled) silently
disabled the approval gate. The constructor now raises `ValueError` with
the offending tool and config keys.

Also investigated #37093: rejected tool calls are already prevented from
executing by `create_agent` routing. The rejected call must remain in
the `AIMessage` so its rejection `ToolMessage` stays protocol-valid.
Added an end-to-end regression test confirming the call is not executed
and the message history remains correctly paired.

Co-authored-by: Yigtwxx <yigiterdogan023@gmail.com>
2026-08-04 23:33:22 -04:00
dependabot[bot] 8af53ae951 chore: bump aiohttp from 3.14.1 to 3.14.3 in /libs/langchain (#39244)
Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.14.1 to
3.14.3.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst">aiohttp's
changelog</a>.</em></p>
<blockquote>
<h1>3.14.3 (2026-07-22)</h1>
<h2>Bug fixes</h2>
<ul>
<li>
<p>Fixed the client dropping only the first <code>Authorization</code>,
<code>Cookie</code> and
<code>Proxy-Authorization</code> header when a redirect crossed an
origin -- by :user:<code>arshsmith1</code>.</p>
<p><em>Related issues and pull requests on GitHub:</em>
:issue:<code>13180</code>.</p>
</li>
<li>
<p>Fixed error message construction in the C HTTP parser -- by
:user:<code>bdraco</code>.</p>
<p><em>Related issues and pull requests on GitHub:</em>
:issue:<code>13222</code>.</p>
</li>
</ul>
<hr />
<h1>3.14.2 (2026-07-20)</h1>
<h2>Bug fixes</h2>
<ul>
<li>
<p>Fixed :py:attr:<code>~aiohttp.web.StreamResponse.last_modified</code>
rounding a
:class:<code>datetime.datetime</code> with a fractional second down.</p>
<p><em>Related issues and pull requests on GitHub:</em>
:issue:<code>5303</code>.</p>
</li>
<li>
<p>Fixed resolving <code>localhost</code> on Windows to fall back
without <code>AI_ADDRCONFIG</code>
when the first lookup fails, so <code>localhost</code> still works
without an active
network.</p>
<p><em>Related issues and pull requests on GitHub:</em>
:issue:<code>5357</code>.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aio-libs/aiohttp/commit/5e392ce0456f5235a4ee6ad46f0e806df2f15873"><code>5e392ce</code></a>
Release v3.14.3 (<a
href="https://redirect.github.com/aio-libs/aiohttp/issues/13225">#13225</a>)</li>
<li><a
href="https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d"><code>49f65d5</code></a>
[PR <a
href="https://redirect.github.com/aio-libs/aiohttp/issues/13222">#13222</a>/f4866933
backport][3.14] Build C parser error message from bounded...</li>
<li><a
href="https://github.com/aio-libs/aiohttp/commit/240099e5216a01b32919dcd8dd5c6c0b1bf83671"><code>240099e</code></a>
[PR <a
href="https://redirect.github.com/aio-libs/aiohttp/issues/13180">#13180</a>/ee53d655
backport][3.14] drop every copy of credential headers on ...</li>
<li><a
href="https://github.com/aio-libs/aiohttp/commit/d93f30a302f8b930074fe14a2be7b2088ba28111"><code>d93f30a</code></a>
Bump version (<a
href="https://redirect.github.com/aio-libs/aiohttp/issues/13202">#13202</a>)</li>
<li><a
href="https://github.com/aio-libs/aiohttp/commit/c1b9212ad3d93c24b5fc66ad0849597166bc816e"><code>c1b9212</code></a>
Release v3.14.2 (<a
href="https://redirect.github.com/aio-libs/aiohttp/issues/13201">#13201</a>)</li>
<li><a
href="https://github.com/aio-libs/aiohttp/commit/380d4b55e8df48dfd62f1addfb530426f6bc4106"><code>380d4b5</code></a>
[PR <a
href="https://redirect.github.com/aio-libs/aiohttp/issues/13054">#13054</a>/ed8b040c
backport][3.14] escape backslashes in digest auth quoted-...</li>
<li><a
href="https://github.com/aio-libs/aiohttp/commit/e1e1bee363dfba04a9a75c8801717da2ed5bdcb9"><code>e1e1bee</code></a>
Make llhttp method array size dynamic (<a
href="https://redirect.github.com/aio-libs/aiohttp/issues/13174">#13174</a>)
(<a
href="https://redirect.github.com/aio-libs/aiohttp/issues/13196">#13196</a>)</li>
<li><a
href="https://github.com/aio-libs/aiohttp/commit/aa4cf29b6a5ad6f4d21fa1dd3f69193dc2f5d505"><code>aa4cf29</code></a>
[PR <a
href="https://redirect.github.com/aio-libs/aiohttp/issues/13170">#13170</a>/2b906869
backport][3.14] Fix StreamResponse.last_modified rounding...</li>
<li><a
href="https://github.com/aio-libs/aiohttp/commit/71b57b40d85a0723c92b0a5a37ebdf518210d2ea"><code>71b57b4</code></a>
[PR <a
href="https://redirect.github.com/aio-libs/aiohttp/issues/13172">#13172</a>/a57747ed
backport][3.14] Fix C parser folding fragment into query_...</li>
<li><a
href="https://github.com/aio-libs/aiohttp/commit/64a03fb620b623e5a5a1b7103c07ae3e536a0d40"><code>64a03fb</code></a>
[PR <a
href="https://redirect.github.com/aio-libs/aiohttp/issues/13169">#13169</a>/1adc0cd7
backport][3.14] Upgrade http:// to https:// in README.rst...</li>
<li>Additional commits viewable in <a
href="https://github.com/aio-libs/aiohttp/compare/v3.14.1...v3.14.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=aiohttp&package-manager=uv&previous-version=3.14.1&new-version=3.14.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 17:10:50 -07:00
dependabot[bot] b3a87a7cab chore: bump aiohttp from 3.14.1 to 3.14.3 in /libs/partners/xai (#39241)
Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.14.1 to
3.14.3.

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=aiohttp&package-manager=uv&previous-version=3.14.1&new-version=3.14.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 17:10:44 -07:00
langchain-oss-model-profiles[bot]andmdrxy 6dcdb63fbc chore(model-profiles): refresh model profile data (#39239)
Automated refresh of model profile data for all in-monorepo partner
integrations via `langchain-profiles refresh`.

🤖 Generated by the [`refresh_model_profiles`
workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml).

## Summary of changes

**2 added · 0 removed · 10 changed** across 2 provider(s).

<details>
<summary>huggingface</summary>

**➕ 1 added**
- `deepseek-ai/DeepSeek-V4-Flash-0731` — 1,048,576 ctx, 384,000 out,
reasoning, tools

</details>

<details>
<summary>openrouter</summary>

**➕ 1 added**
- `qwen/qwen3.8-max` — 1,000,000 ctx, 131,072 out, text+image+video in,
reasoning, tools

**✏️ 10 changed**
- `anthropic/claude-opus-5`: added temperature control
- `meta-llama/llama-3.3-70b-instruct`: max output tokens 128,000 →
16,384
- `qwen/qwen3-235b-a22b-2507`: max output tokens 16,384 → 32,768
- `qwen/qwen3-coder-30b-a3b-instruct`: max output tokens 262,144 →
32,768
- `qwen/qwen3-next-80b-a3b-instruct`: max output tokens 262,144 → 16,384
- `qwen/qwen3-vl-30b-a3b-instruct`: max output tokens 32,768 → 16,384
- `qwen/qwen3.6-27b`: max output tokens 65,536 → 131,072
- `tencent/hy3-preview`: removed structured output
- `thedrummer/unslopnemo-12b`: max output tokens 32,768 → 1,024,000
- `z-ai/glm-5.2`: max output tokens 131,072 → 262,144

</details>

Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com>
2026-08-04 09:32:57 -04:00
dependabot[bot] 1a43a6e14a chore: bump aiohttp from 3.14.1 to 3.14.3 in /libs/partners/huggingface (#39237)
Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.14.1 to
3.14.3.

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=aiohttp&package-manager=uv&previous-version=3.14.1&new-version=3.14.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 02:05:25 -07:00
dependabot[bot] 94f1508ec7 chore: bump aiohttp from 3.14.1 to 3.14.3 in /libs/partners/fireworks (#39236)
Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.14.1 to
3.14.3.

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=aiohttp&package-manager=uv&previous-version=3.14.1&new-version=3.14.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 02:05:18 -07:00
Mason Daugherty a6b904fd5b fix(core): close internally created event loops in streaming tracers (#39222)
Fixed a resource leak in the `astream_events` and `astream_log`
streaming tracers: when constructed from synchronous code on Python
3.14+, an internally created event loop was never closed, causing a
`ResourceWarning: unclosed event loop` to be emitted at
garbage-collection time (and intermittent failures of warning-sensitive
tests such as `test_chat_prompt_template_variable_names`). The loop is
now closed when the handler is garbage collected.
2026-08-03 12:08:44 -04:00
37205e51bc chore: bump the minor-and-patch group across 3 directories with 7 updates (#39187)
Bumps the minor-and-patch group with 4 updates in the
/libs/model-profiles directory:
[typing-extensions](https://github.com/python/typing_extensions),
[syrupy](https://github.com/syrupy-project/syrupy),
[ruff](https://github.com/astral-sh/ruff) and
[mypy](https://github.com/python/mypy).
Bumps the minor-and-patch group with 4 updates in the
/libs/standard-tests directory:
[typing-extensions](https://github.com/python/typing_extensions),
[syrupy](https://github.com/syrupy-project/syrupy),
[ruff](https://github.com/astral-sh/ruff) and
[mypy](https://github.com/python/mypy).
Bumps the minor-and-patch group with 5 updates in the
/libs/text-splitters directory:

| Package | From | To |
| --- | --- | --- |
| [typing-extensions](https://github.com/python/typing_extensions) |
`4.15.0` | `4.16.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.20` | `0.16.0` |
| [ty](https://github.com/astral-sh/ty) | `0.0.56` | `0.0.64` |
| [transformers](https://github.com/huggingface/transformers) | `5.12.1`
| `5.14.1` |
|
[sentence-transformers](https://github.com/huggingface/sentence-transformers)
| `5.6.0` | `5.6.1` |


