mirror of
https://github.com/langchain-ai/langchain.git
synced 2026-10-05 09:25:14 +03:00
2e9616bf0d0467f50a9cff2a2c8f80fa4a09fbc6
16876
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
3f212e7a88 | feat(openai): support async tools (#40208) | ||
|
|
1a3d81756f |
feat(openai): support configuration_update (#40201)
|
||
|
|
aac7904ff4 |
chore(model-profiles): refresh model profile data (#40198)
Automated refresh of model profile data for all in-monorepo partner integrations via `langchain-profiles refresh`. 🤖 Generated by the [`refresh_model_profiles` workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml). ## Summary of changes **3 added · 0 removed · 9 changed** across 3 provider(s). <details> <summary>fireworks-ai</summary> **✏️ 2 changed** - `accounts/fireworks/models/glm-5p3`: last updated `2026-08-28` → `2026-09-04` - `accounts/fireworks/models/glm-5p3-flash`: last updated `2026-08-26` → `2026-09-04` </details> <details> <summary>huggingface</summary> **➕ 1 added** - `deepseek-ai/DeepSeek-V4-Flash-Vision-Exp` — 1,048,576 ctx, 384,000 out, text+image in, reasoning, tools </details> <details> <summary>openrouter</summary> **➕ 2 added** - `inclusionai/ling-3.0-flash-fin` — 262,144 ctx, 235,929 out, reasoning, tools - `nvidia/nemotron-3.5-content-safety` — 131,072 ctx, 117,964 out, text+image in, reasoning **✏️ 7 changed** - `deepseek/deepseek-chat`: max output tokens 16,000 → 16,384 - `deepseek/deepseek-chat-v3.1`: max output tokens 32,768 → 144,900 - `nvidia/nemotron-3-ultra-550b-a55b`: max output tokens 182,520 → 32,768 - `qwen/qwen2.5-vl-72b-instruct`: max output tokens 28,800 → 115,200 - `undi95/remm-slerp-l2-13b`: max output tokens 4,096 → 5,529 - `z-ai/glm-5.3`: max output tokens 131,072 → 262,144 - `~z-ai/glm-latest`: max output tokens 943,718 → 235,929 </details> Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com> |
||
|
|
0d50cbddd9 | docs: add openwiki (#40183) | ||
|
|
79cab2dc7f | release(anthropic): 1.7.1 (#40181) langchain-anthropic==1.7.1 langchain==1.4.0 | ||
|
|
1e6a4f0b45 |
chore(model-profiles): refresh model profile data (#40171)
Automated refresh of model profile data for all in-monorepo partner integrations via `langchain-profiles refresh`. 🤖 Generated by the [`refresh_model_profiles` workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml). ## Summary of changes **4 added · 0 removed · 11 changed** across 4 provider(s). <details> <summary>fireworks-ai</summary> **➕ 1 added** - `accounts/fireworks/models/deepseek-v4-flash-vision-exp` — 1,000,000 ctx, 384,000 out, text+image in, reasoning, tools </details> <details> <summary>huggingface</summary> **✏️ 1 changed** - `tencent/Hy3`: max output tokens 64,000 → 128,000 </details> <details> <summary>openai</summary> **✏️ 2 changed** - `gpt-5.2-chat-latest`: status unset → `deprecated` - `gpt-5.3-chat-latest`: status unset → `deprecated` </details> <details> <summary>openrouter</summary> **➕ 3 added** - `google/gemini-3.8-flash` — 1,048,576 ctx, 65,536 out, text+image+audio+video+pdf in, reasoning, tools - `meta/muse-spark-1.3` — 1,048,576 ctx, 943,718 out, text+image+audio+video+pdf in, reasoning, tools - `meta/muse-spark-1.3-contributor` — 1,048,576 ctx, 943,718 out, text+image+audio+video+pdf in, reasoning, tools **✏️ 8 changed** - `meta-llama/llama-3.3-70b-instruct`: max output tokens 115,200 → 16,384 - `meta/muse-glimmer-30b`: max output tokens 16,384 → 117,964 - `nvidia/nemotron-3-nano-30b-a3b`: max output tokens 228,000 → 235,929 - `nvidia/nemotron-3-ultra-550b-a55b`: max output tokens 32,768 → 182,520 - `qwen/qwen3.5-397b-a17b`: max output tokens 65,536 → 235,929 - `qwen/qwen3.8-2.4t-a95b`: max output tokens 131,072 → 262,144 - `z-ai/glm-4.6`: max output tokens 16,384 → 131,072 - `~z-ai/glm-flash-latest`: max output tokens 131,072 → 943,718 </details> Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com> |
||
|
|
8330dfe987 |
docs(langchain): runnable langchain.mcp examples (#39976)
Stacked on #39939 — review that first; this branch adds only `libs/langchain_v1/examples/mcp/`. Ten self-contained scripts, one idea each. Every one starts whatever MCP server it needs, so `uv run examples/mcp/<name>.py` is the whole workflow. | Example | Shows | Model | Network | |---|---|:-:|:-:| | `transports.py` | one adapter over in-memory, stdio, and HTTP | | | | `remote_server.py` | pointing the adapter at a public MCP server | ✅ | ✅ | | `multi_server.py` | several servers behind one adapter, tools prefixed per server | ✅ | | | `graph_factory.py` | one per-user MCP fleet behind a `langgraph dev` graph factory | ✅ | | | `protocol_eras.py` | one agent holding tools from both MCP protocol eras | ✅ | | | `tool_errors.py` | a failing tool reaching the model so it can retry | ✅ | | | `elicitation.py` | a server asking a human mid-call, via `interrupt()` | ✅ | | | `destructive_interrupt.py` | gating destructive tools behind approval, from tool metadata | ✅ | | | `auth_bearer.py` | a server behind a static bearer token | | | | `auth_oauth.py` | a full OAuth 2.1 flow with dynamic client registration | | | Each was run against a real model (or a real `langgraph dev` server) before committing, and its output is what the docstring claims. A few choices worth knowing about: - **Servers come from FastMCP's own `run_server_in_process`**, not hand-rolled uvicorn plumbing, so the examples teach the adapter rather than how to start a server. - **HTTP appears only where it is the subject.** `multi_server.py` names its backends over stdio, which is less machinery and a better illustration, since a fleet addresses each backend independently. - **`remote_server.py` hits DeepWiki**, a public MCP server, where the URL is the entire configuration. It prints the tool call so the answer is visibly the remote server's work rather than the model's memory. - **`tool_errors.py` pins the model with a system prompt.** Without it the model answers the arithmetic from memory and the error path never runs. - **`destructive_interrupt.py` derives the approval gate from metadata**, reading each tool's `metadata["mcp"]["tool"]["annotations"]["destructive_hint"]` to build the `HumanInTheLoopMiddleware` `interrupt_on` map — so any tool a server flags as destructive pauses for approval, no tool names hardcoded. - **`auth_oauth.py` opens a browser tab.** The demo authorization server auto-approves, so it redirects straight back — but it is the one example that cannot run unattended. `graph_factory.py` is registered by a `langgraph.json` and run under `langgraph dev` rather than invoked directly. It shows a per-user MCP fleet: one shared `httpx` connection pool for everyone, a per-user `ClientGroup` built each run, and per-user discovery caching keyed on the caller's identity read off the injected `ServerRuntime`. `run_graph_factory_demo.py` is an end-to-end driver that stands up two guarded MCP servers plus a `langgraph dev` server with custom auth and runs the graph once per user; `auth.py`, `langgraph.json`, and `_fleet_servers.py` support it. `_servers.py` holds the small MCP servers the examples share, `_stdio_server.py` is the entry point launched as a subprocess over stdio, and neither `_`-prefixed helper is part of the API being demonstrated. `examples/*` picks up the same two ruff exemptions `scripts/*` already has, for printing and for not being a package. ## Release note No library changes — examples only. --- *Prepared with the assistance of an AI agent.* --------- Co-authored-by: Hunter Lovell <hunter@hntrl.io> Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com> Co-authored-by: Sydney Runkle <sydney@langchain.dev> |
||
|
|
280442b54c |
feat(langchain): langchain.mcp namespace, MCPAdapter (#39939)
Adds `langchain.mcp`: adapt an MCP server into LangChain tools ready for
`create_agent`.
```python
from langchain.agents import create_agent
from langchain.mcp import MCPAdapter
adapter = MCPAdapter("https://example.com/mcp")
agent = create_agent("anthropic:claude-sonnet-5", await adapter.list_tools())
```
`langchain-mcp-adapters` stays the place for the full surface
(interceptors, callbacks, prompts, resources). This is the short path
for the common case.
## Public API
`MCPAdapter(target, *, elicitation=None)`, with a `client` property,
`list_tools(*, cache_mode="use")`, and async context management.
`as_langchain_tool(tool, client, *, elicitation=None)` converts a single
tool for callers managing their own client.
`MCPAdapter` accepts anything `fastmcp.Client` accepts — a URL, `Path`,
in-process server, `ClientTransport`, `MCPConfig` (or its dict form), or
a pre-built `Client` — plus a FastMCP `ClientGroup` for a fleet of
servers behind one client. Inference is FastMCP's, so new target types
work without changes here. The target union is `MCPAdapterTarget`; it is
not part of the package's public surface (it is only useful for
annotating a `target`), but it stays importable from
`langchain.mcp.adapter` for that purpose. An `MCPConfig` naming several
servers yields one prefixed toolset from one adapter:
```python
MCPAdapter({"mcpServers": {"notes": {"command": "python", "args": ["notes.py"]},
"web": {"url": "https://example.com/mcp"}}})
# -> ["notes_read_note", "web_get_weather", ...]
```
## Tool conversion
Tool results are ported from `langchain-mcp-adapters`, so a call reaches
a model in the same shape either way. Results become LangChain content
blocks (audio raises `NotImplementedError`); structured content becomes
an `MCPToolArtifact`; `args_schema` is the tool's `input_schema`.
Tool *metadata* is grouped under a single `mcp` namespace so a consumer
can tell an MCP tool's provenance apart and keep tool-level fields
distinct from the serving server's identity:
```python
tool.metadata == {
"mcp": {
"tool": {
"annotations": {"destructive_hint": True, ...}, # snake_case, from tool.annotations
"_meta": {...}, # verbatim MCP `_meta`
},
"server": {"name": "files", "version": "2.1.0", ...}, # from the live client connection
},
}
```
Server identity comes off the connection (a `Tool` carries no server
field) and is read at conversion time while the client is connected.
This metadata rides onto the LangChain tool's `metadata`, so it also
lands on the tool's traced run — `mcp.server.name` becomes filterable in
traces. The examples PR uses the destructive hint to gate a tool behind
human approval.
An `isError=True` result becomes a `ToolMessage` with `status="error"`
carrying the server's own error content, so the agent can correct itself
instead of the run ending. Transport failures and unconvertible content
still raise.
FastMCP clients are reentrant and reference-counted, so the adapter adds
no second layer — tools hold the client and stay callable after the
adapter's context exits.
## Discovery caching
`list_tools(cache_mode=...)` selects how discovery interacts with the
client-side response cache (SEP-2549): `use` (default) serves a cached
tool list within the server's TTL hint, `refresh` calls the server and
repopulates it, `bypass` skips the cache. The cache and its
per-principal isolation are configured on the client itself
(`Client(cache=...)`); this only selects how discovery reads it. The
default is `use` so a configured cache is honored — note this differs
from a bare `ClientGroup.list_tools()`, whose own default is `refresh`.
## Elicitation
Some MCP tools need input before they can finish.
`elicitation="interrupt"` surfaces the question as a LangGraph
interrupt:
```python
adapter = MCPAdapter(server, elicitation="interrupt")
paused = await agent.ainvoke({"messages": [...]}, config)
[question] = paused["__interrupt__"][0].value["requests"]
# {'key': 'date', 'message': 'What date would you like to book?', 'mode': 'form',
# 'requested_schema': {...}}
await agent.ainvoke(
Command(resume={"responses": {question["key"]: {"action": "accept", "content": {"date": "2026-08-26"}}}}),
config,
)
```
Answers correlate by the server's own request keys, so nothing extra is
needed on resume. Several requests in one round share one interrupt;
successive rounds each get their own. The payload types live in
`langchain.mcp.elicitation`, split so the type system carries the
protocol's rules: `mode` discriminates form from URL requests, and only
an accept can carry content, narrowed to the scalar shapes the wire
accepts.
It is opt-in because a declared capability is a promise on the wire —
servers only build flows that depend on it once a client says yes — so
left unset, a server whose tool *requires* an answer refuses the call
rather than running without one. The loop is driven through
`session.call_tool(..., allow_input_required=True)` rather than a
FastMCP handler, which would convert the `GraphInterrupt` into an MCP
error. Resuming re-issues the call from its first round, since the
interrupt unwound it; a server that asks before doing work repeats
nothing, which the tests assert by counting tool-body executions.
Scope is elicitation only. Embedded sampling and roots requests raise,
since driving the loop by hand bypasses the FastMCP callbacks that
answer them, as does a continuation round carrying only `request_state`
— that is the protocol's long-running-work channel, and serving it would
mean polling a remote server from inside a tool call.
## Building on FastMCP
Handing the client to FastMCP is what keeps this small. Most of the
protocol surface is inherited rather than written:
- **Negotiation, per server.** FastMCP speaks both the 2025-11-25
`initialize` handshake and the 2026-07-28 `server/discover` revision,
and picks per connection — so one agent can hold tools from servers on
different revisions at once, with no protocol mode to choose. There is a
test that builds exactly that agent.
- **Transports and auth.** Inference covers URLs, script paths,
in-process servers, and config dicts, while `auth="oauth"`, bearer
tokens, custom `httpx` auth, and TLS via `verify` all arrive without
code here.
- **Fleets.** A `ClientGroup` target lets one adapter serve a fleet of
servers, prefixing each server's tools and routing every call back to
the client that serves it.
- **Connection lifecycle.** Clients are reentrant and reference-counted,
so tools outlive the adapter's context without a second layer of
bookkeeping, and requests race the background session task so a dead
HTTP session raises instead of hanging a tool call.
- **The input-required flow (SEP-2322).** Elicitation intercepts a round
at the session layer instead of reimplementing the multi-round protocol.
- **In-process servers.** The whole unit suite drives real MCP servers
with no subprocess and no socket.
This requires `fastmcp>=4.0.0` — the GA line whose multi-server config
routes to modern-protocol servers, which the `MCPConfig` and
`ClientGroup` support rely on.
## Release note
New `langchain.mcp` namespace. `MCPAdapter` adapts any target
`fastmcp.Client` accepts — a URL, a local script, an in-process server,
an `MCPConfig` naming several servers, or a pre-built client — as well
as a FastMCP `ClientGroup`, into LangChain tools ready for
`create_agent`. `MCPAdapter.list_tools(cache_mode=...)` discovers tools
with optional client-side response caching. `as_langchain_tool` converts
a single MCP tool for callers managing their own client. Tool metadata
(annotations, `_meta`, and the serving server's identity) is grouped
under an `mcp` namespace on each tool. `elicitation="interrupt"`
surfaces a server's mid-call questions as LangGraph interrupts. Requires
the `mcp` extra: `pip install "langchain[mcp]"`.
## Notes for review
- A `Path` or script-path target launches a local subprocess with no
opt-in keyword. Intended, and the target comes from application code
rather than a model, but it loosens the previous default and is awkward
to walk back once released.