Updates `typing-extensions` from 4.15.0 to 4.16.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/python/typing_extensions/releases">typing-extensions's
releases</a>.</em></p>
<blockquote>
<h2>4.16.0</h2>
<p>No changes since 4.16.0rc2.</p>
<p>Changes since 4.15.0:</p>
<ul>
<li>Make <code>typing_extensions.TypeAliasType</code>'s
<code>__module__</code> attribute writable. Backport of CPython PR <a
href="https://redirect.github.com/python/cpython/pull/149172">#149172</a>.</li>
<li>Fix setting of <code>__required_keys__</code> and
<code>__optional_keys__</code> when inheriting keys with the same
name.</li>
<li>Add support for <code>AsyncIterator</code>, <code>io.Reader</code>,
<code>io.Writer</code> and <code>os.PathLike</code> protocols as bases
for other protocols.</li>
<li>Fix incorrect behaviour on Python 3.9 and Python 3.10 that meant
that calling <code>isinstance</code> with
<code>typing_extensions.Concatenate[...]</code> or
<code>typing_extensions.Unpack[...]</code> as the first argument could
have a different result in some situations depending on whether or not a
profiling function had been set using <code>sys.setprofile</code>. This
affected both CPython and PyPy implementations. Patch by Brian
Schubert.</li>
<li>Fix <code>__init_subclass__()</code> behavior in the presence of
multiple inheritance involving an <code>@deprecated</code>-decorated
base class. Backport of CPython PR <a
href="https://redirect.github.com/python/cpython/pull/138210">#138210</a>
by Brian Schubert.</li>
<li>Raise <code>TypeError</code> when attempting to subclass
<code>typing_extensions.ParamSpec</code> on Python 3.9. The
<code>typing</code> implementation has always raised an error, and the
<code>typing_extensions</code> implementation has raised an error on
Python 3.10+ since <code>typing_extensions</code> v4.6.0. Patch by Brian
Schubert.</li>
<li>Add the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code>, and <code>infer_variance</code> parameters
to <code>TypeVarTuple</code>.</li>
<li>Officially support the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code> and <code>infer_variance</code> parameters to
<code>ParamSpec</code>. Improve the validation of these parameters at
runtime.</li>
<li>Rename <code>typing_extensions.Sentinel</code> to
<code>typing_extensions.sentinel</code>, following the name that has
been adopted for <code>builtins.sentinel</code> on Python 3.15.
<code>typing_extensions.Sentinel</code> is retained as a soft-deprecated
alias for backwards compatibility.</li>
<li>Add support for pickling sentinels.</li>
<li>Sentinels now preserve their identity when copied or
deep-copied.</li>
<li>Deprecate passing <code>name</code> as a keyword argument or
<code>repr</code> as a positional argument to the <code>sentinel</code>
constructor.</li>
<li>The default repr of a sentinel <code>X =
sentinel(&quot;X&quot;)</code> is now <code>X</code> rather than
<code>&lt;X&gt;</code>.</li>
<li>Deprecate arbitrary attribute assignments to sentinels.</li>
<li>Deprecate subclassing sentinels.</li>
<li>Add support for Python 3.15.</li>
<li>Avoid a <code>DeprecationWarning</code> when <code>deprecated</code>
is applied to a coroutine function on Python 3.14.0.</li>
</ul>
<h2>4.16.0rc2</h2>
<p>Changes since 4.16.0rc1:</p>
<ul>
<li>Avoid a <code>DeprecationWarning</code> when <code>deprecated</code>
is applied to a coroutine function on Python 3.14.0.</li>
</ul>
<p>Changes since 4.15.0:</p>
<ul>
<li>Make <code>typing_extensions.TypeAliasType</code>'s
<code>__module__</code> attribute writable. Backport of CPython PR <a
href="https://redirect.github.com/python/cpython/pull/149172">#149172</a>.</li>
<li>Fix setting of <code>__required_keys__</code> and
<code>__optional_keys__</code> when inheriting keys with the same
name.</li>
<li>Add support for <code>AsyncIterator</code>, <code>io.Reader</code>,
<code>io.Writer</code> and <code>os.PathLike</code> protocols as bases
for other protocols.</li>
<li>Fix incorrect behaviour on Python 3.9 and Python 3.10 that meant
that calling <code>isinstance</code> with
<code>typing_extensions.Concatenate[...]</code> or
<code>typing_extensions.Unpack[...]</code> as the first argument could
have a different result in some situations depending on whether or not a
profiling function had been set using <code>sys.setprofile</code>. This
affected both CPython and PyPy implementations. Patch by Brian
Schubert.</li>
<li>Fix <code>__init_subclass__()</code> behavior in the presence of
multiple inheritance involving an <code>@deprecated</code>-decorated
base class. Backport of CPython PR <a
href="https://redirect.github.com/python/cpython/pull/138210">#138210</a>
by Brian Schubert.</li>
<li>Raise <code>TypeError</code> when attempting to subclass
<code>typing_extensions.ParamSpec</code> on Python 3.9. The
<code>typing</code> implementation has always raised an error, and the
<code>typing_extensions</code> implementation has raised an error on
Python 3.10+ since <code>typing_extensions</code> v4.6.0. Patch by Brian
Schubert.</li>
<li>Add the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code>, and <code>infer_variance</code> parameters
to <code>TypeVarTuple</code>.</li>
<li>Officially support the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code> and <code>infer_variance</code> parameters to
<code>ParamSpec</code>. Improve the validation of these parameters at
runtime.</li>
<li>Rename <code>typing_extensions.Sentinel</code> to
<code>typing_extensions.sentinel</code>, following the name that has
been adopted for <code>builtins.sentinel</code> on Python 3.15.
<code>typing_extensions.Sentinel</code> is retained as a soft-deprecated
alias for backwards compatibility.</li>
<li>Add support for pickling sentinels.</li>
<li>Sentinels now preserve their identity when copied or
deep-copied.</li>
<li>Deprecate passing <code>name</code> as a keyword argument or
<code>repr</code> as a positional argument to the <code>sentinel</code>
constructor.</li>
<li>The default repr of a sentinel <code>X =
sentinel(&quot;X&quot;)</code> is now <code>X</code> rather than
<code>&lt;X&gt;</code>.</li>
<li>Deprecate arbitrary attribute assignments to sentinels.</li>
<li>Deprecate subclassing sentinels.</li>
<li>Add support for Python 3.15.</li>
</ul>
<h2>4.16.0rc1</h2>
<ul>
<li>Make <code>typing_extensions.TypeAliasType</code>'s
<code>__module__</code> attribute writable. Backport of CPython PR <a
href="https://redirect.github.com/python/cpython/pull/149172">#149172</a>.</li>
<li>Fix setting of <code>__required_keys__</code> and
<code>__optional_keys__</code> when inheriting keys with the same
name.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/python/typing_extensions/blob/main/CHANGELOG.md">typing-extensions's
changelog</a>.</em></p>
<blockquote>
<h1>Release 4.16.0 (July 2, 2025)</h1>
<p>No user-facing changes since 4.16.0rc2.</p>
<h1>Release 4.16.0rc2 (June 25, 2026)</h1>
<ul>
<li>Avoid a <code>DeprecationWarning</code> when <code>deprecated</code>
is applied to a coroutine function on
Python 3.14.0.</li>
</ul>
<h1>Release 4.16.0rc1 (June 24, 2026)</h1>
<ul>
<li>Make <code>typing_extensions.TypeAliasType</code>'s
<code>__module__</code> attribute writable.
Backport of CPython PR
<a
href="https://redirect.github.com/python/cpython/pull/149172">#149172</a>.</li>
<li>Fix setting of <code>__required_keys__</code> and
<code>__optional_keys__</code> when inheriting
keys with the same name.</li>
<li>Add support for <code>AsyncIterator</code>, <code>io.Reader</code>,
<code>io.Writer</code> and <code>os.PathLike</code> protocols
as bases for other protocols.</li>
<li>Fix incorrect behaviour on Python 3.9 and Python 3.10 that meant
that
calling <code>isinstance</code> with
<code>typing_extensions.Concatenate[...]</code> or
<code>typing_extensions.Unpack[...]</code> as the first argument could
have a different
result in some situations depending on whether or not a profiling
function had been
set using <code>sys.setprofile</code>. This affected both CPython and
PyPy implementations.
Patch by Brian Schubert.</li>
<li>Fix <code>__init_subclass__()</code> behavior in the presence of
multiple inheritance involving
an <code>@deprecated</code>-decorated base class. Backport of CPython PR
<a
href="https://redirect.github.com/python/cpython/pull/138210">#138210</a>
by Brian Schubert.</li>
<li>Raise <code>TypeError</code> when attempting to subclass
<code>typing_extensions.ParamSpec</code> on
Python 3.9. The <code>typing</code> implementation has always raised an
error, and the
<code>typing_extensions</code> implementation has raised an error on
Python 3.10+ since
<code>typing_extensions</code> v4.6.0. Patch by Brian Schubert.</li>
<li>Add the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code>, and <code>infer_variance</code> parameters
to <code>TypeVarTuple</code>.</li>
<li>Officially support the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code> and <code>infer_variance</code>
parameters to <code>ParamSpec</code>. Improve the validation of these
parameters at runtime.</li>
<li>Rename <code>typing_extensions.Sentinel</code> to
<code>typing_extensions.sentinel</code>, following the
name that has been adopted for <code>builtins.sentinel</code> on Python
3.15.
<code>typing_extensions.Sentinel</code> is retained as a soft-deprecated
alias for backwards
compatibility.</li>
<li>Add support for pickling sentinels.</li>
<li>Sentinels now preserve their identity when copied or
deep-copied.</li>
<li>Deprecate passing <code>name</code> as a keyword argument or
<code>repr</code> as a positional argument
to the <code>sentinel</code> constructor.</li>
<li>The default repr of a sentinel <code>X =
sentinel(&quot;X&quot;)</code> is now <code>X</code> rather than
<code>&lt;X&gt;</code>.</li>
<li>Deprecate arbitrary attribute assignments to sentinels.</li>
<li>Deprecate subclassing sentinels.</li>
<li>Add support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/python/typing_extensions/commit/f29cd28d8ed7642cafb1d18daf5aa41be6a5c0aa"><code>f29cd28</code></a>
Prepare relase 4.16.0 (<a
href="https://redirect.github.com/python/typing_extensions/issues/774">#774</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/43174610ec0c407ce05ad750077c4e62b9192b2b"><code>4317461</code></a>
Bump version to 4.16.0rc2.dev (<a
href="https://redirect.github.com/python/typing_extensions/issues/772">#772</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/4f71098e5be84798d36416bbca0e776223ee40f9"><code>4f71098</code></a>
Prepare release 4.16.0rc2 (<a
href="https://redirect.github.com/python/typing_extensions/issues/771">#771</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/37ed08a11f3b7c05234f8963ab97e3ebdbdc16a2"><code>37ed08a</code></a>
Remove use of <code>asyncio.coroutines.iscoroutinefunction()</code> (<a
href="https://redirect.github.com/python/typing_extensions/issues/769">#769</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/8dcc5594cbe5a4e348245fea6ce160ce93ed6601"><code>8dcc559</code></a>
Improve <code>TypedDict</code> documentation (<a
href="https://redirect.github.com/python/typing_extensions/issues/770">#770</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/224f8d50551d26f0d603093596c3a47a7302a46f"><code>224f8d5</code></a>
Post-release followups for 3.16.0rc1 (<a
href="https://redirect.github.com/python/typing_extensions/issues/767">#767</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/777de3eb5f4562e2054d1d7ce707f098b1f4fd2f"><code>777de3e</code></a>
Prepare release 4.16.0rc1 (<a
href="https://redirect.github.com/python/typing_extensions/issues/766">#766</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/890be90f1545e7d5fa904dfa3154d5f03c96782c"><code>890be90</code></a>
Type variable tuple variance (<a
href="https://redirect.github.com/python/typing_extensions/issues/741">#741</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/0e0545866d78458b668dc52d2edc411f6e39540d"><code>0e05458</code></a>
Pin SQLAlchemy third-party tests to pytest==9.0.3 (<a
href="https://redirect.github.com/python/typing_extensions/issues/765">#765</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/d2777468c274202ec290103b34313e50cf040229"><code>d277746</code></a>
docs: add version compatibility table (<a
href="https://redirect.github.com/python/typing_extensions/issues/733">#733</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/python/typing_extensions/compare/4.15.0...4.16.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `syrupy` from 5.3.4 to 5.5.3
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/syrupy-project/syrupy/releases">syrupy's
releases</a>.</em></p>
<blockquote>
<h2>v5.5.3</h2>
<h2>What's Changed</h2>
<p>This release has no functional changes. It just fixes an issue where
the release tag pointed to the previous commit instead of the commit
with the updated pyproject.toml (see <a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1144">syrupy-project/syrupy#1144</a>).</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.2...v5.5.3">https://github.com/syrupy-project/syrupy/compare/v5.5.2...v5.5.3</a></p>
<h2>v5.5.2</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: Fix detecting <code>pytest-xdist</code> when loaded via
<code>PYTEST_PLUGINS</code> by <a
href="https://github.com/mgorny"><code>@​mgorny</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1142">syrupy-project/syrupy#1142</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/mgorny"><code>@​mgorny</code></a> made
their first contribution in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1142">syrupy-project/syrupy#1142</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.1...v5.5.2">https://github.com/syrupy-project/syrupy/compare/v5.5.1...v5.5.2</a></p>
<h2>v5.5.1</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: Defer registering <code>pytest-xdist</code> hook
<code>pytest_testnodedown</code> to avoid &quot;unknown hook&quot; error
by <a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1140">syrupy-project/syrupy#1140</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>
made their first contribution in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1140">syrupy-project/syrupy#1140</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.0...v5.5.1">https://github.com/syrupy-project/syrupy/compare/v5.5.0...v5.5.1</a></p>
<h2>v5.5.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat: detect unused snapshots under pytest-xdist by <a
href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1132">syrupy-project/syrupy#1132</a></li>
</ul>
<blockquote>
<p><strong>NOTE</strong>: Test suites using pytest-xdist that previously
passed due to incomplete snapshot support may now fail if unused
snapshots are detected. You can use <code>--snapshot-warn-unused</code>
to downgrade unused snapshot detection from an error to a warning though
it's not recommended.</p>
</blockquote>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.4.0...v5.5.0">https://github.com/syrupy-project/syrupy/compare/v5.4.0...v5.5.0</a></p>
<h2>v5.4.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat: add --snapshot-no-cleanup to keep unused snapshots on update
by <a href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1126">syrupy-project/syrupy#1126</a></li>
<li>fix: honor boolean operators in -k snapshot selection by <a
href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1127">syrupy-project/syrupy#1127</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.3.4...v5.4.0">https://github.com/syrupy-project/syrupy/compare/v5.3.4...v5.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/syrupy-project/syrupy/blob/main/CHANGELOG.md">syrupy's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v5.5.3">v5.5.3</a>
(2026-07-11)</h2>
<h2>What's Changed</h2>
<ul>
<li>chore(deps): update astral-sh/setup-uv action to v8.3.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1143">syrupy-project/syrupy#1143</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v8.3.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1145">syrupy-project/syrupy#1145</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1147">syrupy-project/syrupy#1147</a></li>
<li>chore(deps): update dependency mypy to v2.2.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1148">syrupy-project/syrupy#1148</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.3 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1150">syrupy-project/syrupy#1150</a></li>
<li>chore: closes <a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1144">#1144</a>
by <a href="https://github.com/noahnu"><code>@​noahnu</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1146">syrupy-project/syrupy#1146</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v8.3.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1149">syrupy-project/syrupy#1149</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.2...v5.5.3">https://github.com/syrupy-project/syrupy/compare/v5.5.2...v5.5.3</a></p>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v5.5.2">v5.5.2</a>
(2026-07-08)</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: Fix detecting <code>pytest-xdist</code> when loaded via
<code>PYTEST_PLUGINS</code> by <a
href="https://github.com/mgorny"><code>@​mgorny</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1142">syrupy-project/syrupy#1142</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/mgorny"><code>@​mgorny</code></a> made
their first contribution in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1142">syrupy-project/syrupy#1142</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.1...v5.5.2">https://github.com/syrupy-project/syrupy/compare/v5.5.1...v5.5.2</a></p>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v5.5.1">v5.5.1</a>
(2026-07-06)</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: Defer registering <code>pytest-xdist</code> hook
<code>pytest_testnodedown</code> to avoid &quot;unknown hook&quot; error
by <a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1140">syrupy-project/syrupy#1140</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>
made their first contribution in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1140">syrupy-project/syrupy#1140</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.0...v5.5.1">https://github.com/syrupy-project/syrupy/compare/v5.5.0...v5.5.1</a></p>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v5.5.0">v5.5.0</a>
(2026-07-06)</h2>
<h2>What's Changed</h2>
<ul>
<li>feat: detect unused snapshots under pytest-xdist by <a
href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1132">syrupy-project/syrupy#1132</a></li>
</ul>
<blockquote>
<p><strong>NOTE</strong>: Test suites using pytest-xdist that previously
passed due to incomplete snapshot support may now fail if unused
snapshots are detected. You can use <code>--snapshot-warn-unused</code>
to downgrade unused snapshot detection from an error to a warning though
it's not recommended.</p>
</blockquote>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.4.0...v5.5.0">https://github.com/syrupy-project/syrupy/compare/v5.4.0...v5.5.0</a></p>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v5.4.0">v5.4.0</a>
(2026-07-01)</h2>
<h2>What's Changed</h2>
<ul>
<li>feat: add --snapshot-no-cleanup to keep unused snapshots on update
by <a href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1126">syrupy-project/syrupy#1126</a></li>
<li>fix: honor boolean operators in -k snapshot selection by <a
href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1127">syrupy-project/syrupy#1127</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/3cd347306cf44db076d2e4f50f7dfd325d9b5a92"><code>3cd3473</code></a>
chore(release): 5.5.3 [skip ci]</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/fed7e9f69f4dd14b39360e626236c868147588d5"><code>fed7e9f</code></a>
chore(deps): update astral-sh/setup-uv action to v8.3.2 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1149">#1149</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/443fc11bf67ce588753cd4518ef056463cfe651b"><code>443fc11</code></a>
chore: closes <a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1144">#1144</a>
(<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1146">#1146</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/56bf157ce4135bde78ecc49cfa9532ffa41659e8"><code>56bf157</code></a>
chore(deps): update dependency hypothesis to v6.156.3 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1150">#1150</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/f9c725a5653677bfcafb53645c9a078f3aa79d87"><code>f9c725a</code></a>
chore(deps): update dependency mypy to v2.2.0 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1148">#1148</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/3af2ccf2feeadb3a0d4e3f418d22ad3395725c80"><code>3af2ccf</code></a>
chore(deps): update dependency hypothesis to v6.156.2 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1147">#1147</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/feaa22ca4c211dfcdd8d0d048112531fd6cb344c"><code>feaa22c</code></a>
chore(deps): update astral-sh/setup-uv action to v8.3.1 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1145">#1145</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/5c59701e411922a464497398f5df25d76f2f9dcd"><code>5c59701</code></a>
chore(deps): update astral-sh/setup-uv action to v8.3.0 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1143">#1143</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/1cbf7167ff114e3012b1c139661777c1a0b692ee"><code>1cbf716</code></a>
chore(release): 5.5.2 [skip ci]</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/4f83490d2ebf4ae22aeba6d9946979640151aa34"><code>4f83490</code></a>
fix: Fix detecting <code>pytest-xdist</code> when loaded via
<code>PYTEST_PLUGINS</code> (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1142">#1142</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/syrupy-project/syrupy/compare/v5.3.4...v5.5.3">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.15.20 to 0.16.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.0</h2>
<h2>Release Notes</h2>
<p>Released on 2026-07-23.</p>
<p>Check out the <a href="https://astral.sh/blog/ruff-v0.16.0">blog
post</a> for a migration guide and overview of the changes!</p>
<h3>Breaking changes</h3>
<ul>
<li>
<p>Ruff now enables a much larger set of rules by default (413, up from
59). See the blog post for more details and the new <a
href="https://docs.astral.sh/ruff/default-rules/">Default Rules</a> page
for a full listing of the enabled rules. Note that this is primarily an
expansion, but 18 of the more opinionated pycodestyle (<code>E</code>)
and pyflakes (<code>F</code>) rules have been removed from the default
set: <code>E401</code>, <code>E402</code>, <code>E701</code>,
<code>E702</code>, <code>E703</code>, <code>E711</code>,
<code>E712</code>, <code>E713</code>, <code>E714</code>,
<code>E721</code>, <code>E731</code>, <code>E741</code>,
<code>E742</code>, <code>E743</code>, <code>F403</code>,
<code>F405</code>, <code>F406</code>, and <code>F722</code>.</p>
</li>
<li>
<p>Ruff can now format Python code blocks in Markdown files and will do
this by default. See the <a
href="https://docs.astral.sh/ruff/formatter/#markdown-code-formatting">documentation</a>
for more details.</p>
</li>
<li>
<p>Ruff now supports <code>ruff: ignore</code> comments at the ends of
lines, like <code>noqa</code> comments, or on the line preceding a
diagnostic. For example, these both suppress an <a
href="https://docs.astral.sh/ruff/rules/unused-import/"><code>unused-import</code></a>
(<code>F401</code>) diagnostic:</p>
<pre lang="py"><code>import math  # ruff: ignore[F401]
<h1>ruff: ignore[F401]</h1>
<p>import os
</code></pre></p>
</li>
<li>
<p>Fixes are now shown in <code>check</code> and <code>format
--check</code> output:</p>
<pre lang="console"><code>❯ ruff format --check .
unformatted: File would be reformatted
 --&gt; try.md:1:1
  |
1 | ```python
  - import   math
2 + import math
3 | ```
  |
<p>1 file would be reformatted
</code></pre></p>
<p>This example also shows off the Markdown formatting.</p>
</li>
<li>
<p><code>format --check</code> now supports the same output formats as
the linter, including the <code>github</code> and <code>gitlab</code>
outputs for rendering annotations in CI:</p>
<pre lang="console"><code>❯ ruff format --check --output-format github .
::error title=ruff
(unformatted),file=try.md,line=2,col=8,endLine=2,endColumn=10::try.md:2:8:
unformatted: File would be reformatted
</code></pre>
<p>See the CLI help or <a
href="https://docs.astral.sh/ruff/settings/#output-format">documentation</a>
for the full list of supported formats.</p>
</li>
<li>
<p>The <code>filename</code>, <code>location</code>,
<code>end_location</code>, <code>fix.edits[].location</code>, and
<code>fix.edits[].end_location</code> fields in the JSON output format
may now be <code>null</code> rather than defaulting to the empty string
and row 1, column 1, respectively.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.0</h2>
<p>Released on 2026-07-23.</p>
<p>Check out the <a href="https://astral.sh/blog/ruff-v0.16.0">blog
post</a> for a migration
guide and overview of the changes!</p>
<h3>Breaking changes</h3>
<ul>
<li>
<p>Ruff now enables a much larger set of rules by default (413, up from
59). See the blog post for
more details and the new <a
href="https://docs.astral.sh/ruff/default-rules/">Default Rules</a> page
for a
full listing of the enabled rules. Note that this is primarily an
expansion, but 18 of the more
opinionated pycodestyle (<code>E</code>) and pyflakes (<code>F</code>)
rules have been removed from the default set:
<code>E401</code>, <code>E402</code>, <code>E701</code>,
<code>E702</code>, <code>E703</code>, <code>E711</code>,
<code>E712</code>, <code>E713</code>, <code>E714</code>,
<code>E721</code>, <code>E731</code>, <code>E741</code>,
<code>E742</code>, <code>E743</code>, <code>F403</code>,
<code>F405</code>, <code>F406</code>, and <code>F722</code>.</p>
</li>
<li>
<p>Ruff can now format Python code blocks in Markdown files and will do
this by default. See the
<a
href="https://docs.astral.sh/ruff/formatter/#markdown-code-formatting">documentation</a>
for more details.</p>
</li>
<li>
<p>Ruff now supports <code>ruff: ignore</code> comments at the ends of
lines, like <code>noqa</code> comments, or on the line preceding a
diagnostic. For example, these both suppress an <a
href="https://docs.astral.sh/ruff/rules/unused-import/"><code>unused-import</code></a>
(<code>F401</code>) diagnostic:</p>
<pre lang="py"><code>import math  # ruff: ignore[F401]
<h1>ruff: ignore[F401]</h1>
<p>import os
</code></pre></p>
</li>
<li>
<p>Fixes are now shown in <code>check</code> and <code>format
--check</code> output:</p>
<pre lang="console"><code>❯ ruff format --check .
unformatted: File would be reformatted
 --&gt; try.md:1:1
  |
1 | ```python
  - import   math
2 + import math
3 | ```
  |
<p>1 file would be reformatted
</code></pre></p>
<p>This example also shows off the Markdown formatting.</p>
</li>
<li>
<p><code>format --check</code> now supports the same output formats as
the linter, including the <code>github</code> and
<code>gitlab</code> outputs for rendering annotations in CI:</p>
<pre lang="console"><code></code></pre>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/a2635fd8f39e1d34ce8074cb486809426148f3e9"><code>a2635fd</code></a>
Bump 0.16.0 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27136">#27136</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/34334491652f8ceca5246d15c5c5afe0d6bc77ae"><code>3433449</code></a>
[ty] Reuse full call diagnostics for implicit setter calls (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27115">#27115</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/22400709220931375e072ad5d7460b9fc781af78"><code>2240070</code></a>
Reflect <code>ruff: ignore</code> and <code>--add-ignore</code>
stabilization in documentation (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27">#27</a>...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/17ef71142c52230b923dad46ee5554140fc3fd2e"><code>17ef711</code></a>
Stabilize <code>--add-ignore</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27125">#27125</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ef912bbbe466856aa4aac10ad2a8856eb3d5aef3"><code>ef912bb</code></a>
Add newly stabilized rules to defaults (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27055">#27055</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/b30f04023281b46f12011f13ce6b45c247e0d2e3"><code>b30f040</code></a>
Stabilize new default rules (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27035">#27035</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/bcd70c5f10ea97ed52a785d70e7f33b83b7c697a"><code>bcd70c5</code></a>