- Tool metadata is traced. Whatever a server puts in `_meta` reaches the
tool's LangSmith run verbatim; keeping it nested under `mcp.tool._meta`
(rather than flattened) keeps that clearly demarcated.
- Two FastMCP internals are load-bearing, and both now fail loudly
rather than silently. `elicitation="interrupt"` installs a sentinel
handler purely to trip the SDK's identity comparison against its default
callback, which is the only way the SDK lets a client declare the
capability; a test asserts the negotiated capability so a change
upstream cannot quietly stop servers asking. `_await_monitored` reaches
for FastMCP's private `_await_with_session_monitoring`, without which a
session dying mid-elicitation hangs the tool call; the fallback now
warns.
- `tests/unit_tests/mcp/conftest.py` grants `blockbuster` two narrow
allowances, both caused upstream in FastMCP: entering a server `Context`
resolves an optional dependency through `importlib.metadata` on every
in-process request, and `mcp.client.session` imports `jsonschema` lazily
on first tool call.
---
*Prepared with the assistance of an AI agent.*
---------
Signed-off-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
Co-authored-by: Hunter Lovell <hunter@hntrl.io>
Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
Co-authored-by: Sydney Runkle <sydney@langchain.dev>
|
||
|
|
f5ee2b65f4 |
chore(chroma): bump Pygments security constraint (#40162)
Chroma's development lock still selected Pygments 2.20.0, which is affected by a published security advisory. Raise the existing transitive dependency constraint to 2.21.0 and refresh the lockfile so development and CI environments select the patched release. The other recently reported Chroma lockfile dependencies were already updated on `master`, are no longer present in the current uv dependency graph, or do not yet have a compatible patched release. This contribution was prepared with an AI coding agent. Made by [Open SWE](https://openswe.vercel.app/agents/867a14a4-e0cb-53ec-bf1a-70edcb54e89e) Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
234255c1c7 |
chore(model-profiles): refresh model profile data (#40009)
Automated refresh of model profile data for all in-monorepo partner integrations via `langchain-profiles refresh`. 🤖 Generated by the [`refresh_model_profiles` workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml). ## Summary of changes **10 added · 11 removed · 27 changed** across 4 provider(s). <details> <summary>fireworks-ai</summary> **➕ 2 added** - `accounts/fireworks/models/glm-5p3` — 1,000,000 ctx, 131,072 out, reasoning, tools - `accounts/fireworks/models/glm-5p3-flash` — 1,000,000 ctx, 131,072 out, text+image+video+pdf in, reasoning, tools **➖ 3 removed** - `accounts/fireworks/models/deepseek-v4-flash` - `accounts/fireworks/models/gpt-oss-20b` - `accounts/fireworks/models/minimax-m2p7` **✏️ 4 changed** - `accounts/fireworks/models/deepseek-v4-pro`: attachments no → unset; audio input no → unset; audio output no → unset; image input no → unset; image output no → unset; last updated `2026-04-24` → unset; max input tokens 1,000,000 → unset; max output tokens 384,000 → unset; display name `DeepSeek V4 Pro` → unset; removed open weights; removed reasoning; release date `2026-04-24` → unset; removed structured output; removed temperature control; removed text input; removed text output; removed tool calling; video input no → unset; video output no → unset - `accounts/fireworks/routers/kimi-k2p6-fast`: removed attachments; audio input no → unset; audio output no → unset; removed image input; image output no → unset; last updated `2026-06-05` → unset; max input tokens 262,000 → unset; max output tokens 262,000 → unset; display name `Kimi K2.6 Fast` → unset; removed open weights; removed reasoning; release date `2026-04-17` → unset; removed temperature control; removed text input; removed text output; removed tool calling; video input no → unset; video output no → unset - `accounts/fireworks/routers/kimi-k2p6-turbo`: removed attachments; audio input no → unset; audio output no → unset; removed image input; image output no → unset; last updated `2026-04-17` → unset; max input tokens 262,000 → unset; max output tokens 262,000 → unset; display name `Kimi K2.6 Turbo` → unset; removed open weights; removed reasoning; release date `2026-04-17` → unset; removed temperature control; removed text input; removed text output; removed tool calling; video input no → unset; video output no → unset - `accounts/fireworks/routers/kimi-k2p7-code-fast`: removed attachments; audio input no → unset; audio output no → unset; removed image input; image output no → unset; last updated `2026-06-16` → unset; max input tokens 262,000 → unset; max output tokens 262,000 → unset; display name `Kimi K2.7 Code Fast` → unset; removed open weights; removed reasoning; release date `2026-06-12` → unset; removed temperature control; removed text input; removed text output; removed tool calling; video input no → unset; video output no → unset </details> <details> <summary>groq</summary> **➕ 1 added** - `qwen/qwen3.8-27b` — 131,042 ctx, 16,384 out, text+image in, reasoning, tools </details> <details> <summary>huggingface</summary> **➕ 1 added** - `zai-org/GLM-5.3` — 1,048,576 ctx, 131,072 out, reasoning, tools **✏️ 1 changed** - `zai-org/GLM-5.3-Flash`: added attachments; added image input </details> <details> <summary>openrouter</summary> **➕ 6 added** - `anthropic/claude-fable-5.1` — 1,000,000 ctx, 128,000 out, text+image+pdf in, reasoning, tools - `ibm-granite/granite-4.2-8b` — 131,072 ctx, 117,964 out, reasoning, tools - `inception/mercury-2.5-preview` — 260,000 ctx, 65,536 out, reasoning, tools - `inclusionai/ling-3.0-flash-fin:free` — 262,144 ctx, 32,768 out, reasoning, tools - `tencent/hy4-preview` — 1,048,576 ctx, 64,000 out, reasoning, tools - `~z-ai/glm-flash-latest` — 1,310,720 ctx, 131,072 out, text+image+video in, reasoning, tools **➖ 8 removed** - `allenai/olmo-3-32b-think` - `anthropic/claude-opus-4.7-fast` - `anthropic/claude-opus-4.8-fast` - `anthropic/claude-opus-5-fast` - `arcee-ai/virtuoso-large` - `kwaipilot/kat-coder-air-v2.5` - `mistralai/ministral-8b` - `thedrummer/rocinante-12b` **✏️ 22 changed** - `arcee-ai/trinity-large-thinking`: max output tokens 235,929 → 80,000; removed structured output - `deepseek/deepseek-chat-v3.1`: max output tokens 144,900 → 32,768 - `deepseek/deepseek-v3.2`: max output tokens 147,456 → 65,536 - `deepseek/deepseek-v4-flash-vision-exp`: added structured output - `deepseek/deepseek-v4-pro-0813`: max output tokens 943,717 → 384,000 - `google/gemma-3-27b-it`: max input tokens 262,144 → 131,072 - `kwaipilot/kat-coder-pro-v2`: max output tokens 80,000 → 144,000 - `kwaipilot/kat-coder-pro-v2.5`: max input tokens 256,000 → 262,144; max output tokens 80,000 → 235,929 - `meta-llama/llama-4-maverick`: max output tokens 16,384 → 115,200 - `meta-llama/llama-4-scout`: max output tokens 8,192 → 16,384 - `meta/muse-glimmer-30b`: max output tokens 117,964 → 16,384 - `mistralai/voxtral-small-24b-2507`: max input tokens 32,000 → 32,768; max output tokens 25,600 → 26,214 - `nvidia/nemotron-3-ultra-550b-a55b`: max input tokens 512,288 → 262,144; max output tokens 461,059 → 32,768 - `qwen/qwen3-vl-30b-a3b-instruct`: max output tokens 32,768 → 16,384 - `qwen/qwen3.5-122b-a10b`: max output tokens 235,929 → 81,920 - `qwen/qwen3.6-27b`: max output tokens 81,920 → 235,929 - `thinkingmachines/inkling`: max output tokens 262,144 → 471,859 - `z-ai/glm-5.1`: max output tokens 182,476 → 128,000 - `z-ai/glm-5.2`: max output tokens 262,144 → 131,072 - `z-ai/glm-5.3`: max input tokens 1,048,576 → 1,310,720; added open weights; added structured output - `~deepseek/deepseek-v4-flash-latest`: max output tokens 131,072 → 393,216 - `~z-ai/glm-latest`: max input tokens 1,048,576 → 1,310,720; max output tokens 131,072 → 943,718; added structured output </details> Made by [Open SWE](https://openswe.vercel.app/agents/756572b6-fcc8-59ee-bd9e-7d0c13386290) --------- Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
79e0e4adba |
chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/langchain (#40149)
Bumps [mistune](https://github.com/lepture/mistune) from 3.3.0 to 3.3.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lepture/mistune/releases">mistune's releases</a>.</em></p> <blockquote> <h2>v3.3.3</h2> <h3> 🐞 Bug Fixes</h3> <ul> <li>Set prev token in render_list_item and add block_text to ignore_blocks - by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a> in <a href="https://redirect.github.com/lepture/mistune/issues/456">lepture/mistune#456</a> <a href="https://github.com/lepture/mistune/commit/0799e19"><!-- raw HTML omitted -->(0799e)<!-- raw HTML omitted --></a></li> <li>Improve nested bracket link input - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/fe02f40"><!-- raw HTML omitted -->(fe02f)<!-- raw HTML omitted --></a></li> <li>Escape literal emphasis markers in MarkdownRenderer - by <a href="https://github.com/Sanjays2402"><code>@Sanjays2402</code></a> <a href="https://github.com/lepture/mistune/commit/b042996"><!-- raw HTML omitted -->(b0429)<!-- raw HTML omitted --></a></li> <li>Use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/4009f67"><!-- raw HTML omitted -->(4009f)<!-- raw HTML omitted --></a></li> <li>Add max_emphasis_depth - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/0938fb7"><!-- raw HTML omitted -->(0938f)<!-- raw HTML omitted --></a></li> <li>Add image max depth - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/cca5ee6"><!-- raw HTML omitted -->(cca5e)<!-- raw HTML omitted --></a></li> <li><strong>inline</strong>: Use original run length in emphasis multiple-of-3 rule - by <a href="https://github.com/greymoth-jp"><code>@greymoth-jp</code></a> and <strong>Claude Opus 4.8 (1M context)</strong> <a href="https://github.com/lepture/mistune/commit/2d26bc8"><!-- raw HTML omitted -->(2d26b)<!-- raw HTML omitted --></a></li> </ul> <h3> 🏎 Performance</h3> <ul> <li>Improve link label parsing performance - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/e001d51"><!-- raw HTML omitted -->(e001d)<!-- raw HTML omitted --></a></li> <li>Improve performance for math and formatting plugins - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/c2228a2"><!-- raw HTML omitted -->(c2228)<!-- raw HTML omitted --></a></li> <li>Improve for footnotes, ruby and spoiler - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/ae7e9d5"><!-- raw HTML omitted -->(ae7e9)<!-- raw HTML omitted --></a></li> </ul> <h5> <a href="https://github.com/lepture/mistune/compare/v3.3.2...v3.3.3">View changes on GitHub</a></h5> <h2>v3.3.2</h2> <h3> 🐞 Bug Fixes</h3> <ul> <li>Try to support python 3.8 - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/c9f1a54"><!-- raw HTML omitted -->(c9f1a)<!-- raw HTML omitted --></a></li> <li>Resolve mypy issues for python 3.8 and 3.9+ - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/29b70a9"><!-- raw HTML omitted -->(29b70)<!-- raw HTML omitted --></a></li> </ul> <h5> <a href="https://github.com/lepture/mistune/compare/v3.3.1...v3.3.2">View changes on GitHub</a></h5> <h2>v3.3.1</h2> <h3> 🐞 Bug Fixes</h3> <ul> <li><strong>abbr</strong>: Update process_text method in abrr, adding parse_emphasis parameter - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/ae850f5"><!-- raw HTML omitted -->(ae850)<!-- raw HTML omitted --></a></li> <li><strong>directive</strong>: Use correct file path for include directive - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/18c21d7"><!-- raw HTML omitted -->(18c21)<!-- raw HTML omitted --></a></li> </ul> <h5> <a href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.1">View changes on GitHub</a></h5> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/lepture/mistune/blob/main/docs/changes.rst">mistune's changelog</a>.</em></p> <blockquote> <h2>Version 3.3.3</h2> <p><strong>Released on Jul 9, 2026</strong></p> <ul> <li>Limit deeply nested emphasis and image parsing to avoid <code>RecursionError</code>.</li> <li>Fix repeated link suffix and unclosed formatting marker performance issues.</li> <li>Fix unclosed inline spoiler performance issues.</li> <li>Avoid recursive parsing for adjacent ruby tokens.</li> <li>Speed up footnote reference indexing.</li> </ul> <h2>Version 3.3.2</h2> <p><strong>Released on Jun 23, 2026</strong></p> <ul> <li>Fix Python 3.8 import compatibility in the inline parser.</li> <li>Fix mypy compatibility for list parsing on Python 3.8 and 3.9+.</li> </ul> <h2>Version 3.3.1</h2> <p><strong>Released on Jun 22, 2026</strong></p> <ul> <li>Fix <code>abbr</code> plugin compatibility with escaped inline text.</li> <li>Normalize included Markdown line endings before parsing directives.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/lepture/mistune/commit/060f73ac87e8cf6d9e9b48f2df28c0654d845a4c"><code>060f73a</code></a> chore: release 3.3.3</li> <li><a href="https://github.com/lepture/mistune/commit/ae7e9d571f621b82b287ed98d421893dab87b018"><code>ae7e9d5</code></a> perf: improve for footnotes, ruby and spoiler</li> <li><a href="https://github.com/lepture/mistune/commit/c2228a25ddf66baf73e452edd42bde778c1ce61a"><code>c2228a2</code></a> perf: improve performance for math and formatting plugins</li> <li><a href="https://github.com/lepture/mistune/commit/e001d513a6f57c8a6ed08afcf6217c7dbd74e349"><code>e001d51</code></a> perf: improve link label parsing performance</li> <li><a href="https://github.com/lepture/mistune/commit/cca5ee6d17a458b115d5e63ab95ddedcfb7a15e4"><code>cca5ee6</code></a> fix: add image max depth</li> <li><a href="https://github.com/lepture/mistune/commit/0938fb781d0aded99de801b340ec1f8debeae5b2"><code>0938fb7</code></a> fix: add max_emphasis_depth</li> <li><a href="https://github.com/lepture/mistune/commit/9946c9207d74a55eed872483ab3c9cdc698b89cc"><code>9946c92</code></a> tests: update dealine time for pypy</li> <li><a href="https://github.com/lepture/mistune/commit/4009f67afc674225bbb3aa901614946feebfe4c9"><code>4009f67</code></a> fix: use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS</li> <li><a href="https://github.com/lepture/mistune/commit/30255494bc8fdd14c7a0fd5b0e2c5fc3d4243745"><code>3025549</code></a> Merge pull request <a href="https://redirect.github.com/lepture/mistune/issues/462">#462</a> from Sanjays2402/fix/markdown-renderer-escape-emphasis</li> <li><a href="https://github.com/lepture/mistune/commit/b042996659275aa9719d6efa37163bea62b34cd5"><code>b042996</code></a> fix: escape literal emphasis markers in MarkdownRenderer</li> <li>Additional commits viewable in <a href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.3">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
e90201b7af |
chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (#40150)