Exclude Markdown files from <code>format-dev</code> runs (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27052">#27052</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/87e51e2cbbaed376fc13dead40fd772361fa07c0"><code>87e51e2</code></a>
Fix <code>format --check</code> spans for syntax errors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27045">#27045</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/afe2723a348364ac7f4b9abd76fc67779490c05e"><code>afe2723</code></a>
[<code>flake8-gettext</code>] Stabilize qualified-name and built-in
binding resolution (...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/a9702d8928344f77a41dbe535f655a69fb04e2df"><code>a9702d8</code></a>
[<code>flake8-bandit</code>] Stabilize string literal binding resolution
(<code>S310</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/issues/26944">#26944</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.15.20...0.16.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `mypy` from 2.1.0 to 2.3.0
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/python/mypy/blob/master/CHANGELOG.md">mypy's
changelog</a>.</em></p>
<blockquote>
<h1>Mypy Release Notes</h1>
<h2>Next Release</h2>
<h3>Packaging changes</h3>
<ul>
<li>No longer provide mypyc-accelerated wheels for macOS x86_64
[mypyc-wheels <a
href="https://redirect.github.com/python/mypy/issues/119">#119</a>](<a
href="https://redirect.github.com/mypyc/mypy_mypyc-wheels/pull/119">mypyc/mypy_mypyc-wheels#119</a>)</li>
</ul>
<h2>Mypy 2.3</h2>
<p>We've just uploaded mypy 2.3.0 to the Python Package Index (<a
href="https://pypi.org/project/mypy/">PyPI</a>).
Mypy is a static type checker for Python. This release includes new
features, performance
improvements and bug fixes. You can install it as follows:</p>
<pre><code>python3 -m pip install -U mypy
</code></pre>
<p>You can read the full documentation for this release on <a
href="http://mypy.readthedocs.io">Read the Docs</a>.</p>
<h3>The Upcoming Switch to the New Native Parser</h3>
<p>We are planning to enable the new native parser
(<code>--native-parser</code>) by
default soon. We recommend that you test the native parser in your
projects and report
any issues in the <a href="https://github.com/python/mypy/issues">mypy
issue tracker</a>.</p>
<h3>Mypyc Free-threading Memory Safety</h3>
<p>Free-threaded Python builds that don't have the GIL require
additional synchronization
primitives or lock-free algorithms to ensure memory safety when there
are race conditions
(for example, when a thread reads a list item while another thread
writes the same list
item concurrently). This release greatly improves memory safety of free
threading.</p>
<p>List operations are now memory-safe on free threaded Python builds,
even in the presence of
race conditions. This has some performance cost. For list-heavy
workloads, using
<code>librt.vecs.vec</code> instead of list is often significantly
faster, but note that <code>vec</code> is not
(and likely won't be) fully memory safe, and the user is expected to
avoid race conditions.
The newly introduced <code>librt.threading.Lock</code> helps with this.
Using variable-length tuples
can also be more efficient than lists, since tuples are immutable and
don't require
expensive synchronization to ensure memory safety.</p>
<p>Instance attribute access is also (mostly) memory safe now on
free-threaded builds in
the presence of race conditions. We are planning to fix the remaining
unsafe cases in a
future release.</p>
<p>Full list of changes:</p>
<ul>
<li>Make attribute access memory safe on free-threaded builds (Jukka
Lehtosalo, PR <a
href="https://redirect.github.com/python/mypy/pull/21705">21705</a>)</li>
<li>Fix unsafe borrowing of instance attributes with free-threading
(Jukka Lehtosalo, PR <a
href="https://redirect.github.com/python/mypy/pull/21688">21688</a>)</li>
<li>Make list get/set item more memory safe on free-threaded builds
(Jukka Lehtosalo, PR <a
href="https://redirect.github.com/python/mypy/pull/21683">21683</a>)</li>
<li>Don't borrow list items on free-threaded builds (Jukka Lehtosalo, PR
<a
href="https://redirect.github.com/python/mypy/pull/21679">21679</a>)</li>
<li>Make multiple assignment from list memory-safe on free-threaded
builds (Jukka Lehtosalo, PR <a
href="https://redirect.github.com/python/mypy/pull/21684">21684</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/python/mypy/commit/8aabf8435357eaffceca7237f371e293b8168e54"><code>8aabf84</code></a>
Drop +dev from version</li>
<li><a
href="https://github.com/python/mypy/commit/4d8ad2ab5e86c99581b73775f2c00b9b8265b589"><code>4d8ad2a</code></a>
Update changelog for 2.3 release (<a
href="https://redirect.github.com/python/mypy/issues/21728">#21728</a>)</li>
<li><a
href="https://github.com/python/mypy/commit/2c2154672040c52e481f423854d104e6cf172585"><code>2c21546</code></a>
[mypyc] Update documentation of race conditions under free threading (<a
href="https://redirect.github.com/python/mypy/issues/21726">#21726</a>)</li>
<li><a
href="https://github.com/python/mypy/commit/a9f62a3cf98a58a7a2607b7c81695802b39f5edc"><code>a9f62a3</code></a>
[mypyc] Make attribute access memory safe on free-threaded builds (<a
href="https://redirect.github.com/python/mypy/issues/21705">#21705</a>)</li>
<li><a
href="https://github.com/python/mypy/commit/0faa413ebf7c924a864ef5dabd70303d898e7766"><code>0faa413</code></a>
Use <code>PYODIDE</code> environment variable for Emscripten
cross-compilation detection...</li>
<li><a
href="https://github.com/python/mypy/commit/3d75cdb09f0928fa8b83e5ef03572ed878ac8d09"><code>3d75cdb</code></a>
[mypyc] Borrow final attributes more aggressively (<a
href="https://redirect.github.com/python/mypy/issues/21702">#21702</a>)</li>
<li><a
href="https://github.com/python/mypy/commit/24c237d85b48f618e655ffff1dc0f19089d9b599"><code>24c237d</code></a>
[mypyc] Improve documentation of Final (<a
href="https://redirect.github.com/python/mypy/issues/21713">#21713</a>)</li>
<li><a
href="https://github.com/python/mypy/commit/b5be217392b9b2771d1764066b9d600bf93ce7a8"><code>b5be217</code></a>
[mypyc] Update free threading Python compatibility docs (<a
href="https://redirect.github.com/python/mypy/issues/21711">#21711</a>)</li>
<li><a
href="https://github.com/python/mypy/commit/cbcb51add3094ec91b29cdd4c624943bf251b63f"><code>cbcb51a</code></a>
Narrow for frozendict membership check (<a
href="https://redirect.github.com/python/mypy/issues/21709">#21709</a>)</li>
<li><a
href="https://github.com/python/mypy/commit/af2bc0f3cc7f2f129f0c11294158d0c292692c3d"><code>af2bc0f</code></a>
Sync typeshed (<a
href="https://redirect.github.com/python/mypy/issues/21707">#21707</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/python/mypy/compare/v2.1.0...v2.3.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `typing-extensions` from 4.15.0 to 4.16.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/python/typing_extensions/releases">typing-extensions's
releases</a>.</em></p>
<blockquote>
<h2>4.16.0</h2>
<p>No changes since 4.16.0rc2.</p>
<p>Changes since 4.15.0:</p>
<ul>
<li>Make <code>typing_extensions.TypeAliasType</code>'s
<code>__module__</code> attribute writable. Backport of CPython PR <a
href="https://redirect.github.com/python/cpython/pull/149172">#149172</a>.</li>
<li>Fix setting of <code>__required_keys__</code> and
<code>__optional_keys__</code> when inheriting keys with the same
name.</li>
<li>Add support for <code>AsyncIterator</code>, <code>io.Reader</code>,
<code>io.Writer</code> and <code>os.PathLike</code> protocols as bases
for other protocols.</li>
<li>Fix incorrect behaviour on Python 3.9 and Python 3.10 that meant
that calling <code>isinstance</code> with
<code>typing_extensions.Concatenate[...]</code> or
<code>typing_extensions.Unpack[...]</code> as the first argument could
have a different result in some situations depending on whether or not a
profiling function had been set using <code>sys.setprofile</code>. This
affected both CPython and PyPy implementations. Patch by Brian
Schubert.</li>
<li>Fix <code>__init_subclass__()</code> behavior in the presence of
multiple inheritance involving an <code>@deprecated</code>-decorated
base class. Backport of CPython PR <a
href="https://redirect.github.com/python/cpython/pull/138210">#138210</a>
by Brian Schubert.</li>
<li>Raise <code>TypeError</code> when attempting to subclass
<code>typing_extensions.ParamSpec</code> on Python 3.9. The
<code>typing</code> implementation has always raised an error, and the
<code>typing_extensions</code> implementation has raised an error on
Python 3.10+ since <code>typing_extensions</code> v4.6.0. Patch by Brian
Schubert.</li>
<li>Add the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code>, and <code>infer_variance</code> parameters
to <code>TypeVarTuple</code>.</li>
<li>Officially support the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code> and <code>infer_variance</code> parameters to
<code>ParamSpec</code>. Improve the validation of these parameters at
runtime.</li>
<li>Rename <code>typing_extensions.Sentinel</code> to
<code>typing_extensions.sentinel</code>, following the name that has
been adopted for <code>builtins.sentinel</code> on Python 3.15.
<code>typing_extensions.Sentinel</code> is retained as a soft-deprecated
alias for backwards compatibility.</li>
<li>Add support for pickling sentinels.</li>
<li>Sentinels now preserve their identity when copied or
deep-copied.</li>
<li>Deprecate passing <code>name</code> as a keyword argument or
<code>repr</code> as a positional argument to the <code>sentinel</code>
constructor.</li>
<li>The default repr of a sentinel <code>X =
sentinel(&quot;X&quot;)</code> is now <code>X</code> rather than
<code>&lt;X&gt;</code>.</li>
<li>Deprecate arbitrary attribute assignments to sentinels.</li>
<li>Deprecate subclassing sentinels.</li>
<li>Add support for Python 3.15.</li>
<li>Avoid a <code>DeprecationWarning</code> when <code>deprecated</code>
is applied to a coroutine function on Python 3.14.0.</li>
</ul>
<h2>4.16.0rc2</h2>
<p>Changes since 4.16.0rc1:</p>
<ul>
<li>Avoid a <code>DeprecationWarning</code> when <code>deprecated</code>
is applied to a coroutine function on Python 3.14.0.</li>
</ul>
<p>Changes since 4.15.0:</p>
<ul>
<li>Make <code>typing_extensions.TypeAliasType</code>'s
<code>__module__</code> attribute writable. Backport of CPython PR <a
href="https://redirect.github.com/python/cpython/pull/149172">#149172</a>.</li>
<li>Fix setting of <code>__required_keys__</code> and
<code>__optional_keys__</code> when inheriting keys with the same
name.</li>
<li>Add support for <code>AsyncIterator</code>, <code>io.Reader</code>,
<code>io.Writer</code> and <code>os.PathLike</code> protocols as bases
for other protocols.</li>
<li>Fix incorrect behaviour on Python 3.9 and Python 3.10 that meant
that calling <code>isinstance</code> with
<code>typing_extensions.Concatenate[...]</code> or
<code>typing_extensions.Unpack[...]</code> as the first argument could
have a different result in some situations depending on whether or not a
profiling function had been set using <code>sys.setprofile</code>. This
affected both CPython and PyPy implementations. Patch by Brian
Schubert.</li>
<li>Fix <code>__init_subclass__()</code> behavior in the presence of
multiple inheritance involving an <code>@deprecated</code>-decorated
base class. Backport of CPython PR <a
href="https://redirect.github.com/python/cpython/pull/138210">#138210</a>
by Brian Schubert.</li>
<li>Raise <code>TypeError</code> when attempting to subclass
<code>typing_extensions.ParamSpec</code> on Python 3.9. The
<code>typing</code> implementation has always raised an error, and the
<code>typing_extensions</code> implementation has raised an error on
Python 3.10+ since <code>typing_extensions</code> v4.6.0. Patch by Brian
Schubert.</li>
<li>Add the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code>, and <code>infer_variance</code> parameters
to <code>TypeVarTuple</code>.</li>
<li>Officially support the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code> and <code>infer_variance</code> parameters to
<code>ParamSpec</code>. Improve the validation of these parameters at
runtime.</li>
<li>Rename <code>typing_extensions.Sentinel</code> to
<code>typing_extensions.sentinel</code>, following the name that has
been adopted for <code>builtins.sentinel</code> on Python 3.15.
<code>typing_extensions.Sentinel</code> is retained as a soft-deprecated
alias for backwards compatibility.</li>
<li>Add support for pickling sentinels.</li>
<li>Sentinels now preserve their identity when copied or
deep-copied.</li>
<li>Deprecate passing <code>name</code> as a keyword argument or
<code>repr</code> as a positional argument to the <code>sentinel</code>
constructor.</li>
<li>The default repr of a sentinel <code>X =
sentinel(&quot;X&quot;)</code> is now <code>X</code> rather than
<code>&lt;X&gt;</code>.</li>
<li>Deprecate arbitrary attribute assignments to sentinels.</li>
<li>Deprecate subclassing sentinels.</li>
<li>Add support for Python 3.15.</li>
</ul>
<h2>4.16.0rc1</h2>
<ul>
<li>Make <code>typing_extensions.TypeAliasType</code>'s
<code>__module__</code> attribute writable. Backport of CPython PR <a
href="https://redirect.github.com/python/cpython/pull/149172">#149172</a>.</li>
<li>Fix setting of <code>__required_keys__</code> and
<code>__optional_keys__</code> when inheriting keys with the same
name.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/python/typing_extensions/blob/main/CHANGELOG.md">typing-extensions's
changelog</a>.</em></p>
<blockquote>
<h1>Release 4.16.0 (July 2, 2025)</h1>
<p>No user-facing changes since 4.16.0rc2.</p>
<h1>Release 4.16.0rc2 (June 25, 2026)</h1>
<ul>
<li>Avoid a <code>DeprecationWarning</code> when <code>deprecated</code>
is applied to a coroutine function on
Python 3.14.0.</li>
</ul>
<h1>Release 4.16.0rc1 (June 24, 2026)</h1>
<ul>
<li>Make <code>typing_extensions.TypeAliasType</code>'s
<code>__module__</code> attribute writable.
Backport of CPython PR
<a
href="https://redirect.github.com/python/cpython/pull/149172">#149172</a>.</li>
<li>Fix setting of <code>__required_keys__</code> and
<code>__optional_keys__</code> when inheriting
keys with the same name.</li>
<li>Add support for <code>AsyncIterator</code>, <code>io.Reader</code>,
<code>io.Writer</code> and <code>os.PathLike</code> protocols
as bases for other protocols.</li>
<li>Fix incorrect behaviour on Python 3.9 and Python 3.10 that meant
that
calling <code>isinstance</code> with
<code>typing_extensions.Concatenate[...]</code> or
<code>typing_extensions.Unpack[...]</code> as the first argument could
have a different
result in some situations depending on whether or not a profiling
function had been
set using <code>sys.setprofile</code>. This affected both CPython and
PyPy implementations.
Patch by Brian Schubert.</li>
<li>Fix <code>__init_subclass__()</code> behavior in the presence of
multiple inheritance involving
an <code>@deprecated</code>-decorated base class. Backport of CPython PR
<a
href="https://redirect.github.com/python/cpython/pull/138210">#138210</a>
by Brian Schubert.</li>
<li>Raise <code>TypeError</code> when attempting to subclass
<code>typing_extensions.ParamSpec</code> on
Python 3.9. The <code>typing</code> implementation has always raised an
error, and the
<code>typing_extensions</code> implementation has raised an error on
Python 3.10+ since
<code>typing_extensions</code> v4.6.0. Patch by Brian Schubert.</li>
<li>Add the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code>, and <code>infer_variance</code> parameters
to <code>TypeVarTuple</code>.</li>
<li>Officially support the <code>bound</code>, <code>covariant</code>,
<code>contravariant</code> and <code>infer_variance</code>
parameters to <code>ParamSpec</code>. Improve the validation of these
parameters at runtime.</li>
<li>Rename <code>typing_extensions.Sentinel</code> to
<code>typing_extensions.sentinel</code>, following the
name that has been adopted for <code>builtins.sentinel</code> on Python
3.15.
<code>typing_extensions.Sentinel</code> is retained as a soft-deprecated
alias for backwards
compatibility.</li>
<li>Add support for pickling sentinels.</li>
<li>Sentinels now preserve their identity when copied or
deep-copied.</li>
<li>Deprecate passing <code>name</code> as a keyword argument or
<code>repr</code> as a positional argument
to the <code>sentinel</code> constructor.</li>
<li>The default repr of a sentinel <code>X =
sentinel(&quot;X&quot;)</code> is now <code>X</code> rather than
<code>&lt;X&gt;</code>.</li>
<li>Deprecate arbitrary attribute assignments to sentinels.</li>
<li>Deprecate subclassing sentinels.</li>
<li>Add support for Python 3.15.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/python/typing_extensions/commit/f29cd28d8ed7642cafb1d18daf5aa41be6a5c0aa"><code>f29cd28</code></a>
Prepare relase 4.16.0 (<a
href="https://redirect.github.com/python/typing_extensions/issues/774">#774</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/43174610ec0c407ce05ad750077c4e62b9192b2b"><code>4317461</code></a>
Bump version to 4.16.0rc2.dev (<a
href="https://redirect.github.com/python/typing_extensions/issues/772">#772</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/4f71098e5be84798d36416bbca0e776223ee40f9"><code>4f71098</code></a>
Prepare release 4.16.0rc2 (<a
href="https://redirect.github.com/python/typing_extensions/issues/771">#771</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/37ed08a11f3b7c05234f8963ab97e3ebdbdc16a2"><code>37ed08a</code></a>
Remove use of <code>asyncio.coroutines.iscoroutinefunction()</code> (<a
href="https://redirect.github.com/python/typing_extensions/issues/769">#769</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/8dcc5594cbe5a4e348245fea6ce160ce93ed6601"><code>8dcc559</code></a>
Improve <code>TypedDict</code> documentation (<a
href="https://redirect.github.com/python/typing_extensions/issues/770">#770</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/224f8d50551d26f0d603093596c3a47a7302a46f"><code>224f8d5</code></a>
Post-release followups for 3.16.0rc1 (<a
href="https://redirect.github.com/python/typing_extensions/issues/767">#767</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/777de3eb5f4562e2054d1d7ce707f098b1f4fd2f"><code>777de3e</code></a>
Prepare release 4.16.0rc1 (<a
href="https://redirect.github.com/python/typing_extensions/issues/766">#766</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/890be90f1545e7d5fa904dfa3154d5f03c96782c"><code>890be90</code></a>
Type variable tuple variance (<a
href="https://redirect.github.com/python/typing_extensions/issues/741">#741</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/0e0545866d78458b668dc52d2edc411f6e39540d"><code>0e05458</code></a>
Pin SQLAlchemy third-party tests to pytest==9.0.3 (<a
href="https://redirect.github.com/python/typing_extensions/issues/765">#765</a>)</li>
<li><a
href="https://github.com/python/typing_extensions/commit/d2777468c274202ec290103b34313e50cf040229"><code>d277746</code></a>
docs: add version compatibility table (<a
href="https://redirect.github.com/python/typing_extensions/issues/733">#733</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/python/typing_extensions/compare/4.15.0...4.16.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `syrupy` from 5.3.4 to 5.5.3
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/syrupy-project/syrupy/releases">syrupy's
releases</a>.</em></p>
<blockquote>
<h2>v5.5.3</h2>
<h2>What's Changed</h2>
<p>This release has no functional changes. It just fixes an issue where
the release tag pointed to the previous commit instead of the commit
with the updated pyproject.toml (see <a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1144">syrupy-project/syrupy#1144</a>).</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.2...v5.5.3">https://github.com/syrupy-project/syrupy/compare/v5.5.2...v5.5.3</a></p>
<h2>v5.5.2</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: Fix detecting <code>pytest-xdist</code> when loaded via
<code>PYTEST_PLUGINS</code> by <a
href="https://github.com/mgorny"><code>@​mgorny</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1142">syrupy-project/syrupy#1142</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/mgorny"><code>@​mgorny</code></a> made
their first contribution in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1142">syrupy-project/syrupy#1142</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.1...v5.5.2">https://github.com/syrupy-project/syrupy/compare/v5.5.1...v5.5.2</a></p>
<h2>v5.5.1</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: Defer registering <code>pytest-xdist</code> hook
<code>pytest_testnodedown</code> to avoid &quot;unknown hook&quot; error
by <a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1140">syrupy-project/syrupy#1140</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>
made their first contribution in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1140">syrupy-project/syrupy#1140</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.0...v5.5.1">https://github.com/syrupy-project/syrupy/compare/v5.5.0...v5.5.1</a></p>
<h2>v5.5.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat: detect unused snapshots under pytest-xdist by <a
href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1132">syrupy-project/syrupy#1132</a></li>
</ul>
<blockquote>
<p><strong>NOTE</strong>: Test suites using pytest-xdist that previously
passed due to incomplete snapshot support may now fail if unused
snapshots are detected. You can use <code>--snapshot-warn-unused</code>
to downgrade unused snapshot detection from an error to a warning though
it's not recommended.</p>
</blockquote>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.4.0...v5.5.0">https://github.com/syrupy-project/syrupy/compare/v5.4.0...v5.5.0</a></p>
<h2>v5.4.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat: add --snapshot-no-cleanup to keep unused snapshots on update
by <a href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1126">syrupy-project/syrupy#1126</a></li>
<li>fix: honor boolean operators in -k snapshot selection by <a
href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1127">syrupy-project/syrupy#1127</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.3.4...v5.4.0">https://github.com/syrupy-project/syrupy/compare/v5.3.4...v5.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/syrupy-project/syrupy/blob/main/CHANGELOG.md">syrupy's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v5.5.3">v5.5.3</a>
(2026-07-11)</h2>
<h2>What's Changed</h2>
<ul>
<li>chore(deps): update astral-sh/setup-uv action to v8.3.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1143">syrupy-project/syrupy#1143</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v8.3.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1145">syrupy-project/syrupy#1145</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1147">syrupy-project/syrupy#1147</a></li>
<li>chore(deps): update dependency mypy to v2.2.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1148">syrupy-project/syrupy#1148</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.3 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1150">syrupy-project/syrupy#1150</a></li>
<li>chore: closes <a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1144">#1144</a>
by <a href="https://github.com/noahnu"><code>@​noahnu</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1146">syrupy-project/syrupy#1146</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v8.3.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1149">syrupy-project/syrupy#1149</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.2...v5.5.3">https://github.com/syrupy-project/syrupy/compare/v5.5.2...v5.5.3</a></p>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v5.5.2">v5.5.2</a>
(2026-07-08)</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: Fix detecting <code>pytest-xdist</code> when loaded via
<code>PYTEST_PLUGINS</code> by <a
href="https://github.com/mgorny"><code>@​mgorny</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1142">syrupy-project/syrupy#1142</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/mgorny"><code>@​mgorny</code></a> made
their first contribution in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1142">syrupy-project/syrupy#1142</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.1...v5.5.2">https://github.com/syrupy-project/syrupy/compare/v5.5.1...v5.5.2</a></p>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v5.5.1">v5.5.1</a>
(2026-07-06)</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: Defer registering <code>pytest-xdist</code> hook
<code>pytest_testnodedown</code> to avoid &quot;unknown hook&quot; error
by <a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1140">syrupy-project/syrupy#1140</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>
made their first contribution in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1140">syrupy-project/syrupy#1140</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.0...v5.5.1">https://github.com/syrupy-project/syrupy/compare/v5.5.0...v5.5.1</a></p>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v5.5.0">v5.5.0</a>
(2026-07-06)</h2>
<h2>What's Changed</h2>
<ul>
<li>feat: detect unused snapshots under pytest-xdist by <a
href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1132">syrupy-project/syrupy#1132</a></li>
</ul>
<blockquote>
<p><strong>NOTE</strong>: Test suites using pytest-xdist that previously
passed due to incomplete snapshot support may now fail if unused
snapshots are detected. You can use <code>--snapshot-warn-unused</code>
to downgrade unused snapshot detection from an error to a warning though
it's not recommended.</p>
</blockquote>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.4.0...v5.5.0">https://github.com/syrupy-project/syrupy/compare/v5.4.0...v5.5.0</a></p>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v5.4.0">v5.4.0</a>
(2026-07-01)</h2>
<h2>What's Changed</h2>
<ul>
<li>feat: add --snapshot-no-cleanup to keep unused snapshots on update
by <a href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1126">syrupy-project/syrupy#1126</a></li>
<li>fix: honor boolean operators in -k snapshot selection by <a
href="https://github.com/frenck"><code>@​frenck</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1127">syrupy-project/syrupy#1127</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/3cd347306cf44db076d2e4f50f7dfd325d9b5a92"><code>3cd3473</code></a>
chore(release): 5.5.3 [skip ci]</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/fed7e9f69f4dd14b39360e626236c868147588d5"><code>fed7e9f</code></a>
chore(deps): update astral-sh/setup-uv action to v8.3.2 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1149">#1149</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/443fc11bf67ce588753cd4518ef056463cfe651b"><code>443fc11</code></a>
chore: closes <a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1144">#1144</a>
(<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1146">#1146</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/56bf157ce4135bde78ecc49cfa9532ffa41659e8"><code>56bf157</code></a>
chore(deps): update dependency hypothesis to v6.156.3 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1150">#1150</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/f9c725a5653677bfcafb53645c9a078f3aa79d87"><code>f9c725a</code></a>
chore(deps): update dependency mypy to v2.2.0 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1148">#1148</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/3af2ccf2feeadb3a0d4e3f418d22ad3395725c80"><code>3af2ccf</code></a>
chore(deps): update dependency hypothesis to v6.156.2 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1147">#1147</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/feaa22ca4c211dfcdd8d0d048112531fd6cb344c"><code>feaa22c</code></a>
chore(deps): update astral-sh/setup-uv action to v8.3.1 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1145">#1145</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/5c59701e411922a464497398f5df25d76f2f9dcd"><code>5c59701</code></a>
chore(deps): update astral-sh/setup-uv action to v8.3.0 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1143">#1143</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/1cbf7167ff114e3012b1c139661777c1a0b692ee"><code>1cbf716</code></a>
chore(release): 5.5.2 [skip ci]</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/4f83490d2ebf4ae22aeba6d9946979640151aa34"><code>4f83490</code></a>
fix: Fix detecting <code>pytest-xdist</code> when loaded via
<code>PYTEST_PLUGINS</code> (<a href="https://redi...