Bumps [mistune](https://github.com/lepture/mistune) from 3.3.0 to 3.3.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lepture/mistune/releases">mistune's releases</a>.</em></p> <blockquote> <h2>v3.3.3</h2> <h3> 🐞 Bug Fixes</h3> <ul> <li>Set prev token in render_list_item and add block_text to ignore_blocks - by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a> in <a href="https://redirect.github.com/lepture/mistune/issues/456">lepture/mistune#456</a> <a href="https://github.com/lepture/mistune/commit/0799e19"><!-- raw HTML omitted -->(0799e)<!-- raw HTML omitted --></a></li> <li>Improve nested bracket link input - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/fe02f40"><!-- raw HTML omitted -->(fe02f)<!-- raw HTML omitted --></a></li> <li>Escape literal emphasis markers in MarkdownRenderer - by <a href="https://github.com/Sanjays2402"><code>@Sanjays2402</code></a> <a href="https://github.com/lepture/mistune/commit/b042996"><!-- raw HTML omitted -->(b0429)<!-- raw HTML omitted --></a></li> <li>Use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/4009f67"><!-- raw HTML omitted -->(4009f)<!-- raw HTML omitted --></a></li> <li>Add max_emphasis_depth - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/0938fb7"><!-- raw HTML omitted -->(0938f)<!-- raw HTML omitted --></a></li> <li>Add image max depth - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/cca5ee6"><!-- raw HTML omitted -->(cca5e)<!-- raw HTML omitted --></a></li> <li><strong>inline</strong>: Use original run length in emphasis multiple-of-3 rule - by <a href="https://github.com/greymoth-jp"><code>@greymoth-jp</code></a> and <strong>Claude Opus 4.8 (1M context)</strong> <a href="https://github.com/lepture/mistune/commit/2d26bc8"><!-- raw HTML omitted -->(2d26b)<!-- raw HTML omitted --></a></li> </ul> <h3> 🏎 Performance</h3> <ul> <li>Improve link label parsing performance - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/e001d51"><!-- raw HTML omitted -->(e001d)<!-- raw HTML omitted --></a></li> <li>Improve performance for math and formatting plugins - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/c2228a2"><!-- raw HTML omitted -->(c2228)<!-- raw HTML omitted --></a></li> <li>Improve for footnotes, ruby and spoiler - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/ae7e9d5"><!-- raw HTML omitted -->(ae7e9)<!-- raw HTML omitted --></a></li> </ul> <h5> <a href="https://github.com/lepture/mistune/compare/v3.3.2...v3.3.3">View changes on GitHub</a></h5> <h2>v3.3.2</h2> <h3> 🐞 Bug Fixes</h3> <ul> <li>Try to support python 3.8 - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/c9f1a54"><!-- raw HTML omitted -->(c9f1a)<!-- raw HTML omitted --></a></li> <li>Resolve mypy issues for python 3.8 and 3.9+ - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/29b70a9"><!-- raw HTML omitted -->(29b70)<!-- raw HTML omitted --></a></li> </ul> <h5> <a href="https://github.com/lepture/mistune/compare/v3.3.1...v3.3.2">View changes on GitHub</a></h5> <h2>v3.3.1</h2> <h3> 🐞 Bug Fixes</h3> <ul> <li><strong>abbr</strong>: Update process_text method in abrr, adding parse_emphasis parameter - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/ae850f5"><!-- raw HTML omitted -->(ae850)<!-- raw HTML omitted --></a></li> <li><strong>directive</strong>: Use correct file path for include directive - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/18c21d7"><!-- raw HTML omitted -->(18c21)<!-- raw HTML omitted --></a></li> </ul> <h5> <a href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.1">View changes on GitHub</a></h5> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/lepture/mistune/blob/main/docs/changes.rst">mistune's changelog</a>.</em></p> <blockquote> <h2>Version 3.3.3</h2> <p><strong>Released on Jul 9, 2026</strong></p> <ul> <li>Limit deeply nested emphasis and image parsing to avoid <code>RecursionError</code>.</li> <li>Fix repeated link suffix and unclosed formatting marker performance issues.</li> <li>Fix unclosed inline spoiler performance issues.</li> <li>Avoid recursive parsing for adjacent ruby tokens.</li> <li>Speed up footnote reference indexing.</li> </ul> <h2>Version 3.3.2</h2> <p><strong>Released on Jun 23, 2026</strong></p> <ul> <li>Fix Python 3.8 import compatibility in the inline parser.</li> <li>Fix mypy compatibility for list parsing on Python 3.8 and 3.9+.</li> </ul> <h2>Version 3.3.1</h2> <p><strong>Released on Jun 22, 2026</strong></p> <ul> <li>Fix <code>abbr</code> plugin compatibility with escaped inline text.</li> <li>Normalize included Markdown line endings before parsing directives.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/lepture/mistune/commit/060f73ac87e8cf6d9e9b48f2df28c0654d845a4c"><code>060f73a</code></a> chore: release 3.3.3</li> <li><a href="https://github.com/lepture/mistune/commit/ae7e9d571f621b82b287ed98d421893dab87b018"><code>ae7e9d5</code></a> perf: improve for footnotes, ruby and spoiler</li> <li><a href="https://github.com/lepture/mistune/commit/c2228a25ddf66baf73e452edd42bde778c1ce61a"><code>c2228a2</code></a> perf: improve performance for math and formatting plugins</li> <li><a href="https://github.com/lepture/mistune/commit/e001d513a6f57c8a6ed08afcf6217c7dbd74e349"><code>e001d51</code></a> perf: improve link label parsing performance</li> <li><a href="https://github.com/lepture/mistune/commit/cca5ee6d17a458b115d5e63ab95ddedcfb7a15e4"><code>cca5ee6</code></a> fix: add image max depth</li> <li><a href="https://github.com/lepture/mistune/commit/0938fb781d0aded99de801b340ec1f8debeae5b2"><code>0938fb7</code></a> fix: add max_emphasis_depth</li> <li><a href="https://github.com/lepture/mistune/commit/9946c9207d74a55eed872483ab3c9cdc698b89cc"><code>9946c92</code></a> tests: update dealine time for pypy</li> <li><a href="https://github.com/lepture/mistune/commit/4009f67afc674225bbb3aa901614946feebfe4c9"><code>4009f67</code></a> fix: use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS</li> <li><a href="https://github.com/lepture/mistune/commit/30255494bc8fdd14c7a0fd5b0e2c5fc3d4243745"><code>3025549</code></a> Merge pull request <a href="https://redirect.github.com/lepture/mistune/issues/462">#462</a> from Sanjays2402/fix/markdown-renderer-escape-emphasis</li> <li><a href="https://github.com/lepture/mistune/commit/b042996659275aa9719d6efa37163bea62b34cd5"><code>b042996</code></a> fix: escape literal emphasis markers in MarkdownRenderer</li> <li>Additional commits viewable in <a href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4240248e7b |
chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/text-splitters (#40148)
Bumps [mistune](https://github.com/lepture/mistune) from 3.3.0 to 3.3.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lepture/mistune/releases">mistune's releases</a>.</em></p> <blockquote> <h2>v3.3.3</h2> <h3> 🐞 Bug Fixes</h3> <ul> <li>Set prev token in render_list_item and add block_text to ignore_blocks - by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a> in <a href="https://redirect.github.com/lepture/mistune/issues/456">lepture/mistune#456</a> <a href="https://github.com/lepture/mistune/commit/0799e19"><!-- raw HTML omitted -->(0799e)<!-- raw HTML omitted --></a></li> <li>Improve nested bracket link input - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/fe02f40"><!-- raw HTML omitted -->(fe02f)<!-- raw HTML omitted --></a></li> <li>Escape literal emphasis markers in MarkdownRenderer - by <a href="https://github.com/Sanjays2402"><code>@Sanjays2402</code></a> <a href="https://github.com/lepture/mistune/commit/b042996"><!-- raw HTML omitted -->(b0429)<!-- raw HTML omitted --></a></li> <li>Use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/4009f67"><!-- raw HTML omitted -->(4009f)<!-- raw HTML omitted --></a></li> <li>Add max_emphasis_depth - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/0938fb7"><!-- raw HTML omitted -->(0938f)<!-- raw HTML omitted --></a></li> <li>Add image max depth - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/cca5ee6"><!-- raw HTML omitted -->(cca5e)<!-- raw HTML omitted --></a></li> <li><strong>inline</strong>: Use original run length in emphasis multiple-of-3 rule - by <a href="https://github.com/greymoth-jp"><code>@greymoth-jp</code></a> and <strong>Claude Opus 4.8 (1M context)</strong> <a href="https://github.com/lepture/mistune/commit/2d26bc8"><!-- raw HTML omitted -->(2d26b)<!-- raw HTML omitted --></a></li> </ul> <h3> 🏎 Performance</h3> <ul> <li>Improve link label parsing performance - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/e001d51"><!-- raw HTML omitted -->(e001d)<!-- raw HTML omitted --></a></li> <li>Improve performance for math and formatting plugins - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/c2228a2"><!-- raw HTML omitted -->(c2228)<!-- raw HTML omitted --></a></li> <li>Improve for footnotes, ruby and spoiler - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/ae7e9d5"><!-- raw HTML omitted -->(ae7e9)<!-- raw HTML omitted --></a></li> </ul> <h5> <a href="https://github.com/lepture/mistune/compare/v3.3.2...v3.3.3">View changes on GitHub</a></h5> <h2>v3.3.2</h2> <h3> 🐞 Bug Fixes</h3> <ul> <li>Try to support python 3.8 - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/c9f1a54"><!-- raw HTML omitted -->(c9f1a)<!-- raw HTML omitted --></a></li> <li>Resolve mypy issues for python 3.8 and 3.9+ - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/29b70a9"><!-- raw HTML omitted -->(29b70)<!-- raw HTML omitted --></a></li> </ul> <h5> <a href="https://github.com/lepture/mistune/compare/v3.3.1...v3.3.2">View changes on GitHub</a></h5> <h2>v3.3.1</h2> <h3> 🐞 Bug Fixes</h3> <ul> <li><strong>abbr</strong>: Update process_text method in abrr, adding parse_emphasis parameter - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/ae850f5"><!-- raw HTML omitted -->(ae850)<!-- raw HTML omitted --></a></li> <li><strong>directive</strong>: Use correct file path for include directive - by <a href="https://github.com/lepture"><code>@lepture</code></a> <a href="https://github.com/lepture/mistune/commit/18c21d7"><!-- raw HTML omitted -->(18c21)<!-- raw HTML omitted --></a></li> </ul> <h5> <a href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.1">View changes on GitHub</a></h5> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/lepture/mistune/blob/main/docs/changes.rst">mistune's changelog</a>.</em></p> <blockquote> <h2>Version 3.3.3</h2> <p><strong>Released on Jul 9, 2026</strong></p> <ul> <li>Limit deeply nested emphasis and image parsing to avoid <code>RecursionError</code>.</li> <li>Fix repeated link suffix and unclosed formatting marker performance issues.</li> <li>Fix unclosed inline spoiler performance issues.</li> <li>Avoid recursive parsing for adjacent ruby tokens.</li> <li>Speed up footnote reference indexing.</li> </ul> <h2>Version 3.3.2</h2> <p><strong>Released on Jun 23, 2026</strong></p> <ul> <li>Fix Python 3.8 import compatibility in the inline parser.</li> <li>Fix mypy compatibility for list parsing on Python 3.8 and 3.9+.</li> </ul> <h2>Version 3.3.1</h2> <p><strong>Released on Jun 22, 2026</strong></p> <ul> <li>Fix <code>abbr</code> plugin compatibility with escaped inline text.</li> <li>Normalize included Markdown line endings before parsing directives.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/lepture/mistune/commit/060f73ac87e8cf6d9e9b48f2df28c0654d845a4c"><code>060f73a</code></a> chore: release 3.3.3</li> <li><a href="https://github.com/lepture/mistune/commit/ae7e9d571f621b82b287ed98d421893dab87b018"><code>ae7e9d5</code></a> perf: improve for footnotes, ruby and spoiler</li> <li><a href="https://github.com/lepture/mistune/commit/c2228a25ddf66baf73e452edd42bde778c1ce61a"><code>c2228a2</code></a> perf: improve performance for math and formatting plugins</li> <li><a href="https://github.com/lepture/mistune/commit/e001d513a6f57c8a6ed08afcf6217c7dbd74e349"><code>e001d51</code></a> perf: improve link label parsing performance</li> <li><a href="https://github.com/lepture/mistune/commit/cca5ee6d17a458b115d5e63ab95ddedcfb7a15e4"><code>cca5ee6</code></a> fix: add image max depth</li> <li><a href="https://github.com/lepture/mistune/commit/0938fb781d0aded99de801b340ec1f8debeae5b2"><code>0938fb7</code></a> fix: add max_emphasis_depth</li> <li><a href="https://github.com/lepture/mistune/commit/9946c9207d74a55eed872483ab3c9cdc698b89cc"><code>9946c92</code></a> tests: update dealine time for pypy</li> <li><a href="https://github.com/lepture/mistune/commit/4009f67afc674225bbb3aa901614946feebfe4c9"><code>4009f67</code></a> fix: use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS</li> <li><a href="https://github.com/lepture/mistune/commit/30255494bc8fdd14c7a0fd5b0e2c5fc3d4243745"><code>3025549</code></a> Merge pull request <a href="https://redirect.github.com/lepture/mistune/issues/462">#462</a> from Sanjays2402/fix/markdown-renderer-escape-emphasis</li> <li><a href="https://github.com/lepture/mistune/commit/b042996659275aa9719d6efa37163bea62b34cd5"><code>b042996</code></a> fix: escape literal emphasis markers in MarkdownRenderer</li> <li>Additional commits viewable in <a href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
530290a9d4 |
chore(deps): bump uv to 0.12.8 (#40092)
Bumps the uv pin in `.github/actions/uv_setup/action.yml` from `0.12.1` to [`0.12.8`](https://github.com/astral-sh/uv/releases/tag/0.12.8). Opened automatically by `bump_uv_pin.yml`. Mirror availability on `releases.astral.sh` was verified before this PR was created, so CI should not race the fallback. Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> |
||
|
|
1eeca8c318 |
chore(deps): bump the minor-and-patch group across 3 directories with 5 updates (#40085)
Bumps the minor-and-patch group with 1 update in the /libs/model-profiles directory: [ruff](https://github.com/astral-sh/ruff). Bumps the minor-and-patch group with 2 updates in the /libs/standard-tests directory: [ruff](https://github.com/astral-sh/ruff) and [pytest-benchmark](https://github.com/ionelmc/pytest-benchmark). Bumps the minor-and-patch group with 4 updates in the /libs/text-splitters directory: [ruff](https://github.com/astral-sh/ruff), [ty](https://github.com/astral-sh/ty), [spacy](https://github.com/explosion/spaCy) and [transformers](https://github.com/huggingface/transformers). Updates `ruff` from 0.16.4 to 0.16.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.5</h2> <h2>Release Notes</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> <h2>Install ruff 0.16.5</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1 | iex" </code></pre> <h2>Download ruff 0.16.5</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.5</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a> Bump 0.16.5 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a> Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a> Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a> Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a> Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a> Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a> [ty] Infer lambda parameters through callable type aliases (<a href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a> [ty] Narrow functional enum members in <code>==</code> and <code>match</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a> [ty] Intersection simplifications with subtype-related generic specialization...</li> <li><a href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a> [ty] Bump ecosystem-analyzer for HTML escaping (<a href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.4 to 0.16.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.5</h2> <h2>Release Notes</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> <h2>Install ruff 0.16.5</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1 | iex" </code></pre> <h2>Download ruff 0.16.5</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.5</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a> Bump 0.16.5 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a> Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a> Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a> Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a> Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a> Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a> [ty] Infer lambda parameters through callable type aliases (<a href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a> [ty] Narrow functional enum members in <code>==</code> and <code>match</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a> [ty] Intersection simplifications with subtype-related generic specialization...</li> <li><a href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a> [ty] Bump ecosystem-analyzer for HTML escaping (<a href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.4 to 0.16.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.5</h2> <h2>Release Notes</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> <h2>Install ruff 0.16.5</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1 | iex" </code></pre> <h2>Download ruff 0.16.5</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.5</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a> Bump 0.16.5 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a> Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a> Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a> Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a> Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a> Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a> [ty] Infer lambda parameters through callable type aliases (<a href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a> [ty] Narrow functional enum members in <code>==</code> and <code>match</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a> [ty] Intersection simplifications with subtype-related generic specialization...</li> <li><a href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a> [ty] Bump ecosystem-analyzer for HTML escaping (<a href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.4 to 0.16.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.5</h2> <h2>Release Notes</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> <h2>Install ruff 0.16.5</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1 | iex" </code></pre> <h2>Download ruff 0.16.5</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.5</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a> Bump 0.16.5 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a> Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a> Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a> Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a> Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a> Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a> [ty] Infer lambda parameters through callable type aliases (<a href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a> [ty] Narrow functional enum members in <code>==</code> and <code>match</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a> [ty] Intersection simplifications with subtype-related generic specialization...</li> <li><a href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a> [ty] Bump ecosystem-analyzer for HTML escaping (<a href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare view</a></li> </ul> </details> <br /> Updates `pytest-benchmark` from 5.2.3 to 5.3.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ionelmc/pytest-benchmark/releases">pytest-benchmark's releases</a>.</em></p> <blockquote> <h2>v5.3.0</h2> <ul> <li>Added <code>--benchmark-precision</code> and <code>--benchmark-confidence</code>: instead of a fixed number of rounds, stop once the mean's relative margin of error falls below the given fraction. Contributed by Aarni Koskela in <a href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/318">ionelmc/pytest-benchmark#318</a>.</li> <li>Added compare <code>--between</code> mode. Example: <code>pytest-benchmark compare --between=min 0001 0002</code>. Contributed by Aarni Koskela in <a href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/302">ionelmc/pytest-benchmark#302</a>.</li> <li>Modernized the CI/linting and added spellchecking. Contributed by Aarni Koskela in <a href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/304">ionelmc/pytest-benchmark#304</a>, <a href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/306">ionelmc/pytest-benchmark#306</a> and <a href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/319">ionelmc/pytest-benchmark#319</a>.</li> <li>Defer the xdist auto-disable warning until a benchmark fixture is collected. Contributed by xlyyddy in <a href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/317">ionelmc/pytest-benchmark#317</a> (fixes <a href="https://redirect.github.com/ionelmc/pytest-benchmark/issues/65">ionelmc/pytest-benchmark#65</a>).</li> <li>Replaced deprecated <code>argparse.FileType</code>. Contributed by Sophia Castellarin in <a href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/310">ionelmc/pytest-benchmark#310</a>.</li> <li>Fixed various spelling/typos. Contributed by Daniel Holth and Hugo van Kemenade in <a href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/297">ionelmc/pytest-benchmark#297</a> and <a href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/299">ionelmc/pytest-benchmark#299</a>.</li> <li>Cleaned up various dead code. Contributed by Hugo van Kemenade in <a href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/300">ionelmc/pytest-benchmark#300</a> and <a href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/301">ionelmc/pytest-benchmark#301</a>.</li> <li>CI now tests only with latest Pytest (now 9.1.1), Python 3.10-3.14 and PyPy 3.11.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/ionelmc/pytest-benchmark/blob/master/CHANGELOG.rst">pytest-benchmark's changelog</a>.</em></p> <blockquote> <h2>v5.3.0 (2026-08-23)</h2> <ul> <li>Added <code>--benchmark-precision</code> and <code>--benchmark-confidence</code>: instead of a fixed number of rounds, stop once the mean's relative margin of error falls below the given fraction. Contributed by Aarni Koskela in <code>[#318](https://github.com/ionelmc/pytest-benchmark/issues/318) <https://github.com/ionelmc/pytest-benchmark/pull/318></code>_.</li> <li>Added <code>compare --between</code> mode. Example: <code>pytest-benchmark compare --between=min 0001 0002</code>. Contributed by Aarni Koskela in <code>[#302](https://github.com/ionelmc/pytest-benchmark/issues/302) <https://github.com/ionelmc/pytest-benchmark/pull/302></code>_.</li> <li>Modernized the CI/linting and added spellchecking. Contributed by Aarni Koskela in <code>[#304](https://github.com/ionelmc/pytest-benchmark/issues/304) <https://github.com/ionelmc/pytest-benchmark/pull/304></code><em>, <code>[#306](https://github.com/ionelmc/pytest-benchmark/issues/306) <https://github.com/ionelmc/pytest-benchmark/pull/306></code></em> and <code>[#319](https://github.com/ionelmc/pytest-benchmark/issues/319) <https://github.com/ionelmc/pytest-benchmark/pull/319></code>_.</li> <li>Defer the xdist auto-disable warning until a benchmark fixture is collected. Contributed by xlyyddy in <code>[#317](https://github.com/ionelmc/pytest-benchmark/issues/317) <https://github.com/ionelmc/pytest-benchmark/pull/317></code>_ (fixes <code>[#65](https://github.com/ionelmc/pytest-benchmark/issues/65) <https://github.com/ionelmc/pytest-benchmark/issues/65></code>_).</li> <li>Replaced deprecated argparse.FileType. Contributed by Sophia Castellarin in <code>[#310](https://github.com/ionelmc/pytest-benchmark/issues/310) <https://github.com/ionelmc/pytest-benchmark/pull/310></code>_.</li> <li>Fixed various spelling/typos. Contributed by Daniel Holth and Hugo van Kemenade in <code>[#297](https://github.com/ionelmc/pytest-benchmark/issues/297) <https://github.com/ionelmc/pytest-benchmark/pull/297></code>_ and <code>[#299](https://github.com/ionelmc/pytest-benchmark/issues/299) <https://github.com/ionelmc/pytest-benchmark/pull/299></code>_.</li> <li>Cleaned up various dead code. Contributed by Hugo van Kemenade in <code>[#300](https://github.com/ionelmc/pytest-benchmark/issues/300) <https://github.com/ionelmc/pytest-benchmark/pull/300></code>_ and <code>[#301](https://github.com/ionelmc/pytest-benchmark/issues/301) <https://github.com/ionelmc/pytest-benchmark/pull/301></code>_.</li> <li>CI now tests only with latest Pytest (now 9.1.1), Python 3.10-3.14 and PyPy 3.11.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/ionelmc/pytest-benchmark/commit/07d519672687402e6c3fac1a543fbefd810d1e5b"><code>07d5196</code></a> Bump version: 5.2.3 → 5.3.0</li> <li><a href="https://github.com/ionelmc/pytest-benchmark/commit/accf7331e22c0ede38ffa72081c38f3469e0c9b5"><code>accf733</code></a> Add some details on <a href="https://redirect.github.com/ionelmc/pytest-benchmark/issues/304">#304</a>.</li> <li><a href="https://github.com/ionelmc/pytest-benchmark/commit/417dd9fa275e8b9d62c469e676cdb7546d2c4b8f"><code>417dd9f</code></a> Really update the changelog.</li> <li><a href="https://github.com/ionelmc/pytest-benchmark/commit/898acb34430c99ad877e94c52c8b90256a3bb4a8"><code>898acb3</code></a> Update changelog and plan release.</li> <li><a href="https://github.com/ionelmc/pytest-benchmark/commit/9cc7ef0bb1ad3785a46834b24660562dd48e4a0b"><code>9cc7ef0</code></a> Defer xdist warning until benchmark collection (<a href="https://redirect.github.com/ionelmc/pytest-benchmark/issues/65">#65</a>)</li> <li><a href="https://github.com/ionelmc/pytest-benchmark/commit/ef485506f04d5510831fdbdee5be7014f4726a93"><code>ef48550</code></a> Some minor skel updates: test only against latest pytest; bump linting/format...</li> <li><a href="https://github.com/ionelmc/pytest-benchmark/commit/88eaea957d1685f604a5835555d2ce5dbec1ac29"><code>88eaea9</code></a> Add --benchmark-precision for adaptive rounds (opt-in)</li> <li><a href="https://github.com/ionelmc/pytest-benchmark/commit/3b83d127127de74d9f71a3a78e5f661fac044950"><code>3b83d12</code></a> Update and freeze GHA actions</li> <li><a href="https://github.com/ionelmc/pytest-benchmark/commit/4b7662fbfba046eb92dd183e005e8708ac81e6cd"><code>4b7662f</code></a> Fix ruff complaints</li> <li><a href="https://github.com/ionelmc/pytest-benchmark/commit/26b011361d2c41f529a73833e1be8d3a565600fa"><code>26b0113</code></a> Remove Taplo lint (unmaintained)</li> <li>Additional commits viewable in <a href="https://github.com/ionelmc/pytest-benchmark/compare/v5.2.3...v5.3.0">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.4 to 0.16.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.5</h2> <h2>Release Notes</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> <h2>Install ruff 0.16.5</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1 | iex" </code></pre> <h2>Download ruff 0.16.5</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.5</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a> Bump 0.16.5 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a> Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a> Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a> Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a> Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a> Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a> [ty] Infer lambda parameters through callable type aliases (<a href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a> [ty] Narrow functional enum members in <code>==</code> and <code>match</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a> [ty] Intersection simplifications with subtype-related generic specialization...</li> <li><a href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a> [ty] Bump ecosystem-analyzer for HTML escaping (<a href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.4 to 0.16.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.5</h2> <h2>Release Notes</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> <h2>Install ruff 0.16.5</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1 | iex" </code></pre> <h2>Download ruff 0.16.5</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.5</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a> Bump 0.16.5 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a> Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a> Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a> Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a> Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a> Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a> [ty] Infer lambda parameters through callable type aliases (<a href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a> [ty] Narrow functional enum members in <code>==</code> and <code>match</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a> [ty] Intersection simplifications with subtype-related generic specialization...</li> <li><a href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a> [ty] Bump ecosystem-analyzer for HTML escaping (<a href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.4 to 0.16.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.5</h2> <h2>Release Notes</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> <h2>Install ruff 0.16.5</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1 | iex" </code></pre> <h2>Download ruff 0.16.5</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.5</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a> Bump 0.16.5 (<a href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a> Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a> Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a> Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a> Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a> Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a> [ty] Infer lambda parameters through callable type aliases (<a href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a> [ty] Narrow functional enum members in <code>==</code> and <code>match</code> (<a href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a> [ty] Intersection simplifications with subtype-related generic specialization...</li> <li><a href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a> [ty] Bump ecosystem-analyzer for HTML escaping (<a href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.16.4 to 0.16.5 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.16.5</h2> <h2>Release Notes</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of" in <code>ClientOptions</code> doc comment (<a href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li> </ul> <h3>Documentation</h3> <ul> <li>Document rule acceptance guidelines (<a href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li> <li>Document the new category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/AlexWaygood"><code>@AlexWaygood</code></a></li> <li><a href="https://github.com/sharkdp"><code>@sharkdp</code></a></li> <li><a href="https://github.com/jelle-openai"><code>@jelle-openai</code></a></li> <li><a href="https://github.com/charliermarsh"><code>@charliermarsh</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> <li><a href="https://github.com/aarushkandukoori"><code>@aarushkandukoori</code></a></li> </ul> <h2>Install ruff 0.16.5</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1 | iex" </code></pre> <h2>Download ruff 0.16.5</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.16.5</h2> <p>Released on 2026-08-27.</p> <h3>Preview features</h3> <ul> <li>Allow rules without codes (<a href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li> <li>Introduce category selectors (<a href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li> <li>Update preview default rules and categories (<a href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>[<code>flake8-async</code>] Detect blocking generic HTTP requests (<code>ASYNC210</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li> <li>[<code>flake8-datetimez</code>] Allow timezone-safe <code>strptime</code> chains (<code>DTZ007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li> <li>[<code>flake8-simplify</code>] Respect side effects in <code>lambda</code> defaults (<code>SIM401</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li> </ul> <h3>Server</h3> <ul> <li>Fix duplicated "of"... _Description has been truncated_ --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
8e103b5ba7 |
chore(huggingface): bump transformers from 5.5.0 to 5.10.1 (#40117)
Bumps [transformers](https://github.com/huggingface/transformers) from 5.5.0 to 5.10.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/huggingface/transformers/releases">transformers's releases</a>.</em></p> <blockquote> <h1>Release v5.10.1</h1> <p>v5.10.0 was yanked as we publish on a corrupted branch. Sorry everyone, this happens when we rush a release!!!</p> <h2>New Model additions</h2> <h3>Gemma4 unified+ Gemma4 MTP</h3> <!-- raw HTML omitted --> <p>Gemma 4 12B Unified is an <strong>encoder-free</strong> multimodal model with pretrained and instruction-tuned variants. Unlike <a href="https://github.com/huggingface/transformers/blob/HEAD/gemma4">standard Gemma 4</a>, which uses dedicated encoder towers, Gemma 4 12B Unified projects raw inputs directly into the language model's embedding space through lightweight linear pipelines. This results in a simpler architecture while maintaining strong multimodal performance.</p> <p>Key differences from standard Gemma 4:</p> <ul> <li><strong>No Vision Tower</strong>: Raw pixel patches are projected directly into LM space via a <code>Dense + LayerNorm</code> pipeline with factorized 2D positional embeddings, replacing the vision encoder.</li> <li><strong>No Audio Tower</strong>: Raw 16 kHz waveform samples are chunked into fixed-length frames and projected through a simple <code>RMSNorm → Linear</code> pipeline, replacing the mel spectrogram + Conformer encoder.</li> <li><strong>Shared Multimodal Pipeline</strong>: Both vision and audio use the same <code>Gemma4UnifiedMultimodalEmbedder</code> (RMSNorm → Linear) for the final projection to text hidden space.</li> </ul> <p>You can find the original Gemma 4 12B Unified checkpoints under the <a href="https://huggingface.co/collections/google/gemma-4">Gemma 4</a> release.</p> <ul> <li>who needs encoders? (<a href="https://redirect.github.com/huggingface/transformers/issues/46385">#46385</a>) by <a href="https://github.com/douglas-reid"><code>@douglas-reid</code></a> <a href="https://github.com/sgerrard"><code>@sgerrard</code></a> <a href="https://github.com/vasqu"><code>@vasqu</code></a> <a href="https://github.com/molbap"><code>@molbap</code></a></li> </ul> <h3>Sapiens2</h3> <p>Sapiens2 is a family of high-resolution vision transformers pretrained on ~1 billion curated human images, designed for human-centric computer vision tasks including pose estimation, body-part segmentation, surface normal estimation, and pointmap estimation. The models scale from 0.4B to 5B parameters and train at native 1K resolution, with hierarchical 4K variants for extended spatial reasoning. Sapiens2 achieves substantial improvements over its predecessor with +4 mAP in pose estimation, +24.3 mIoU in body-part segmentation, and 45.6% error reduction in normal estimation.