_Description has been truncated_

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Mason Daugherty <mason@langchain.dev>
Co-authored-by: Mason Daugherty <github@mdrxy.com>
2026-08-03 10:08:53 -04:00
dependabot[bot] a303f846a4 chore: bump the minor-and-patch group with 3 updates (#39183)
Bumps the minor-and-patch group with 3 updates:
[actions/checkout](https://github.com/actions/checkout),
[pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish)
and
[aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials).

Updates `actions/checkout` from 7.0.0 to 7.0.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/releases">actions/checkout's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.1</h2>
<h2>What's Changed</h2>
<ul>
<li>skip running unsafe pr check if input is default by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
<li>trim only ascii whitespace for branch by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
<li>escape values passed to --unset by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
<li>Various dependency updates</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v7...v7.0.1">https://github.com/actions/checkout/compare/v7...v7.0.1</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v7.0.1</h2>
<ul>
<li>Skip running unsafe pr check if input is default by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
<li>Trim only ascii whitespace for branch by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
<li>Escape values passed to --unset by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v7.0.0</h2>
<ul>
<li>Block checking out fork PR for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v6.0.3</h2>
<ul>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<h2>v6.0.2</h2>
<ul>
<li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
</ul>
<h2>v6.0.1</h2>
<ul>
<li>Add worktree support for persist-credentials includeIf by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
</ul>
<h2>v6.0.0</h2>
<ul>
<li>Persist creds to a separate file by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
<li>Update README to include Node.js 24 support details and requirements
by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
</ul>
<h2>v5.0.1</h2>
<ul>
<li>Port v6 cleanup to v5 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
</ul>
<h2>v5.0.0</h2>
<ul>
<li>Update actions checkout to use node 24 by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
</ul>
<h2>v4.3.1</h2>
<ul>
<li>Port v6 cleanup to v4 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
</ul>
<h2>v4.3.0</h2>
<ul>
<li>docs: update README.md by <a
href="https://github.com/motss"><code>@​motss</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
<li>Add internal repos for checking out multiple repositories by <a
href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
<li>Documentation update - add recommended permissions to Readme by <a
href="https://github.com/benwells"><code>@​benwells</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
<li>Adjust positioning of user email note and permissions heading by <a
href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
<li>Update README.md by <a
href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
<li>Update CODEOWNERS for actions by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
<li>Update package dependencies by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
</ul>
<h2>v4.2.2</h2>
<ul>
<li><code>url-helper.ts</code> now leverages well-known environment
variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
<li>Expand unit test coverage for <code>isGhes</code> by <a
href="https://github.com/jww3"><code>@​jww3</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
</ul>
<h2>v4.2.1</h2>
<ul>
<li>Check out other refs/* by commit if provided, fall back to ref by <a
href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1"><code>3d3c42e</code></a>
prep v7.0.1 release (<a
href="https://redirect.github.com/actions/checkout/issues/2531">#2531</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07"><code>2880268</code></a>
escape values passed to --unset (<a
href="https://redirect.github.com/actions/checkout/issues/2530">#2530</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1"><code>12cd223</code></a>
trim only ascii whitespace for branch (<a
href="https://redirect.github.com/actions/checkout/issues/2521">#2521</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541"><code>62661c4</code></a>
skip running unsafe pr check if input is default (<a
href="https://redirect.github.com/actions/checkout/issues/2518">#2518</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f"><code>e8d4307</code></a>
Bump the minor-actions-dependencies group with 2 updates (<a
href="https://redirect.github.com/actions/checkout/issues/2499">#2499</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87"><code>631c942</code></a>
eslint 9 (<a
href="https://redirect.github.com/actions/checkout/issues/2474">#2474</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e"><code>4f1f4ae</code></a>
Bump actions/upload-artifact from 4 to 7 (<a
href="https://redirect.github.com/actions/checkout/issues/2476">#2476</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92"><code>ba09753</code></a>
Bump actions/checkout from 6 to 7 (<a
href="https://redirect.github.com/actions/checkout/issues/2488">#2488</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22"><code>b9e0990</code></a>
Bump docker/login-action from 3.3.0 to 4.2.0 (<a
href="https://redirect.github.com/actions/checkout/issues/2479">#2479</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2"><code>e8cb398</code></a>
Bump docker/build-push-action from 6.5.0 to 7.2.0 (<a
href="https://redirect.github.com/actions/checkout/issues/2478">#2478</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1">compare
view</a></li>
</ul>
</details>
<br />

Updates `pypa/gh-action-pypi-publish` from 1.14.0 to 1.14.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pypa/gh-action-pypi-publish/releases">pypa/gh-action-pypi-publish's
releases</a>.</em></p>
<blockquote>
<h2>v1.14.2</h2>
<!-- raw HTML omitted -->
<h2>🛠️ Urgh… Another release!? Again? Explain yourself!</h2>
<p>Looking at the diff, you'll only witness updates across the
dependency tree. That's it! It's not a security fix or anything like
that even, no. But you'll want this update.</p>
<blockquote>
<p>[!tip]
So what <em>most</em> people will find useful is <a
href="https://github.com/takluyver"><code>@​takluyver</code></a><a
href="https://github.com/sponsors/takluyver">💰</a>'s update of Twine to
v7 that we use internally (<a
href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416">#416</a>).
This version will let them upload their sdists and wheels containing
core packaging metadata v2.5 to (Test)PyPI.</p>
</blockquote>
<h2>🧐 Tell me why..</h2>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
<p>TL;DR non-pure-python projects with C-extensions tend to have dozens
(sometimes hundreds) wheels to upload to PyPI per release. They are
often quite big and take time to transfer over the network. People
started noticing problems and coming up with DIY sharding workarounds
like <a
href="https://redirect.github.com/aio-libs/aiohttp/pull/13226">aio-libs/aiohttp#13226</a>
around July 23.
On this date, projects with a good amount of bytes to publish would
start getting timeouts 5 minutes after the PyPI publishing job begun.
The same job that worked just fine before.</p>
<p>I had to start pinging upstream library and ecosystem people, on
GitHub and privately, to start making sense of what was happening.
Eventually, we collectively concluded that GitHub must've shortened the
lifetime of their OIDC identity — it seems to have used to be 10 minutes
long (at some point in the past) and is now 5 minutes, apparently. It's
not documented clearly, and we have not been able to get any clarity by
attempting to contact GitHub through private channels, using personal
connections.</p>
<p>Over the course of investigation, <a
href="https://github.com/facutuesca"><code>@​facutuesca</code></a><a
href="https://github.com/sponsors/facutuesca">💰</a> found and fixed a
related underlying cache invalidation bug in <a
href="https://redirect.github.com/sigstore/sigstore-python/pull/1838">sigstore/sigstore-python#1838</a>,
which he then coordinated propagation through the dependency chain
updates in sigstore-python, pypi-attestations, gh-action-pypi-publish
and gh-action-sigstore-python.</p>
<p>Mike's also discovered that Sigstore's Rekor slowdown seems to have
become the main contributing cause of the last week's incident. He's
collected some data to support this claim: <a
href="https://publishing-five-minute-timeout.tiiny.site">https://publishing-five-minute-timeout.tiiny.site</a>.</p>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
<h2>🫶 New Contributors</h2>
<ul>
<li><a
href="https://github.com/davidbrochart"><code>@​davidbrochart</code></a>
made their first contribution in <a
href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415">#415</a></li>
<li><a href="https://github.com/takluyver"><code>@​takluyver</code></a>
made their first contribution in <a
href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416">#416</a></li>
</ul>
<p><strong>🪞 Full Diff</strong>: <a
href="https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2">https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2</a></p>
<p><strong>🧔‍♂️ Release Manager:</strong> <a
href="https://github.com/sponsors/webknjaz"><code>@​webknjaz</code></a>
<a href="https://stand-with-ukraine.pp.ua">🇺🇦</a></p>
<p><strong>🙏 Special Thanks</strong> to <a
href="https://github.com/davidbrochart"><code>@​davidbrochart</code></a><a
href="https://github.com/sponsors/davidbrochart">💰</a> and <a
href="https://github.com/Dreamsorcerer"><code>@​Dreamsorcerer</code></a><a
href="https://github.com/sponsors/Dreamsorcerer">💰</a> for turning my
attention (in <a
href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415">#415</a>
and in private) to the newly surfaced corner case in GitHub's behavior
that only affected a narrow category of projects while many others
remained blissfully unaware. <a
href="https://github.com/bdraco"><code>@​bdraco</code></a><a
href="https://github.com/sponsors/bdraco">💰</a> came up with a DIY
sharding workaround for aiohttp that served as a demo for other
projects. <a
href="https://github.com/miketheman"><code>@​miketheman</code></a><a
href="https://github.com/sponsors/miketheman">💰</a> confirmed the
Warehouse-side details. Also, <a
href="https://github.com/jku"><code>@​jku</code></a><a
href="https://github.com/sponsors/jku">💰</a> and <a
href="https://github.com/woodruffw"><code>@​woodruffw</code></a><a
href="https://github.com/sponsors/woodruffw">💰</a> helped work through,
review and release the Sigstore ecosystem upstream libs.</p>
<p><strong>💬 Discuss</strong> <a
href="https://bsky.app/profile/did:plc:ve6s3mxkefjaxty3m4fdqumn/post/3mrsqy2xba22j">on
Bluesky 🦋</a>, <a
href="https://mastodon.social/@webknjaz/117005132816750073">on Mastodon
🐘</a> and [on GitHub][release discussion].</p>
<p>[![GH Sponsors badge]][GH Sponsors URL]</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pypa/gh-action-pypi-publish/commit/dc37677b2e1c63e2034f94d8a5b11f265b73ba33"><code>dc37677</code></a>
Merge pull request <a
href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/417">#417</a>
from trail-of-forks/ft/bump-deps</li>
<li><a
href="https://github.com/pypa/gh-action-pypi-publish/commit/8b2f23418f024937cf97f77534a597947105e772"><code>8b2f234</code></a>
Bump <code>pypi-attestations</code> and <code>sigstore</code></li>
<li><a
href="https://github.com/pypa/gh-action-pypi-publish/commit/78b72dbfed6e025eb89577c059edc936f8a2df14"><code>78b72db</code></a>
Merge pull request <a
href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416">#416</a>
from takluyver/twine-v7</li>
<li><a
href="https://github.com/pypa/gh-action-pypi-publish/commit/92f4d2a159875dd135a7e56b7b3262f502b23a13"><code>92f4d2a</code></a>
Update twine to v7</li>
<li><a
href="https://github.com/pypa/gh-action-pypi-publish/commit/ba38be9e461d3875417946c167d0b5f3d385a247"><code>ba38be9</code></a>
Merge pull request <a
href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/408">#408</a>
from adisivaprasad/bump-setup-python-v6</li>
<li><a
href="https://github.com/pypa/gh-action-pypi-publish/commit/a6c5088d60d08ef54b70075735d25df696e5ccaa"><code>a6c5088</code></a>
Bump actions/setup-python from v5.6.0 to v6.2.0</li>
<li>See full diff in <a
href="https://github.com/pypa/gh-action-pypi-publish/compare/cef221092ed1bacb1cc03d23a2d87d1d172e277b...dc37677b2e1c63e2034f94d8a5b11f265b73ba33">compare
view</a></li>
</ul>
</details>
<br />

Updates `aws-actions/configure-aws-credentials` from 6.2.1 to 6.2.3
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws-actions/configure-aws-credentials/releases">aws-actions/configure-aws-credentials's
releases</a>.</em></p>
<blockquote>
<h2>v6.2.3</h2>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.2...v6.2.3">6.2.3</a>
(2026-07-22)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>attach git credentials before Tag Major Version push (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1877">#1877</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/9ae780b171afa8c5a3a6a2d154a765b709492482">9ae780b</a>)</li>
<li>PackedPolicyTooLarge detection in STS tags (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1899">#1899</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/fa8d6a57bbf44b34439fb080bbdadc7c92c285eb">fa8d6a5</a>)</li>
</ul>
<h2>v6.2.2</h2>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.1...v6.2.2">6.2.2</a>
(2026-07-07)</h2>
<h3>Miscellaneous Chores</h3>
<ul>
<li>release 6.2.2 (<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/d01d678e65d6d2bd9d5ca7a95d6f07b00e25f2c2">d01d678</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md">aws-actions/configure-aws-credentials's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<p>All notable changes to this project will be documented in this file.
See <a
href="https://github.com/conventional-changelog/standard-version">standard-version</a>
for commit guidelines.</p>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.2...v6.2.3">6.2.3</a>
(2026-07-22)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>attach git credentials before Tag Major Version push (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1877">#1877</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/9ae780b171afa8c5a3a6a2d154a765b709492482">9ae780b</a>)</li>
<li>PackedPolicyTooLarge detection in STS tags (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1899">#1899</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/fa8d6a57bbf44b34439fb080bbdadc7c92c285eb">fa8d6a5</a>)</li>
</ul>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.1...v6.2.2">6.2.2</a>
(2026-07-07)</h2>
<h3>Miscellaneous Chores</h3>
<ul>
<li>release 6.2.2 (<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/d01d678e65d6d2bd9d5ca7a95d6f07b00e25f2c2">d01d678</a>)</li>
</ul>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.0...v6.2.1">6.2.1</a>
(2026-06-26)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>enforce allowed-account-ids on all auth paths (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1847">#1847</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/4d281fbc56a82e63c3fc14f2cc22361f34c97493">4d281fb</a>)</li>
</ul>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.1.3...v6.2.0">6.2.0</a>
(2026-06-01)</h2>
<h3>Features</h3>
<ul>
<li>add additional session tags by default (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1775">#1775</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/e0ba7685077379a14a82d01fefd511490344ebfc">e0ba768</a>)</li>
<li>add more retry logic and better logging (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1764">#1764</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/540d0c13aedb8d55501d220bd2f0b3cdedfe84e8">540d0c1</a>)</li>
<li>add regex validation to role-session-name (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1765">#1765</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/e35449909c6ede5083a48ba4b8bbfaaa1cf09ba1">e354499</a>)</li>
<li>Allow custom session tags to be passed when assuming a role (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1759">#1759</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/61f50f630f383628add73c1eab3f1935ba07da2b">61f50f6</a>)</li>
<li>expose run id in STS client user-agent (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1774">#1774</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/29d1be30273e7ef371d59fccf6ec54572c64ec89">29d1be3</a>)</li>
<li>support custom STS endpoints (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1762">#1762</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/8d52d05d7a4521fa52b39de50cb6114b12e5c332">8d52d05</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>skip credential check on output-env-credentials: false (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1778">#1778</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/58e7c47adf77846879008deadfeeef8a6969fe6c">58e7c47</a>)</li>
<li>assumeRole failing from session tag size too large (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1808">#1808</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/d6f5dc331b44474b19a52caaf85fa4d637b13c8e">d6f5dc3</a>)</li>
</ul>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.1.2...v6.1.3">6.1.3</a>
(2026-05-28)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>fix: allow kubelet token symlink in <a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1805">#1805</a></li>
</ul>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.1.1...v6.1.2">6.1.2</a>
(2026-05-26)</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/e6de054238d6b7531b4efff3b6587d9aade6a06c"><code>e6de054</code></a>
chore(main): release 6.2.3 (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1878">#1878</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/ab3b2ba025afb33b6856abfc1626992c70909302"><code>ab3b2ba</code></a>
chore: Update dist</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/fa8d6a57bbf44b34439fb080bbdadc7c92c285eb"><code>fa8d6a5</code></a>
fix: PackedPolicyTooLarge detection in STS tags (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1899">#1899</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/42e118a65655a9bcd2929e1ab7c4588fdd3255d3"><code>42e118a</code></a>
chore(deps-dev): bump markdownlint-cli from 0.49.0 to 0.49.1 (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1896">#1896</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/d86ddfcecc93d50cd1d1ca675d859403357c3d89"><code>d86ddfc</code></a>
chore: Update dist</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/874aaac21e617e1544df3c6a9f043c9bc96adf70"><code>874aaac</code></a>
chore(deps): bump <code>@​aws-sdk/client-sts</code> from 3.1086.0 to
3.1091.0 (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1892">#1892</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/d4341b65accaa2ddbb952380d8ef12f95043d338"><code>d4341b6</code></a>
chore: Update dist</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/fe51823c9714409fc32ade60b0bb4e79890beff1"><code>fe51823</code></a>
chore(deps-dev): bump <code>@​aws-sdk/credential-provider-env</code> (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1894">#1894</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/a8be382115e1ad5c77c560af842deddb56cd375c"><code>a8be382</code></a>
chore(deps-dev): bump <code>@​biomejs/biome</code> from 2.5.3 to 2.5.4
(<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1893">#1893</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/e000376c2c1f88ccef5f22a6bda02c24932d8ea5"><code>e000376</code></a>
chore: Update dist</li>
<li>Additional commits viewable in <a
href="https://github.com/aws-actions/configure-aws-credentials/compare/254c19bd240aabef8777f48595e9d2d7b972184b...e6de054238d6b7531b4efff3b6587d9aade6a06c">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-03 09:53:27 -04:00
dependabot[bot] 86c31677ef chore: bump actions/setup-python from 6.3.0 to 7.0.0 in the major group (#39184)
Bumps the major group with 1 update:
[actions/setup-python](https://github.com/actions/setup-python).

Updates `actions/setup-python` from 6.3.0 to 7.0.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-python/releases">actions/setup-python's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements</h3>
<ul>
<li>Migrate to ESM and upgrade dependencies by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-python/pull/1330">actions/setup-python#1330</a></li>
<li>Pin SHA commits and update docs with latest versions by <a
href="https://github.com/HarithaVattikuti"><code>@​HarithaVattikuti</code></a>
in <a
href="https://redirect.github.com/actions/setup-python/pull/1338">actions/setup-python#1338</a></li>
<li>Remove the pip-install input by <a
href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
<a
href="https://redirect.github.com/actions/setup-python/pull/1336">actions/setup-python#1336</a></li>
</ul>
<h3>Bug Fix</h3>
<ul>
<li>Fix to Classify stderr warning messages as warnings instead of
errors in annotations by <a
href="https://github.com/lmvysakh"><code>@​lmvysakh</code></a> in <a
href="https://redirect.github.com/actions/setup-python/pull/1335">actions/setup-python#1335</a></li>
<li>Validate and retry manifest fetch to prevent silent failures by <a
href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
in <a
href="https://redirect.github.com/actions/setup-python/pull/1332">actions/setup-python#1332</a></li>
</ul>
<h3>Dependency Upgrade</h3>
<ul>
<li>Bump certifi from 2020.6.20 to 2024.7.4 in
/<strong>tests</strong>/data by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
href="https://redirect.github.com/actions/setup-python/pull/1328">actions/setup-python#1328</a></li>
<li>Remove EOL Python versions and Bumps numpy text fixture by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-python/pull/1333">actions/setup-python#1333</a></li>
<li>Upgrade <code>@​actions/cache</code> to 6.2.0 by <a
href="https://github.com/philip-gai"><code>@​philip-gai</code></a> in <a
href="https://redirect.github.com/actions/setup-python/pull/1337">actions/setup-python#1337</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/lmvysakh"><code>@​lmvysakh</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-python/pull/1335">actions/setup-python#1335</a></li>
<li><a
href="https://github.com/philip-gai"><code>@​philip-gai</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-python/pull/1337">actions/setup-python#1337</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-python/compare/v6...v7.0.0">https://github.com/actions/setup-python/compare/v6...v7.0.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-python/commit/5fda3b95a4ea91299a34e894583c3862153e4b97"><code>5fda3b9</code></a>
Pin SHA commits and update docs with latest versions (<a
href="https://redirect.github.com/actions/setup-python/issues/1338">#1338</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/4ab7e95f05e168b4356aebde89dd84f59c283d8e"><code>4ab7e95</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/setup-python/issues/1337">#1337</a>
from actions/philip-gai/bump-actions-cache-6-2-0</li>
<li><a
href="https://github.com/actions/setup-python/commit/0f3a009f475dbea83c0371cd85d099690fee8c5c"><code>0f3a009</code></a>
Remove the pip-install input (<a
href="https://redirect.github.com/actions/setup-python/issues/1336">#1336</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/f8cf4291c8b8e273ddd26e569454615c7315d932"><code>f8cf429</code></a>
Migrate to ESM and upgrade dependencies (<a
href="https://redirect.github.com/actions/setup-python/issues/1330">#1330</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/54baeea5b34417d10a7479663a23cca53ea209b5"><code>54baeea</code></a>
Validate and retry manifest fetch to prevent silent failures (<a
href="https://redirect.github.com/actions/setup-python/issues/1332">#1332</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/c7092773a316760f4ecfe498e4af668a4dafeac5"><code>c709277</code></a>
Annotation code fix (<a
href="https://redirect.github.com/actions/setup-python/issues/1335">#1335</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/6849080452e69b330395e8a6d23cf90f56d76a1a"><code>6849080</code></a>
remove EOL Python versions and Bumps numpy text fixture (<a
href="https://redirect.github.com/actions/setup-python/issues/1333">#1333</a>)</li>
<li><a
href="https://github.com/actions/setup-python/commit/0903b469fbf4441aadfe4f4b249dc5b1fba3a73e"><code>0903b46</code></a>
Bump certifi from 2020.6.20 to 2024.7.4 in /<strong>tests</strong>/data
(<a
href="https://redirect.github.com/actions/setup-python/issues/1328">#1328</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/setup-python/compare/ece7cb06caefa5fff74198d8649806c4678c61a1...5fda3b95a4ea91299a34e894583c3862153e4b97">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-python&package-manager=github_actions&previous-version=6.3.0&new-version=7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-03 09:52:49 -04:00
github-actions[bot] af06896544 chore(deps): bump uv to 0.12.1 (#39190)
Bumps the uv pin in `.github/actions/uv_setup/action.yml` from `0.12.0`
to [`0.12.1`](https://github.com/astral-sh/uv/releases/tag/0.12.1).

Opened automatically by `bump_uv_pin.yml`. Mirror availability on
`releases.astral.sh` was verified before this PR was created, so CI
should not race the fallback.

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-03 09:52:15 -04:00
langchain-oss-model-profiles[bot]andmdrxy f8703d85b9 chore(model-profiles): refresh model profile data (#39166)
Automated refresh of model profile data for all in-monorepo partner
integrations via `langchain-profiles refresh`.

🤖 Generated by the [`refresh_model_profiles`
workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml).