</p> <p><strong>Links:</strong> <a href="https://huggingface.co/docs/transformers/main/en/model_doc/sapiens2">Documentation</a> | <a href="https://huggingface.co/papers/2604.21681">Paper</a></p> <ul> <li>Add Sapiens2 Model (<a href="https://redirect.github.com/huggingface/transformers/issues/45919">#45919</a>) by <a href="https://github.com/guarin"><code>@guarin</code></a> in <a href="https://redirect.github.com/huggingface/transformers/pull/45919">#45919</a></li> </ul> <h3>DeepSeek-OCR-2</h3> <p>DeepSeek-OCR-2 is an OCR-specialized vision-language model built on a distinctive architecture that combines a SAM ViT-B vision encoder with a Qwen2 hybrid attention encoder, connected through an MLP projector to a DeepSeek-V2 Mixture-of-Experts (MoE) language model. The model features a hybrid attention mechanism that applies bidirectional attention over image tokens and causal attention over query tokens, enabling efficient and accurate document understanding. It supports both plain OCR tasks and grounding capabilities with coordinate-aware output for document conversion to markdown format.</p> <p><strong>Links:</strong> <a href="https://huggingface.co/docs/transformers/main/en/model_doc/deepseek_ocr2">Documentation</a></p> <ul> <li>Add Deepseek-OCR-2 model (<a href="https://redirect.github.com/huggingface/transformers/issues/45075">#45075</a>) by <a href="https://github.com/thisisiron"><code>@thisisiron</code></a> in <a href="https://redirect.github.com/huggingface/transformers/pull/45075">#45075</a></li> </ul> <h3>Mellum</h3> <p>Mellum is a code-focused Mixture-of-Experts language model developed by JetBrains. It is derived from the Qwen3-MoE architecture with per-layer-type RoPE and interleaved sliding window attention. The model has 12B total parameters with 2.5B active parameters per token, using 64 routed experts with 8 activated per token across 28 layers.</p> <p><strong>Links:</strong> <a href="https://huggingface.co/docs/transformers/main/en/model_doc/mellum">Documentation</a></p> <ul> <li>feat: Add support for JetBrains' <code>Mellum</code> v2 code generation model (<a href="https://redirect.github.com/huggingface/transformers/issues/46112">#46112</a>) by <a href="https://github.com/shadeMe"><code>@shadeMe</code></a> in <a href="https://redirect.github.com/huggingface/transformers/pull/46112">#46112</a></li> </ul> <h2>Breaking changes</h2> <p>The Gemma4 vision pooler now casts inputs to float32 before scaling to prevent float16 overflow (inf saturation) with large checkpoints, which may cause minor numerical differences in outputs for users running Gemma-4 vision models in float16.</p> <ul> <li>🚨 Fix float16 overflow in Gemma4 vision pooler (<a href="https://redirect.github.com/huggingface/transformers/issues/46277">#46277</a>) by <a href="https://github.com/Bluear7878"><code>@Bluear7878</code></a></li> </ul> <p>Audio Language Models (ALMs) now have a dedicated base model class without a language modeling head, aligning them with the design of Vision Language Models (VLMs); users relying on the previous model class structure should update their code to use the new base model class where appropriate.</p> <ul> <li>🚨 [ALM] Add base model without head (<a href="https://redirect.github.com/huggingface/transformers/issues/45534">#45534</a>) by <a href="https://github.com/eustlb"><code>@eustlb</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/huggingface/transformers/commit/90c3ae54d448d4906b6167317ea5a7f5d48a232d"><code>90c3ae5</code></a> Patch because we had to yank 5.10 because the release branch was not up to date</li> <li><a href="https://github.com/huggingface/transformers/commit/0bd94b37db639d8f29a094dce2fde06f86af8968"><code>0bd94b3</code></a> v5.10.0</li> <li><a href="https://github.com/huggingface/transformers/commit/1423d22f7a3b62e8c70ad67b58ec25cd9b675897"><code>1423d22</code></a> who needs encoders? (<a href="https://redirect.github.com/huggingface/transformers/issues/46385">#46385</a>)</li> <li><a href="https://github.com/huggingface/transformers/commit/50eb20a24f9dd512e6770072f422e4b86ca3cd98"><code>50eb20a</code></a> Fix dsv4 dequant + tp/ep (<a href="https://redirect.github.com/huggingface/transformers/issues/46378">#46378</a>)</li> <li><a href="https://github.com/huggingface/transformers/commit/74464e8c49c91b574c30cc3cb3c5a44000237299"><code>74464e8</code></a> Fix wrong changes produced by style/repo. check bot (<a href="https://redirect.github.com/huggingface/transformers/issues/46371">#46371</a>)</li> <li><a href="https://github.com/huggingface/transformers/commit/1b8ec344fb6c277235fc76c37e7a5c156a1f0ddc"><code>1b8ec34</code></a> Fix path traversal when saving Bark voice preset embeddings (<a href="https://redirect.github.com/huggingface/transformers/issues/46237">#46237</a>)</li> <li><a href="https://github.com/huggingface/transformers/commit/e820678256f22e7647e39e8b7ed040fa81b7b872"><code>e820678</code></a> Add Sapiens2 Model (<a href="https://redirect.github.com/huggingface/transformers/issues/45919">#45919</a>)</li> <li><a href="https://github.com/huggingface/transformers/commit/595721c44cb14db37fa504903e2edd5e9f0eba43"><code>595721c</code></a> Pass library_name/version to Hub calls via a shared HfApi (<a href="https://redirect.github.com/huggingface/transformers/issues/46318">#46318</a>)</li> <li><a href="https://github.com/huggingface/transformers/commit/0f0036c888ed81b714cb04aa6fe6689eb36bce0a"><code>0f0036c</code></a> docs: update ACL Anthology URL in CITATION.cff (<a href="https://redirect.github.com/huggingface/transformers/issues/46352">#46352</a>)</li> <li><a href="https://github.com/huggingface/transformers/commit/fa6c8308e22dade298c10c72d44937e41b962353"><code>fa6c830</code></a> DeepGEMM BF16 + mixed FP8/FP4 + MegaMoE + refactor (<a href="https://redirect.github.com/huggingface/transformers/issues/45634">#45634</a>)</li> <li>Additional commits viewable in <a href="https://github.com/huggingface/transformers/compare/v5.5.0...v5.10.1">compare view</a></li> </ul> </details> <br /> Made by [Open SWE](https://openswe.vercel.app/agents/ac1ed59d-d5b3-5bef-b44a-3af86e5e14ab) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
5b9d7e9dbf |
chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/partners/huggingface (#40110)
[//]: # (dependabot-start) ⚠️ **Dependabot is rebasing this PR** ⚠️ Rebasing might not happen immediately, so don't worry if this takes some time. Note: if you make any changes to this PR yourself, they will take precedence over the rebase. --- [//]: # (dependabot-end) Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.7 to 6.5.8. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's changelog</a>.</em></p> <blockquote> <h1>Release notes</h1> <p>.. toctree:: :maxdepth: 2</p> <p>releases/v6.5.8 releases/v6.5.7 releases/v6.5.6 releases/v6.5.5 releases/v6.5.4 releases/v6.5.3 releases/v6.5.2 releases/v6.5.1 releases/v6.5.0 releases/v6.4.2 releases/v6.4.1 releases/v6.4.0 releases/v6.3.3 releases/v6.3.2 releases/v6.3.1 releases/v6.3.0 releases/v6.2.0 releases/v6.1.0 releases/v6.0.4 releases/v6.0.3 releases/v6.0.2 releases/v6.0.1 releases/v6.0.0 releases/v5.1.1 releases/v5.1.0 releases/v5.0.2 releases/v5.0.1 releases/v5.0.0 releases/v4.5.3 releases/v4.5.2 releases/v4.5.1 releases/v4.5.0 releases/v4.4.3 releases/v4.4.2 releases/v4.4.1 releases/v4.4.0 releases/v4.3.0 releases/v4.2.1 releases/v4.2.0 releases/v4.1.0 releases/v4.0.2 releases/v4.0.1 releases/v4.0.0 releases/v3.2.2</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7"><code>a55abe3</code></a> Merge pull request <a href="https://redirect.github.com/tornadoweb/tornado/issues/3704">#3704</a> from bdarnell/security-6.5.8</li> <li><a href="https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c"><code>fc79488</code></a> docs: add additional credit to release notes</li> <li><a href="https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129"><code>7b01763</code></a> Fix test_strip_headers_on_redirect's URL-embedded-credentials cases</li> <li><a href="https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c"><code>d72fff8</code></a> release notes and version bump for 6.5.8</li> <li><a href="https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e"><code>b168818</code></a> auth: Formally deprecated OpenIDMixin</li> <li><a href="https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7"><code>da28476</code></a> web: Also check for semicolons in deprecated mixed-case cookie args</li> <li><a href="https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de"><code>8d6363e</code></a> httputil: Enforce a new limit on the number of arguments in a request</li> <li><a href="https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05"><code>de85b3f</code></a> httputil: Apply multipart max_parts limit earlier</li> <li>See full diff in <a href="https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ef548a8435 |
chore(deps): bump the major group across 2 directories with 1 update (#40086)
Bumps the major group with 1 update in the /libs/model-profiles directory: [syrupy](https://github.com/syrupy-project/syrupy). Bumps the major group with 1 update in the /libs/standard-tests directory: [syrupy](https://github.com/syrupy-project/syrupy). Updates `syrupy` from 5.5.3 to 6.0.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/syrupy-project/syrupy/releases">syrupy's releases</a>.</em></p> <blockquote> <h2>v6.0.0</h2> <h1>Syrupy 6.0.0</h1> <p><em>(2026-08-22)</em></p> <p>Syrupy 6 focuses on better built-in serialization, clearer snapshot workflows, and large-suite performance. Please review the <strong>breaking changes</strong> before upgrading.</p> <p>Most suites should not need significant snapshot updates on upgrade — the main exception is <strong>dataclass</strong> usage (see below). Syrupy v6 does <strong>not</strong> change the required Python version or other package dependencies. Support for Python 3.10 will instead be dropped in the next Syrupy major version (v7).</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0">https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0</a></p> <hr /> <h2>Breaking Changes</h2> <h3>Built-in dataclass serialization (removed <code>DataclassPlugin</code>)</h3> <p>stdlib dataclasses are now serialized natively by the Amber serializer. The separate <code>DataclassPlugin</code> has been <strong>removed</strong>.</p> <ul> <li><strong>If you used <code>DataclassPlugin</code>:</strong> remove imports and plugin wiring. Behavior should match what the plugin produced; no snapshot rewrite should be needed for the dataclass shape itself.</li> <li><strong>If you did <em>not</em> use the plugin:</strong> dataclass snapshots may change from a <code>repr</code>-style string to structured Amber form (field-by-field). Re-run with <code>--snapshot-update</code> where those assertions fail.</li> </ul> <p>Example of what to remove:</p> <pre lang="python"><code># Before (v5) from syrupy.extensions.amber.dataclasses_plugin import DataclassPlugin <p>class MySerializer(AmberDataSerializer): serializer_plugins = [DataclassPlugin, ...] </code></pre></p> <pre lang="python"><code># After (v6) — dataclasses work with the default Amber extension assert MyDataclass(...) == snapshot </code></pre> <p>Attrs and Pydantic models are unchanged and still need their serializer plugins. See the <a href="https://github.com/syrupy-project/syrupy/blob/main/tests/syrupy/extensions/amber/test_amber_serializer_plugins.py">serializer plugins example</a>.</p> <p>(<a href="https://redirect.github.com/syrupy-project/syrupy/pull/1220">#1220</a>, closes <a href="https://redirect.github.com/syrupy-project/syrupy/issues/1048">#1048</a>)</p> <h3>JSON <code>datetime.date</code> snapshots</h3> <p>The JSON extension now serializes <code>datetime.date</code> as <code>YYYY-MM-DD</code> instead of a <code>repr</code> string. Existing JSON snapshots that contain dates will need an update.</p> <p>(<a href="https://redirect.github.com/syrupy-project/syrupy/pull/1216">#1216</a>, closes <a href="https://redirect.github.com/syrupy-project/syrupy/issues/1058">#1058</a>)</p> <h3><code>path_value</code> nested path replacement in default (literal) mode</h3> <p><code>path_value(..., regex=False)</code> now correctly replaces values at nested paths such as <code>user.token</code>. Previously, the default-mode lookup missed escaped path keys, so nested values were left unchanged (and could leak into committed snapshots).</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/syrupy-project/syrupy/blob/main/CHANGELOG.md">syrupy's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/syrupy-project/syrupy/releases/tag/v6.0.0">v6.0.0</a> (2026-08-22)</h2> <h2>What's Changed</h2> <ul> <li>chore(deps): bump pygments from 2.19.2 to 2.20.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1151">syrupy-project/syrupy#1151</a></li> <li>chore(deps): update dependency hypothesis to v6.156.5 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1152">syrupy-project/syrupy#1152</a></li> <li>chore(deps): update dependency ruff to v0.15.21 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1153">syrupy-project/syrupy#1153</a></li> <li>chore(deps): update dependency hypothesis to v6.156.6 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1154">syrupy-project/syrupy#1154</a></li> <li>chore(deps): update dependency coverage to v7.15.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1157">syrupy-project/syrupy#1157</a></li> <li>chore(deps): update dependency mypy to v2.3.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1158">syrupy-project/syrupy#1158</a></li> <li>fix: make set/dict serialization deterministic for partial-order elements by <a href="https://github.com/chuenchen309"><code>@chuenchen309</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1159">syrupy-project/syrupy#1159</a></li> <li>docs: add chuenchen309 as a contributor for bug by <a href="https://github.com/allcontributors"><code>@allcontributors</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1160">syrupy-project/syrupy#1160</a></li> <li>chore(deps): update dependency coverage to v7.15.2 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1163">syrupy-project/syrupy#1163</a></li> <li>chore(deps): update dependency ruff to v0.15.22 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1164">syrupy-project/syrupy#1164</a></li> <li>chore(deps): update dependency hypothesis to v6.156.7 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1165">syrupy-project/syrupy#1165</a></li> <li>chore(deps): update dependency hypothesis to v6.156.9 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1166">syrupy-project/syrupy#1166</a></li> <li>chore(deps): update dependency hypothesis to v6.157.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1167">syrupy-project/syrupy#1167</a></li> <li>fix(matchers): replace values at nested paths in path_value default mode by <a href="https://github.com/chuenchen309"><code>@chuenchen309</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1162">syrupy-project/syrupy#1162</a></li> <li>fix: preserve skipped single-file snapshots by <a href="https://github.com/KSmanis"><code>@KSmanis</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1161">syrupy-project/syrupy#1161</a></li> <li>docs: add KSmanis as a contributor for bug by <a href="https://github.com/allcontributors"><code>@allcontributors</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1168">syrupy-project/syrupy#1168</a></li> <li>chore(deps): update pypa/gh-action-pypi-publish action to v1.14.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1169">syrupy-project/syrupy#1169</a></li> <li>chore(deps): update dependency hypothesis to v6.157.2 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1171">syrupy-project/syrupy#1171</a></li> <li>chore(deps): update actions/checkout action to v7.0.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1170">syrupy-project/syrupy#1170</a></li> <li>chore(deps): update dependency hypothesis to v6.158.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1172">syrupy-project/syrupy#1172</a></li> <li>chore(deps): update astral-sh/setup-uv action to v9 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1174">syrupy-project/syrupy#1174</a></li> <li>chore(deps): update dependency hypothesis to v6.158.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1173">syrupy-project/syrupy#1173</a></li> <li>chore(deps): update dependency hypothesis to v6.160.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1176">syrupy-project/syrupy#1176</a></li> <li>feat: support in-memory snapshot diff data by <a href="https://github.com/yangfan-yf-yf"><code>@yangfan-yf-yf</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1175">syrupy-project/syrupy#1175</a></li> <li>docs: add yangfan-yf-yf as a contributor for code by <a href="https://github.com/allcontributors"><code>@allcontributors</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1178">syrupy-project/syrupy#1178</a></li> <li>chore(deps): update dependency hypothesis to v6.161.