## Summary of changes

**10 added · 5 removed · 14 changed** across 6 provider(s).

<details>
<summary>deepseek</summary>

**✏️ 1 changed**
- `deepseek-v4-flash`: last updated `2026-04-24` → `2026-07-31`; release
date `2026-04-24` → `2026-07-31`

</details>

<details>
<summary>fireworks-ai</summary>

**➕ 1 added**
- `accounts/fireworks/models/deepseek-v4-flash-0731` — 1,000,000 ctx,
384,000 out, reasoning, tools

</details>

<details>
<summary>huggingface</summary>

**➕ 3 added**
- `tencent/Hy3` — 262,144 ctx, 64,000 out, reasoning, tools
- `thinkingmachines/Inkling` — 1,048,576 ctx, 1,048,576 out, text+image
in, reasoning, tools
- `thinkingmachines/Inkling-Small` — 524,288 ctx, 1,048,576 out,
text+image in, reasoning, tools

</details>

<details>
<summary>mistral</summary>

**➕ 3 added**
- `voxtral-mini-latest` — text+audio in
- `voxtral-mini-tts-latest`
- `voxtral-small-latest` — 32,000 ctx, 32,000 out, text+audio in, tools

</details>

<details>
<summary>openrouter</summary>

**➕ 3 added**
- `deepseek/deepseek-v4-flash-0731` — 1,048,576 ctx, 65,536 out,
reasoning, tools
- `thinkingmachines/inkling-small` — 524,288 ctx, 262,144 out,
text+image+audio in, reasoning, tools
- `~deepseek/deepseek-v4-flash-latest` — 1,048,576 ctx, 65,536 out,
reasoning, tools

**➖ 5 removed**
- `mistralai/devstral-2512`
- `openai/gpt-5-codex`
- `openai/gpt-5.1-chat`
- `openai/o3-deep-research`
- `openai/o4-mini-deep-research`

**✏️ 12 changed**
- `anthropic/claude-opus-5`: removed temperature control
- `google/gemini-3.1-flash-lite-image`: max output tokens 66,000 →
65,536
- `nvidia/nemotron-3-nano-30b-a3b`: max output tokens 228,000 → 262,144
- `qwen/qwen3-30b-a3b`: removed structured output
- `qwen/qwen3-coder-30b-a3b-instruct`: max output tokens 32,768 →
262,144
- `qwen/qwen3-vl-30b-a3b-instruct`: max output tokens 16,384 → 32,768
- `qwen/qwen3.7-flash`: last updated `2026-07-27` → `2026-07-15`;
release date `2026-07-27` → `2026-07-15`
- `qwen/qwen3.7-max`: max output tokens 65,536 → 131,072
- `qwen/qwen3.7-plus`: max output tokens 65,536 → 131,072
- `sakana/fugu-ultra`: last updated `2026-06-24` → `2026-06-15`; release
date `2026-06-24` → `2026-06-15`
- `tencent/hy3-preview`: added structured output
- `thedrummer/unslopnemo-12b`: max input tokens 32,768 → 1,024,000

</details>

<details>
<summary>xai</summary>

**✏️ 1 changed**
- `grok-imagine-video-1.5`: added audio input; added text input

</details>

Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com>
2026-08-03 09:29:53 -04:00
ccurmeandSYED ALI ABBAS RAHIL dd60819770 fix(openai): filter langchain-generated content block IDs (#39209)
Co-authored-by: SYED ALI ABBAS RAHIL <76390003+RahilOp@users.noreply.github.com>
2026-08-02 18:01:05 -04:00
ccurmeandzerafachris 9f81e43cbe fix(openai): preserve Responses text options (#39204)
Co-authored-by: zerafachris <christopher.zerafa@blocklabs.io>
2026-08-02 16:59:32 -04:00
8034b64e66 fix(anthropic): preserve caller tool_choice (#39206)
Co-authored-by: Vanhci <vanhci@wanghanchaodeMac-mini.local>
Co-authored-by: suneeldk <suneelkaliyannan@gmail.com>
2026-08-02 16:58:11 -04:00
ccurmeandAnton Petnitsky cec553afcd fix(perplexity): preserve caller extra_body (#39203)
Co-authored-by: Anton Petnitsky <168552591+Mukller@users.noreply.github.com>
2026-08-02 16:56:03 -04:00
ccurmeandMiguel Ingram ffef4e7d05 fix(core): preserve OpenAI file blocks (#39205)
Co-authored-by: Miguel Ingram <miguel.ingram.research@gmail.com>
2026-08-02 16:53:35 -04:00
ccurmeandyassernamez03 f03de61f26 fix(core): document reserved argument names for tools (#39207)
Co-authored-by: yassernamez03 <99099773+yassernamez03@users.noreply.github.com>
2026-08-02 16:48:41 -04:00
ccurmeandonyx679 d6b0c82fde fix(core): handle injected args for subclasses of BaseTool (#39202)
Co-authored-by: onyx679 <126763931+onyx679@users.noreply.github.com>
2026-08-02 16:38:55 -04:00
ccurmeandindexedakki 576b6fa060 fix(core): respect include_injected=False with filter_args (#39200)
Co-authored-by: indexedakki <74480055+indexedakki@users.noreply.github.com>
2026-08-02 15:49:05 -04:00
698602eedf fix(langchain): propagate model middleware control flow (#39199)
Co-authored-by: Yigtwxx <156921875+Yigtwxx@users.noreply.github.com>
Co-authored-by: Saniyagupte <144199485+Saniyagupte@users.noreply.github.com>
2026-08-02 15:29:49 -04:00
John Kennedyandjkennedyvz 4cc6231785 fix(core): redact streaming callback options (#39179)
Credential-bearing model kwargs can be sanitized by an integration's
`_get_invocation_params`, but streaming callbacks also received the
original kwargs through `options`. This could expose remote MCP
credentials to callback handlers and persisted LangSmith traces even
when `invocation_params` was redacted.

Streaming and v3 streaming-event callbacks now construct `options` from
the integration-sanitized invocation parameters while the model
invocation continues to receive the original values. Sync and async
regression coverage verifies both callback redaction and provider
propagation.

## Release note

Streaming chat-model callbacks no longer receive unsanitized invocation
options when an integration redacts sensitive parameters.

This contribution was prepared with AI-agent assistance.

Co-authored-by: jkennedyvz <jkennedyvz@users.noreply.github.com>
2026-07-31 15:18:58 -07:00
Nick Hollon a78daf0233 fix(core): type text stream projections (#39170)
Types sync and async text stream projections as strings.
2026-07-31 14:49:02 -04:00
Nick Hollon ad97e5c04f fix(langchain): update Anthropic config test (#39172)
Updates the expected `ChatAnthropic` config for `user_profile_id`.
2026-07-31 10:25:16 -04:00
John Kennedy 725489f135 fix(openai): redact MCP authorization (#39155) 2026-07-30 18:20:34 -04:00
ccurme a1a1ad3bb3 feat(anthropic): add user_profile_id convenience attribute (#39148) 2026-07-30 11:40:51 -04:00
Mason Daugherty 447e45604f chore(infra): expand credential coverage in root .gitignore (#39147)
The root `.gitignore` covers `.env` files, `*.pem`/`*.key`/`*.crt`, and
`credentials.json`, but a number of common local credential files are
still stageable and easy to commit by accident — especially SSH private
keys, which usually have no extension, so the existing `*.key` pattern
never matches `id_rsa` or `id_ed25519`.

This adds ignores, all within the existing `# Environments` section,
for:

- **SSH private keys** — `id_rsa` / `id_dsa` / `id_ecdsa` / `id_ed25519`
and their `*_rsa` / `*_dsa` / `*_ecdsa` / `*_ed25519` counterparts. A
`!*.pub` negation keeps public keys (e.g. `id_rsa.pub`,
`deploy_ed25519.pub`) committable, since those are not secrets and are
sometimes checked in deliberately.
- **Keystores** — `*.p12`, `*.pfx`, `*.jks`.
- **Tokens, cookie jars, and git credential stores** — `token.json`,
`Cookies`, `Cookies.db`, `cookies.sqlite`, `cookies.txt`,
`.git-credentials`.

No source files are touched; this only narrows what `git add` will
stage.

## Verification

`git check-ignore` is authoritative here (grepping the file is not,
since patterns can come from multiple files).

Newly ignored (all `IGNORED`):

```text
IGNORED      id_rsa
IGNORED      id_dsa
IGNORED      id_ecdsa
IGNORED      id_ed25519
IGNORED      mykey_rsa
IGNORED      deploy_ed25519
IGNORED      x.p12
IGNORED      x.pfx
IGNORED      x.jks
IGNORED      token.json
IGNORED      Cookies
IGNORED      cookies.sqlite
IGNORED      cookies.txt
IGNORED      .git-credentials
```

Deliberately still committable (all NOT ignored):

```text
ok  id_rsa.pub
ok  deploy_ed25519.pub
ok  .env.example
```

The `!*.pub` negation is placed after the key patterns so it is not
re-matched, and `.env.example`'s existing `!.env.example` negation is
earlier in the file than every new pattern, so neither is re-ignored.
Finally, `git ls-files | git check-ignore --stdin` prints nothing,
confirming no already-tracked file is newly shadowed.
2026-07-30 11:27:08 -04:00
Mason Daugherty 9cd9684136 chore(infra): add missing LICENSE files to publishable packages (#39146)
`langchain-core` and a few other packages under `libs/` build their PyPI
sdists without a LICENSE file, so downstream redistributors have to
supply their own copy (the conda-forge `langchain-core` feedstock, for
example, keeps a manual `recipe/LICENSE` as a workaround).

Packages like `langchain-classic` and `langchain-anthropic` already ship
the license correctly because they have a `LICENSE` file in the package
directory that hatchling picks up by default. This brings the remaining
packages in line with that pattern by copying the repo-root MIT
`LICENSE` (verified byte-identical to the existing
`libs/langchain/LICENSE`) into the four package directories that lacked
one:

- `langchain-core`
- `langchain-model-profiles`
- `langchain-tests` (standard-tests)
- `langchain-text-splitters`

No `pyproject.toml` or build-config changes were needed — hatchling
includes a root-level `LICENSE` in the sdist automatically once the file
exists. All other package dirs (both `langchain` packages and every
`libs/partners/*`) already have one and were left untouched.

Verified by building each sdist with `uv build --sdist` and confirming
the file is in the tarball:

- `langchain_core-1.5.3.tar.gz` → `langchain_core-1.5.3/LICENSE`
- `langchain_model_profiles-0.0.6.tar.gz` →
`langchain_model_profiles-0.0.6/LICENSE`
- `langchain_tests-1.1.9.tar.gz` → `langchain_tests-1.1.9/LICENSE`
- `langchain_text_splitters-1.1.2.tar.gz` →
`langchain_text_splitters-1.1.2/LICENSE`

## Release note

The PyPI sdists for `langchain-core`, `langchain-model-profiles`,
`langchain-tests`, and `langchain-text-splitters` now include the MIT
`LICENSE` file.

---

🤖 This description was written with assistance from an AI agent.
2026-07-30 10:56:16 -04:00
ccurme 01d8481ae3 release(core): 1.5.3 (#39145) langchain-core==1.5.3 2026-07-30 10:40:19 -04:00
langchain-oss-model-profiles[bot]andmdrxy b8a6e36d3f chore(model-profiles): refresh model profile data (#39141)
Automated refresh of model profile data for all in-monorepo partner
integrations via `langchain-profiles refresh`.

🤖 Generated by the [`refresh_model_profiles`
workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml).

## Summary of changes

**0 added · 2 removed · 3 changed** across 1 provider(s).

### openrouter

**➖ 2 removed**
- `poolside/laguna-m.1`
- `poolside/laguna-m.1:free`

**✏️ 3 changed**
- `google/gemma-4-26b-a4b-it`: max output tokens 262,144 → 16,384
- `qwen/qwen3-max`: max output tokens 32,768 → 65,536
- `qwen/qwen3-max-thinking`: max output tokens 32,768 → 65,536

Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com>
2026-07-30 10:24:27 -04:00
ccurme cdca311de2 fix(core): fall back to LANGSMITH_API_KEY for gateway (#39115) 2026-07-28 20:59:08 -04:00
Mason Daugherty a5a8762436 ci: annotate uv bump workflow with PR links (#39112)
When the uv pin bump workflow opens a PR (or finds one already open),
the Actions run now shows a notice annotation with the PR URL.

---

Previously the URL only appeared buried in step stdout after `gh pr
create`, which made it easy to miss from the run page. This matches the
same change in deepagents.
2026-07-28 15:53:17 -04:00