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1177">syrupy-project/syrupy#1177</a></li> <li>chore(deps): update dependency hypothesis to v6.161.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1180">syrupy-project/syrupy#1180</a></li> <li>chore(deps): update dependency hypothesis to v6.161.4 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1182">syrupy-project/syrupy#1182</a></li> <li>chore(deps): update dependency hypothesis to v6.161.6 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1183">syrupy-project/syrupy#1183</a></li> <li>chore(deps): update dependency ruff to >=0.16,<0.17 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1179">syrupy-project/syrupy#1179</a></li> <li>chore(deps): update dependency hypothesis to v6.161.7 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1184">syrupy-project/syrupy#1184</a></li> <li>chore(deps): update pypa/gh-action-pypi-publish action to v1.14.2 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1186">syrupy-project/syrupy#1186</a></li> <li>perf: compress xdist snapshot reports by <a href="https://github.com/w3lld1"><code>@w3lld1</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1188">syrupy-project/syrupy#1188</a></li> <li>docs: add w3lld1 as a contributor for code by <a href="https://github.com/allcontributors"><code>@allcontributors</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1190">syrupy-project/syrupy#1190</a></li> <li>chore(deps): update dependency ruff to v0.16.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1189">syrupy-project/syrupy#1189</a></li> <li>chore(deps): update dependency hypothesis to v6.164.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1187">syrupy-project/syrupy#1187</a></li> <li>chore(deps): update dependency hypothesis to v6.165.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1191">syrupy-project/syrupy#1191</a></li> <li>chore(deps): update dependency coverage to v7.15.3 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1192">syrupy-project/syrupy#1192</a></li> <li>chore(deps): update python docker tag to v3.14.7 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1195">syrupy-project/syrupy#1195</a></li> <li>chore(deps): update dependency coverage to v7.15.4 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1197">syrupy-project/syrupy#1197</a></li> <li>chore(deps): update dependency hypothesis to v6.165.2 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1194">syrupy-project/syrupy#1194</a></li> <li>chore(deps): update dependency ruff to v0.16.2 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1198">syrupy-project/syrupy#1198</a></li> <li>chore(deps): update dependency hypothesis to v6.165.3 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1199">syrupy-project/syrupy#1199</a></li> <li>chore(deps): update astral-sh/setup-uv action to v10 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1200">syrupy-project/syrupy#1200</a></li> <li>chore(deps): update dependency hypothesis to v6.165.5 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1201">syrupy-project/syrupy#1201</a></li> <li>chore(deps): update dependency ruff to v0.16.3 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1202">syrupy-project/syrupy#1202</a></li> <li>chore(deps): update astral-sh/setup-uv action to v10.0.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1205">syrupy-project/syrupy#1205</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/syrupy-project/syrupy/commit/621af75dd8dfa3301b503099b204a3d874e787d7"><code>621af75</code></a> chore(release): 6.0.0 [skip ci]</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/3a9f69182366401c372dd0a1690177e70e994fec"><code>3a9f691</code></a> fix: single file snapshot no longer buffers in memory (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1223">#1223</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/ab13f8d4a9eeba10572a6a12f485f79a6e0a1b23"><code>ab13f8d</code></a> chore: sponsorship (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1224">#1224</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/98f989c42a7c1c9cf49e031e9b97374bf97a6b6d"><code>98f989c</code></a> feat: add --snapshot-declaration-order for respecting declaration order (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1222">#1222</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/b549b4b6329cca03f871162748b3ea8597add1a3"><code>b549b4b</code></a> feat: built-in support for Dataclasses (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1220">#1220</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/d34933fce2d8eb65c24a89f29f5900b413775b5e"><code>d34933f</code></a> chore: use the benchmarks git branch (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1221">#1221</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/f6eda020d8671fc1648c0d94ed436805d5548978"><code>f6eda02</code></a> chore(ci): permissions for gh-pages</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/a5ce0492e68525f499f5cb395e273d3ac5a1f8e3"><code>a5ce049</code></a> chore(deps): update actions/configure-pages action to v6 (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1219">#1219</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/c0cb162f5fbaca6eeda43937152db314e0313c82"><code>c0cb162</code></a> chore: update github pages</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/4d59bde91c87f6a2fb3b476ea995246a43449bc2"><code>4d59bde</code></a> chore: update docs for v6 release (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1218">#1218</a>)</li> <li>Additional commits viewable in <a href="https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0">compare view</a></li> </ul> </details> <br /> Updates `syrupy` from 5.5.3 to 6.0.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/syrupy-project/syrupy/releases">syrupy's releases</a>.</em></p> <blockquote> <h2>v6.0.0</h2> <h1>Syrupy 6.0.0</h1> <p><em>(2026-08-22)</em></p> <p>Syrupy 6 focuses on better built-in serialization, clearer snapshot workflows, and large-suite performance. Please review the <strong>breaking changes</strong> before upgrading.</p> <p>Most suites should not need significant snapshot updates on upgrade — the main exception is <strong>dataclass</strong> usage (see below). Syrupy v6 does <strong>not</strong> change the required Python version or other package dependencies. Support for Python 3.10 will instead be dropped in the next Syrupy major version (v7).</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0">https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0</a></p> <hr /> <h2>Breaking Changes</h2> <h3>Built-in dataclass serialization (removed <code>DataclassPlugin</code>)</h3> <p>stdlib dataclasses are now serialized natively by the Amber serializer. The separate <code>DataclassPlugin</code> has been <strong>removed</strong>.</p> <ul> <li><strong>If you used <code>DataclassPlugin</code>:</strong> remove imports and plugin wiring. Behavior should match what the plugin produced; no snapshot rewrite should be needed for the dataclass shape itself.</li> <li><strong>If you did <em>not</em> use the plugin:</strong> dataclass snapshots may change from a <code>repr</code>-style string to structured Amber form (field-by-field). Re-run with <code>--snapshot-update</code> where those assertions fail.</li> </ul> <p>Example of what to remove:</p> <pre lang="python"><code># Before (v5) from syrupy.extensions.amber.dataclasses_plugin import DataclassPlugin <p>class MySerializer(AmberDataSerializer): serializer_plugins = [DataclassPlugin, ...] </code></pre></p> <pre lang="python"><code># After (v6) — dataclasses work with the default Amber extension assert MyDataclass(...) == snapshot </code></pre> <p>Attrs and Pydantic models are unchanged and still need their serializer plugins. See the <a href="https://github.com/syrupy-project/syrupy/blob/main/tests/syrupy/extensions/amber/test_amber_serializer_plugins.py">serializer plugins example</a>.</p> <p>(<a href="https://redirect.github.com/syrupy-project/syrupy/pull/1220">#1220</a>, closes <a href="https://redirect.github.com/syrupy-project/syrupy/issues/1048">#1048</a>)</p> <h3>JSON <code>datetime.date</code> snapshots</h3> <p>The JSON extension now serializes <code>datetime.date</code> as <code>YYYY-MM-DD</code> instead of a <code>repr</code> string. Existing JSON snapshots that contain dates will need an update.</p> <p>(<a href="https://redirect.github.com/syrupy-project/syrupy/pull/1216">#1216</a>, closes <a href="https://redirect.github.com/syrupy-project/syrupy/issues/1058">#1058</a>)</p> <h3><code>path_value</code> nested path replacement in default (literal) mode</h3> <p><code>path_value(..., regex=False)</code> now correctly replaces values at nested paths such as <code>user.token</code>. Previously, the default-mode lookup missed escaped path keys, so nested values were left unchanged (and could leak into committed snapshots).</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/syrupy-project/syrupy/blob/main/CHANGELOG.md">syrupy's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/syrupy-project/syrupy/releases/tag/v6.0.0">v6.0.0</a> (2026-08-22)</h2> <h2>What's Changed</h2> <ul> <li>chore(deps): bump pygments from 2.19.2 to 2.20.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1151">syrupy-project/syrupy#1151</a></li> <li>chore(deps): update dependency hypothesis to v6.156.5 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1152">syrupy-project/syrupy#1152</a></li> <li>chore(deps): update dependency ruff to v0.15.21 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1153">syrupy-project/syrupy#1153</a></li> <li>chore(deps): update dependency hypothesis to v6.156.6 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1154">syrupy-project/syrupy#1154</a></li> <li>chore(deps): update dependency coverage to v7.15.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1157">syrupy-project/syrupy#1157</a></li> <li>chore(deps): update dependency mypy to v2.3.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1158">syrupy-project/syrupy#1158</a></li> <li>fix: make set/dict serialization deterministic for partial-order elements by <a href="https://github.com/chuenchen309"><code>@chuenchen309</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1159">syrupy-project/syrupy#1159</a></li> <li>docs: add chuenchen309 as a contributor for bug by <a href="https://github.com/allcontributors"><code>@allcontributors</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1160">syrupy-project/syrupy#1160</a></li> <li>chore(deps): update dependency coverage to v7.15.2 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1163">syrupy-project/syrupy#1163</a></li> <li>chore(deps): update dependency ruff to v0.15.22 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1164">syrupy-project/syrupy#1164</a></li> <li>chore(deps): update dependency hypothesis to v6.156.7 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1165">syrupy-project/syrupy#1165</a></li> <li>chore(deps): update dependency hypothesis to v6.156.9 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1166">syrupy-project/syrupy#1166</a></li> <li>chore(deps): update dependency hypothesis to v6.157.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1167">syrupy-project/syrupy#1167</a></li> <li>fix(matchers): replace values at nested paths in path_value default mode by <a href="https://github.com/chuenchen309"><code>@chuenchen309</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1162">syrupy-project/syrupy#1162</a></li> <li>fix: preserve skipped single-file snapshots by <a href="https://github.com/KSmanis"><code>@KSmanis</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1161">syrupy-project/syrupy#1161</a></li> <li>docs: add KSmanis as a contributor for bug by <a href="https://github.com/allcontributors"><code>@allcontributors</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1168">syrupy-project/syrupy#1168</a></li> <li>chore(deps): update pypa/gh-action-pypi-publish action to v1.14.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1169">syrupy-project/syrupy#1169</a></li> <li>chore(deps): update dependency hypothesis to v6.157.2 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1171">syrupy-project/syrupy#1171</a></li> <li>chore(deps): update actions/checkout action to v7.0.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1170">syrupy-project/syrupy#1170</a></li> <li>chore(deps): update dependency hypothesis to v6.158.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1172">syrupy-project/syrupy#1172</a></li> <li>chore(deps): update astral-sh/setup-uv action to v9 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1174">syrupy-project/syrupy#1174</a></li> <li>chore(deps): update dependency hypothesis to v6.158.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1173">syrupy-project/syrupy#1173</a></li> <li>chore(deps): update dependency hypothesis to v6.160.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1176">syrupy-project/syrupy#1176</a></li> <li>feat: support in-memory snapshot diff data by <a href="https://github.com/yangfan-yf-yf"><code>@yangfan-yf-yf</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1175">syrupy-project/syrupy#1175</a></li> <li>docs: add yangfan-yf-yf as a contributor for code by <a href="https://github.com/allcontributors"><code>@allcontributors</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1178">syrupy-project/syrupy#1178</a></li> <li>chore(deps): update dependency hypothesis to v6.161.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1177">syrupy-project/syrupy#1177</a></li> <li>chore(deps): update dependency hypothesis to v6.161.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1180">syrupy-project/syrupy#1180</a></li> <li>chore(deps): update dependency hypothesis to v6.161.4 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1182">syrupy-project/syrupy#1182</a></li> <li>chore(deps): update dependency hypothesis to v6.161.6 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1183">syrupy-project/syrupy#1183</a></li> <li>chore(deps): update dependency ruff to >=0.16,<0.17 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1179">syrupy-project/syrupy#1179</a></li> <li>chore(deps): update dependency hypothesis to v6.161.7 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1184">syrupy-project/syrupy#1184</a></li> <li>chore(deps): update pypa/gh-action-pypi-publish action to v1.14.2 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1186">syrupy-project/syrupy#1186</a></li> <li>perf: compress xdist snapshot reports by <a href="https://github.com/w3lld1"><code>@w3lld1</code></a> in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1188">syrupy-project/syrupy#1188</a></li> <li>docs: add w3lld1 as a contributor for code by <a href="https://github.com/allcontributors"><code>@allcontributors</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1190">syrupy-project/syrupy#1190</a></li> <li>chore(deps): update dependency ruff to v0.16.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1189">syrupy-project/syrupy#1189</a></li> <li>chore(deps): update dependency hypothesis to v6.164.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1187">syrupy-project/syrupy#1187</a></li> <li>chore(deps): update dependency hypothesis to v6.165.0 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1191">syrupy-project/syrupy#1191</a></li> <li>chore(deps): update dependency coverage to v7.15.3 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1192">syrupy-project/syrupy#1192</a></li> <li>chore(deps): update python docker tag to v3.14.7 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1195">syrupy-project/syrupy#1195</a></li> <li>chore(deps): update dependency coverage to v7.15.4 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1197">syrupy-project/syrupy#1197</a></li> <li>chore(deps): update dependency hypothesis to v6.165.2 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1194">syrupy-project/syrupy#1194</a></li> <li>chore(deps): update dependency ruff to v0.16.2 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1198">syrupy-project/syrupy#1198</a></li> <li>chore(deps): update dependency hypothesis to v6.165.3 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1199">syrupy-project/syrupy#1199</a></li> <li>chore(deps): update astral-sh/setup-uv action to v10 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1200">syrupy-project/syrupy#1200</a></li> <li>chore(deps): update dependency hypothesis to v6.165.5 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1201">syrupy-project/syrupy#1201</a></li> <li>chore(deps): update dependency ruff to v0.16.3 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1202">syrupy-project/syrupy#1202</a></li> <li>chore(deps): update astral-sh/setup-uv action to v10.0.1 by <a href="https://github.com/renovate"><code>@renovate</code></a>[bot] in <a href="https://redirect.github.com/syrupy-project/syrupy/pull/1205">syrupy-project/syrupy#1205</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/syrupy-project/syrupy/commit/621af75dd8dfa3301b503099b204a3d874e787d7"><code>621af75</code></a> chore(release): 6.0.0 [skip ci]</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/3a9f69182366401c372dd0a1690177e70e994fec"><code>3a9f691</code></a> fix: single file snapshot no longer buffers in memory (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1223">#1223</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/ab13f8d4a9eeba10572a6a12f485f79a6e0a1b23"><code>ab13f8d</code></a> chore: sponsorship (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1224">#1224</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/98f989c42a7c1c9cf49e031e9b97374bf97a6b6d"><code>98f989c</code></a> feat: add --snapshot-declaration-order for respecting declaration order (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1222">#1222</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/b549b4b6329cca03f871162748b3ea8597add1a3"><code>b549b4b</code></a> feat: built-in support for Dataclasses (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1220">#1220</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/d34933fce2d8eb65c24a89f29f5900b413775b5e"><code>d34933f</code></a> chore: use the benchmarks git branch (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1221">#1221</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/f6eda020d8671fc1648c0d94ed436805d5548978"><code>f6eda02</code></a> chore(ci): permissions for gh-pages</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/a5ce0492e68525f499f5cb395e273d3ac5a1f8e3"><code>a5ce049</code></a> chore(deps): update actions/configure-pages action to v6 (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1219">#1219</a>)</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/c0cb162f5fbaca6eeda43937152db314e0313c82"><code>c0cb162</code></a> chore: update github pages</li> <li><a href="https://github.com/syrupy-project/syrupy/commit/4d59bde91c87f6a2fb3b476ea995246a43449bc2"><code>4d59bde</code></a> chore: update docs for v6 release (<a href="https://redirect.github.com/syrupy-project/syrupy/issues/1218">#1218</a>)</li> <li>Additional commits viewable in <a href="https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4662366268 |
chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (#40113)
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.7 to 6.5.8. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's changelog</a>.</em></p> <blockquote> <h1>Release notes</h1> <p>.. toctree:: :maxdepth: 2</p> <p>releases/v6.5.8 releases/v6.5.7 releases/v6.5.6 releases/v6.5.5 releases/v6.5.4 releases/v6.5.3 releases/v6.5.2 releases/v6.5.1 releases/v6.5.0 releases/v6.4.2 releases/v6.4.1 releases/v6.4.0 releases/v6.3.3 releases/v6.3.2 releases/v6.3.1 releases/v6.3.0 releases/v6.2.0 releases/v6.1.0 releases/v6.0.4 releases/v6.0.3 releases/v6.0.2 releases/v6.0.1 releases/v6.0.0 releases/v5.1.1 releases/v5.1.0 releases/v5.0.2 releases/v5.0.1 releases/v5.0.0 releases/v4.5.3 releases/v4.5.2 releases/v4.5.1 releases/v4.5.0 releases/v4.4.3 releases/v4.4.2 releases/v4.4.1 releases/v4.4.0 releases/v4.3.0 releases/v4.2.1 releases/v4.2.0 releases/v4.1.0 releases/v4.0.2 releases/v4.0.1 releases/v4.0.0 releases/v3.2.2</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7"><code>a55abe3</code></a> Merge pull request <a href="https://redirect.github.com/tornadoweb/tornado/issues/3704">#3704</a> from bdarnell/security-6.5.8</li> <li><a href="https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c"><code>fc79488</code></a> docs: add additional credit to release notes</li> <li><a href="https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129"><code>7b01763</code></a> Fix test_strip_headers_on_redirect's URL-embedded-credentials cases</li> <li><a href="https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c"><code>d72fff8</code></a> release notes and version bump for 6.5.8</li> <li><a href="https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e"><code>b168818</code></a> auth: Formally deprecated OpenIDMixin</li> <li><a href="https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7"><code>da28476</code></a> web: Also check for semicolons in deprecated mixed-case cookie args</li> <li><a href="https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de"><code>8d6363e</code></a> httputil: Enforce a new limit on the number of arguments in a request</li> <li><a href="https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05"><code>de85b3f</code></a> httputil: Apply multipart max_parts limit earlier</li> <li>See full diff in <a href="https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
673b9c5981 |
chore(deps): update lxml requirement from <7.0,>=6.1.0 to >=6.1.2,<7.0 in /libs/text-splitters (#40087)
Updates the requirements on [lxml](https://github.com/lxml/lxml) to permit the latest version. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/lxml/lxml/blob/master/CHANGES.txt">lxml's changelog</a>.</em></p> <blockquote> <h1>6.1.2 (2026-08-18)</h1> <ul> <li> <p>GH#526: Some build files were missing in the sdist. Patch by Nicola Soranzo.</p> </li> <li> <p>Some minor corrections for error handling cases.</p> </li> </ul> <h2>Other changes</h2> <ul> <li>Built with Cython 3.2.9.</li> </ul> <h1>6.1.1 (2026-05-18)</h1> <h2>Bugs fixed</h2> <ul> <li> <p>The known link attributes in <code>lxml.html.defs.link_attrs</code> were missing <code>xlink:href</code>, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. <a href="https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f">https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f</a></p> </li> <li> <p>The Linux wheels use a patched libxslt 1.1.43, fixing CVE-2025-7424 and CVE-2025-11731.</p> </li> <li> <p>The Windows wheels use libxslt 1.1.45, fixing CVE-2025-7424 and CVE-2025-11731.</p> </li> </ul> <h1>6.1.0 (2026-04-17)</h1> <p>This release fixes a possible external entity injection (XXE) vulnerability in <code>iterparse()</code> and the <code>ETCompatXMLParser</code>.</p> <h2>Features added</h2> <ul> <li> <p>GH#486: The HTML ARIA accessibility attributes were added to the set of safe attributes in <code>lxml.html.defs</code>. This allows <code>lxml_html_clean</code> to pass them through. Patch by oomsveta.</p> </li> <li> <p>The default chunk size for reading from file-likes in <code>iterparse()</code> is now configurable with a new <code>chunk_size</code> argument.</p> </li> </ul> <h2>Bugs fixed</h2> <ul> <li>LP#2146291: The <code>resolve_entities</code> option was still set to <code>True</code> for <code>iterparse</code> and <code>ETCompatXMLParser</code>, allowing for external entity injection (XXE)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/lxml/lxml/commit/f2874e9008c83d2d26e0b7292772eb74d2b83ce3"><code>f2874e9</code></a> Update release date.</li> <li><a href="https://github.com/lxml/lxml/commit/687a295a4c19288b95ec1b74c31a620acaabdf9d"><code>687a295</code></a> Build: Exclude Py3.8 from windows-arm builds.</li> <li><a href="https://github.com/lxml/lxml/commit/acadc56553ff74e6ea296158e118b08ac6ec9f4b"><code>acadc56</code></a> Build: Remove outdated build target.</li> <li><a href="https://github.com/lxml/lxml/commit/59f93eb420a988bc61e7c5b8f4d97869c0536be7"><code>59f93eb</code></a> Build: Split old-Linux and other-Py3.8 builds.</li> <li><a href="https://github.com/lxml/lxml/commit/923df83ed6a40ca5aab267b1c3fe073ff13a00ab"><code>923df83</code></a> Build: Fix manylinux2014 build.</li> <li><a href="https://github.com/lxml/lxml/commit/975cc83e4626117e36adb6d336ac9a6f6cc0ca42"><code>975cc83</code></a> Build: Fix Px3.8 build setup.</li> <li><a href="https://github.com/lxml/lxml/commit/09e5d3e968f380d7a790c2b47f59f7937e00942e"><code>09e5d3e</code></a> Build: Fix cibuildwheel version.</li> <li><a href="https://github.com/lxml/lxml/commit/998cf504a3b0da7f316861c5a552c5c16069d91f"><code>998cf50</code></a> Build: Build Py3.8 wheels only once, not in every build job.</li> <li><a href="https://github.com/lxml/lxml/commit/55670370cd68117ff2b3b71e0f20a7f275d1baeb"><code>5567037</code></a> Build: Exclude Py3.15 from 32bit builds.</li> <li><a href="https://github.com/lxml/lxml/commit/904db40b04ef590ae1ca8fc84be863fc0f8196dc"><code>904db40</code></a> Build: Update cibuildwheel to include Py3.15.</li> <li>Additional commits viewable in <a href="https://github.com/lxml/lxml/compare/lxml-6.1.0...lxml-6.1.2">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
0cac488d0b |
chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/langchain (#40111)
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.7 to 6.5.8. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's changelog</a>.</em></p> <blockquote> <h1>Release notes</h1> <p>.. toctree:: :maxdepth: 2</p> <p>releases/v6.5.8 releases/v6.5.7 releases/v6.5.6 releases/v6.5.5 releases/v6.5.4 releases/v6.5.3 releases/v6.5.2 releases/v6.5.1 releases/v6.5.0 releases/v6.4.2 releases/v6.4.1 releases/v6.4.0 releases/v6.3.3 releases/v6.3.2 releases/v6.3.1 releases/v6.3.0 releases/v6.2.0 releases/v6.1.0 releases/v6.0.4 releases/v6.0.3 releases/v6.0.2 releases/v6.0.1 releases/v6.0.0 releases/v5.1.1 releases/v5.1.0 releases/v5.0.2 releases/v5.0.1 releases/v5.0.0 releases/v4.5.3 releases/v4.5.2 releases/v4.5.1 releases/v4.5.0 releases/v4.4.3 releases/v4.4.2 releases/v4.4.1 releases/v4.4.0 releases/v4.3.0 releases/v4.2.1 releases/v4.2.0 releases/v4.1.0 releases/v4.0.2 releases/v4.0.1 releases/v4.0.0 releases/v3.2.2</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7"><code>a55abe3</code></a> Merge pull request <a href="https://redirect.github.com/tornadoweb/tornado/issues/3704">#3704</a> from bdarnell/security-6.5.8</li> <li><a href="https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c"><code>fc79488</code></a> docs: add additional credit to release notes</li> <li><a href="https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129"><code>7b01763</code></a> Fix test_strip_headers_on_redirect's URL-embedded-credentials cases</li> <li><a href="https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c"><code>d72fff8</code></a> release notes and version bump for 6.5.8</li> <li><a href="https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e"><code>b168818</code></a> auth: Formally deprecated OpenIDMixin</li> <li><a href="https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7"><code>da28476</code></a> web: Also check for semicolons in deprecated mixed-case cookie args</li> <li><a href="https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de"><code>8d6363e</code></a> httputil: Enforce a new limit on the number of arguments in a request</li> <li><a href="https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05"><code>de85b3f</code></a> httputil: Apply multipart max_parts limit earlier</li> <li>See full diff in <a href="https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1490686e09 |
chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/text-splitters (#40112)
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.7 to 6.5.8. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's changelog</a>.</em></p> <blockquote> <h1>Release notes</h1> <p>.. toctree:: :maxdepth: 2</p> <p>releases/v6.5.8 releases/v6.5.7 releases/v6.5.6 releases/v6.5.5 releases/v6.5.4 releases/v6.5.3 releases/v6.5.2 releases/v6.5.1 releases/v6.5.0 releases/v6.4.2 releases/v6.4.1 releases/v6.4.0 releases/v6.3.3 releases/v6.3.2 releases/v6.3.1 releases/v6.3.0 releases/v6.2.0 releases/v6.1.0 releases/v6.0.4 releases/v6.0.3 releases/v6.0.2 releases/v6.0.1 releases/v6.0.0 releases/v5.1.1 releases/v5.1.0 releases/v5.0.2 releases/v5.0.1 releases/v5.0.0 releases/v4.5.3 releases/v4.5.2 releases/v4.5.1 releases/v4.5.0 releases/v4.4.3 releases/v4.4.2 releases/v4.4.1 releases/v4.4.0 releases/v4.3.0 releases/v4.2.1 releases/v4.2.0 releases/v4.1.0 releases/v4.0.2 releases/v4.0.1 releases/v4.0.0 releases/v3.2.2</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7"><code>a55abe3</code></a> Merge pull request <a href="https://redirect.github.com/tornadoweb/tornado/issues/3704">#3704</a> from bdarnell/security-6.5.8</li> <li><a href="https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c"><code>fc79488</code></a> docs: add additional credit to release notes</li> <li><a href="https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129"><code>7b01763</code></a> Fix test_strip_headers_on_redirect's URL-embedded-credentials cases</li> <li><a href="https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c"><code>d72fff8</code></a> release notes and version bump for 6.5.8</li> <li><a href="https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e"><code>b168818</code></a> auth: Formally deprecated OpenIDMixin</li> <li><a href="https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7"><code>da28476</code></a> web: Also check for semicolons in deprecated mixed-case cookie args</li> <li><a href="https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de"><code>8d6363e</code></a> httputil: Enforce a new limit on the number of arguments in a request</li> <li><a href="https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05"><code>de85b3f</code></a> httputil: Apply multipart max_parts limit earlier</li> <li>See full diff in <a href="https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
07b2085c8a |
chore(deps): bump orjson from 3.11.6 to 3.12.0 in /libs/partners/huggingface (#40115)
[//]: # (dependabot-start) ⚠️ **Dependabot is rebasing this PR** ⚠️ Rebasing might not happen immediately, so don't worry if this takes some time. Note: if you make any changes to this PR yourself, they will take precedence over the rebase. --- [//]: # (dependabot-end) Bumps [orjson](https://github.com/ijl/orjson) from 3.11.6 to 3.12.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ijl/orjson/releases">orjson's releases</a>.</em></p> <blockquote> <h2>3.12.0</h2> <h3>Changed</h3> <ul> <li>Serialization implementation substantially rewritten.</li> <li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later, <code>manylinux_2_39</code> (2024) is targeted instead of <code>manylinux_2_17</code> (2012).</li> <li>No longer publish PyPI wheels for ppc64le and s390x.</li> </ul> <h2>3.11.9</h2> <h3>Changed</h3> <ul> <li>Build now depends on Rust 1.95 or later instead of 1.89.</li> </ul> <h3>Fixed</h3> <ul> <li>Fix building on Rust 1.95.</li> </ul> <h2>3.11.8</h2> <h3>Changed</h3> <ul> <li>Build and compatibility improvements.</li> </ul> <h2>3.11.7</h2> <h3>Changed</h3> <ul> <li>Use a faster library to serialize <code>float</code>. Users with byte-exact regression tests should note positive exponents are now written using a <code>+</code>, e.g., <code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are spec-compliant.</li> <li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/ijl/orjson/blob/master/CHANGELOG.md">orjson's changelog</a>.</em></p> <blockquote> <h2>3.12.0 - 2026-08-14</h2> <h3>Changed</h3> <ul> <li>Serialization implementation substantially rewritten.</li> <li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later, <code>manylinux_2_39</code> (2024) is targeted instead of <code>manylinux_2_17</code> (2012).</li> <li>No longer publish PyPI wheels for ppc64le and s390x.</li> </ul> <h2>3.11.9 - 2026-05-06</h2> <h3>Changed</h3> <ul> <li>Build now depends on Rust 1.95 or later instead of 1.89.</li> </ul> <h3>Fixed</h3> <ul> <li>Fix building on Rust 1.95.</li> </ul> <h2>3.11.8 - 2026-03-31</h2> <h3>Changed</h3> <ul> <li>Build and compatibility improvements.</li> </ul> <h2>3.11.7 - 2026-02-02</h2> <h3>Changed</h3> <ul> <li>Use a faster library to serialize <code>float</code>. Users with byte-exact regression tests should note positive exponents are now written using a <code>+</code>, e.g., <code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are spec-compliant.</li> <li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/ijl/orjson/commit/6737895a1a4e3e26df0569a40147893a786f9a58"><code>6737895</code></a> 3.12.0</li> <li><a href="https://github.com/ijl/orjson/commit/c2a6e8ff7b898635fb68a85bd5a62df1edf61cfc"><code>c2a6e8f</code></a> JsonWriter, iterators</li> <li><a href="https://github.com/ijl/orjson/commit/6a2d7a7d66dc3c5698625a7b334c40db459e46ae"><code>6a2d7a7</code></a> yyjson 1ea2fb0</li> <li><a href="https://github.com/ijl/orjson/commit/97bf170d9726e91c891f35eae4892801520b9dce"><code>97bf170</code></a> build update</li> <li><a href="https://github.com/ijl/orjson/commit/705515d77b28429d0b7c30c3d781abe52e8a1e5a"><code>705515d</code></a> 3.11.9</li> <li><a href="https://github.com/ijl/orjson/commit/d19055d5bab432f98d53b71606a9c6c23fb21bf6"><code>d19055d</code></a> build update</li> <li><a href="https://github.com/ijl/orjson/commit/77e2d96c3febe099cde2447856fe2523d68c71b0"><code>77e2d96</code></a> MSRV 1.95, remove compiler feature detection</li> <li><a href="https://github.com/ijl/orjson/commit/5cbb3d0398a2f42de51210270286fecd798c5d78"><code>5cbb3d0</code></a> 3.11.8</li> <li><a href="https://github.com/ijl/orjson/commit/4195d7f263e33076295b75efdcbaf6a55af8674e"><code>4195d7f</code></a> writer::half</li> <li><a href="https://github.com/ijl/orjson/commit/d00641b69410728a735f0855eb1c2843b0a5819b"><code>d00641b</code></a> writer::uuid</li> <li>Additional commits viewable in <a href="https://github.com/ijl/orjson/compare/3.11.6...3.12.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
379bdc448c |
chore(deps): bump requests from 2.33.0 to 2.34.2 in /libs/partners/huggingface (#40116)
[//]: # (dependabot-start) ⚠️ **Dependabot is rebasing this PR** ⚠️ Rebasing might not happen immediately, so don't worry if this takes some time. Note: if you make any changes to this PR yourself, they will take precedence over the rebase. --- [//]: # (dependabot-end) Bumps [requests](https://github.com/psf/requests) from 2.33.0 to 2.34.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/psf/requests/releases">requests's releases</a>.</em></p> <blockquote> <h2>v2.34.2</h2> <h2>2.34.2 (2026-05-14)</h2> <ul> <li>Moved <code>headers</code> input type back to <code>Mapping</code> to avoid invariance issues with <code>MutableMapping</code> and inferred dict types. Users calling <code>Request.headers.update()</code> may need to narrow typing in their code. (<a href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14">https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14</a></p> <h2>v2.34.1</h2> <h2>2.34.1 (2026-05-13)</h2> <p><strong>Bugfixes</strong></p> <ul> <li>Widened <code>json</code> input type from <code>dict</code> and <code>list</code> to <code>Mapping</code> and <code>Sequence</code>. (<a href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li> <li>Changed <code>headers</code> input type to MutableMapping and removed <code>None</code> from <code>Request.headers</code> typing to improve handling for users. (<a href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li> <li><code>Response.reason</code> moved from <code>str | None</code> to <code>str</code> to improve handling for users. (<a href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li> <li>Fixed a bug where some bodies with custom <code>__getattr__</code> implementations weren't being properly detected as Iterables. (<a href="https://redirect.github.com/psf/requests/issues/7433">#7433</a>)</li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/k223kim"><code>@k223kim</code></a> made their first contribution in <a href="https://redirect.github.com/psf/requests/pull/7433">psf/requests#7433</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13">https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13</a></p> <h2>v2.34.0</h2> <h2>2.34.0 (2026-05-11)</h2> <p><strong>Announcements</strong></p> <ul> <li> <p>Requests 2.34.0 introduces inline types, replacing those provided by typeshed. Public API types should be fully compatible with mypy, pyright, and ty. <strong>We believe types are comprehensive but if you find issues, please report them to the <a href="https://redirect.github.com/psf/requests/issues/7271">pinned tracking issue</a>.</strong></p> <p>Special thanks to <a href="https://github.com/bastimeyer"><code>@bastimeyer</code></a>, <a href="https://github.com/cthoyt"><code>@cthoyt</code></a>, <a href="https://github.com/edgarrmondragon"><code>@edgarrmondragon</code></a>, and <a href="https://github.com/srittau"><code>@srittau</code></a> for helping review and test the types ahead of the release. (<a href="https://redirect.github.com/psf/requests/issues/7272">#7272</a>)</p> </li> </ul> <p><strong>Improvements</strong></p> <ul> <li>Digest Auth hashing algorithms have added <code>usedforsecurity=False</code> to clarify security considerations. (<a href="https://redirect.github.com/psf/requests/issues/7310">#7310</a>)</li> <li>Requests added support for Python 3.15 based on beta1. Downstream projects should be able to start testing prior to its release in October. (<a href="https://redirect.github.com/psf/requests/issues/7422">#7422</a>)</li> <li>Requests added support for Python 3.14t. (<a href="https://redirect.github.com/psf/requests/issues/7419">#7419</a>)</li> </ul> <p><strong>Bugfixes</strong></p> <ul> <li><code>Response.history</code> no longer contains a reference to itself, preventing accidental looping when traversing the history list. (<a href="https://redirect.github.com/psf/requests/issues/7328">#7328</a>)</li> <li>Requests no longer performs greedy matching on no_proxy domains. The</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/psf/requests/blob/main/HISTORY.md">requests's changelog</a>.</em></p> <blockquote> <h2>2.34.2 (2026-05-14)</h2> <ul> <li>Moved <code>headers</code> input type back to <code>Mapping</code> to avoid invariance issues with <code>MutableMapping</code> and inferred dict types. Users calling <code>Request.headers.update()</code> may need to narrow typing in their code. (<a href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li> </ul> <h2>2.34.1 (2026-05-13)</h2> <p><strong>Bugfixes</strong></p> <ul> <li>Widened <code>json</code> input type from <code>dict</code> and <code>list</code> to <code>Mapping</code> and <code>Sequence</code>. (<a href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li> <li>Changed <code>headers</code> input type to MutableMapping and removed <code>None</code> from <code>Request.headers</code> typing to improve handling for users. (<a href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li> <li><code>Response.reason</code> moved from <code>str | None</code> to <code>str</code> to improve handling for users. (<a href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li> <li>Fixed a bug where some bodies with custom <code>__getattr__</code> implementations weren't being properly detected as Iterables. (<a href="https://redirect.github.com/psf/requests/issues/7433">#7433</a>)</li> </ul> <h2>2.34.0 (2026-05-11)</h2> <p><strong>Announcements</strong></p> <ul> <li> <p>Requests 2.34.0 introduces inline types, replacing those provided by typeshed. Public API types should be fully compatible with mypy, pyright, and ty. We believe types are comprehensive but if you find issues, please report them to the pinned tracking issue.</p> <p>Special thanks to <a href="https://github.com/bastimeyer"><code>@bastimeyer</code></a>, <a href="https://github.com/cthoyt"><code>@cthoyt</code></a>, <a href="https://github.com/edgarrmondragon"><code>@edgarrmondragon</code></a>, and <a href="https://github.com/srittau"><code>@srittau</code></a> for helping review and test the types ahead of the release. (<a href="https://redirect.github.com/psf/requests/issues/7272">#7272</a>)</p> </li> </ul> <p><strong>Improvements</strong></p> <ul> <li>Digest Auth hashing algorithms have added <code>usedforsecurity=False</code> to clarify security considerations. (<a href="https://redirect.github.com/psf/requests/issues/7310">#7310</a>)</li> <li>Requests added support for Python 3.15 based on beta1. Downstream projects should be able to start testing prior to its release in October. (<a href="https://redirect.github.com/psf/requests/issues/7422">#7422</a>)</li> <li>Requests added support for Python 3.14t. (<a href="https://redirect.github.com/psf/requests/issues/7419">#7419</a>)</li> </ul> <p><strong>Bugfixes</strong></p> <ul> <li><code>Response.history</code> no longer contains a reference to itself, preventing accidental looping when traversing the history list. (<a href="https://redirect.github.com/psf/requests/issues/7328">#7328</a>)</li> <li>Requests no longer performs greedy matching on no_proxy domains. The proxy_bypass implementation has been updated with CPython's fix from bpo-39057. (<a href="https://redirect.github.com/psf/requests/issues/7427">#7427</a>)</li> <li>Requests no longer incorrectly strips duplicate leading slashes in URI paths. This should address user issues with specific presigned URLs. Note the full fix requires urllib3 2.7.0+. (<a href="https://redirect.github.com/psf/requests/issues/7315">#7315</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3"><code>6e83187</code></a> v2.34.2</li> <li><a href="https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b"><code>84d10f0</code></a> Move Request.headers back to Mapping (<a href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li> <li><a href="https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224"><code>b7b549b</code></a> v2.34.1</li> <li><a href="https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe"><code>e511bc7</code></a> Fix mutability issues with headers input types (<a href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li> <li><a href="https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61"><code>5691f59</code></a> Update JsonType containers to read-based collections (<a href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li> <li><a href="https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035"><code>2144213</code></a> Constrain Response.reason to str (<a href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li> <li><a href="https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232"><code>6404f34</code></a> Fix <code>prepare_body</code> stream detection for <code>__getattr__</code>-based file wrappers (<a href="https://redirect.github.com/psf/requests/issues/7">#7</a>...</li> <li><a href="https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca"><code>0b401c7</code></a> v2.34.0</li> <li><a href="https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4"><code>86b378d</code></a> Align Session.get parameters with requests.get (<a href="https://redirect.github.com/psf/requests/issues/7429">#7429</a>)</li> <li><a href="https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f"><code>a4f9a59</code></a> Port bpo-39057 to Requests (<a href="https://redirect.github.com/psf/requests/issues/7427">#7427</a>)</li> <li>Additional commits viewable in <a href="https://github.com/psf/requests/compare/v2.33.0...v2.34.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
7c1e6ab62a |
chore(deps): bump filelock from 3.20.3 to 3.32.5 in /libs/partners/huggingface (#40118)
[//]: # (dependabot-start) ⚠️ **Dependabot is rebasing this PR** ⚠️ Rebasing might not happen immediately, so don't worry if this takes some time. Note: if you make any changes to this PR yourself, they will take precedence over the rebase. --- [//]: # (dependabot-end) Bumps [filelock](https://github.com/tox-dev/py-filelock) from 3.20.3 to 3.32.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/tox-dev/py-filelock/releases">filelock's releases</a>.</em></p> <blockquote> <h2>3.32.5</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🧪 test(fork): report where a stalled fork stops by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/715">tox-dev/filelock#715</a></li> <li>📝 docs: say that mode is read-only in the thread-local section by <a href="https://github.com/Gares95"><code>@Gares95</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/716">tox-dev/filelock#716</a></li> <li>🐛 fix(lease): clear token after failed acquire by <a href="https://github.com/lprnmns"><code>@lprnmns</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/721">tox-dev/filelock#721</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/lprnmns"><code>@lprnmns</code></a> made their first contribution in <a href="https://redirect.github.com/tox-dev/filelock/pull/721">tox-dev/filelock#721</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5">https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5</a></p> <h2>3.32.4</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🐛 fix: retry transient denials on open and claim read by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/705">tox-dev/filelock#705</a></li> <li>🧪 test: deflake six scheduled-run failures by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/704">tox-dev/filelock#704</a></li> <li>🧪 test: cover a reclaimed private record for real by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/706">tox-dev/filelock#706</a></li> <li>🧪 test(fork): fork once the event loop has closed by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/714">tox-dev/filelock#714</a></li> <li>🔧 chore: batch dependency updates weekly on Tuesday by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/713">tox-dev/filelock#713</a></li> <li>escape the hostname every marker publishes by <a href="https://github.com/dxbjavid"><code>@dxbjavid</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/709">tox-dev/filelock#709</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4">https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4</a></p> <h2>3.32.3</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🧪 test(strict): deflake close-fault injections on graalpy by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/697">tox-dev/filelock#697</a></li> <li>📄 docs: publish llms.txt from the docs build by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/700">tox-dev/filelock#700</a></li> <li>🐛 fix(fork): survive audit events during interpreter shutdown by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/703">tox-dev/filelock#703</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/filelock/compare/3.32.2...3.32.3">https://github.com/tox-dev/filelock/compare/3.32.2...3.32.3</a></p> <h2>3.32.2</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>Fix test failures on NetBSD (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/689">#689</a>) by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/693">tox-dev/filelock#693</a></li> <li>🧪 test(soft-rw): deflake writer phase-2 peer-marker test by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/694">tox-dev/filelock#694</a></li> <li>hand back the claim when a heartbeat thread fails to start by <a href="https://github.com/dxbjavid"><code>@dxbjavid</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/691">tox-dev/filelock#691</a></li> <li>🧪 test(unix): deflake sticky-bit concurrent-unlink on graalpy by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/695">tox-dev/filelock#695</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/filelock/compare/3.32.1...3.32.2">https://github.com/tox-dev/filelock/compare/3.32.1...3.32.2</a></p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst">filelock's changelog</a>.</em></p> <blockquote> <p>########### Changelog ###########</p> <p>.. towncrier-draft-entries:: Unreleased</p> <p>.. towncrier release notes start</p> <hr /> <p>3.32.5 (2026-08-31)</p> <hr /> <ul> <li><code>SoftFileLease.token</code> and <code>AsyncSoftFileLease.token</code> now read <code>None</code> after a failed acquisition, so a contender turned away by a live holder no longer reports a token for a claim it never published. :pr:<code>721</code></li> <li>Document that <code>mode</code> has no setter: unlike <code>poll_interval</code>, <code>timeout</code>, <code>blocking</code> and <code>lifetime</code>, it is fixed at construction and <code>lock.mode = ...</code> raises <code>AttributeError</code>. :pr:<code>716</code></li> </ul> <hr /> <p>3.32.4 (2026-08-23)</p> <hr /> <ul> <li><code>StrictSoftFileLock</code> always retries a claim read whose first attempt reports the claim as pending, so a first read that itself outlasts the retry grace no longer fails closed on a claim it could have read. :pr:<code>705</code></li> <li><code>WindowsFileLock</code> waits out a transient <code>STATUS_ACCESS_DENIED</code> from <code>NtCreateFile</code> for up to half a second before raising <code>PermissionError</code>, since a peer unlinking the lock file as it releases can answer that for a moment; a real denial still fails fast. :pr:<code>705</code></li> <li>Every lock class now escapes the hostname it publishes, so a host whose <code>socket.gethostname()</code> carries a space, a newline or a byte outside UTF-8 no longer writes a marker it reads back as malformed. Such a host used to lose a held <code>SoftReadWriteLock</code> read slot to a peer and could not take a write slot or a <code>StrictSoftFileLock</code> at all. :pr:<code>709</code></li> </ul> <hr /> <p>3.32.3 (2026-08-13)</p> <hr /> <ul> <li>The fork-safety audit hook no longer prints <code>Exception ignored in audit hook</code> with a <code>TypeError</code> when an audit event fires during interpreter shutdown, after CPython has already cleared the module globals. :pr:<code>701</code></li> </ul> <hr /> <p>3.32.2 (2026-07-29)</p> <hr /> <ul> <li>A <code>SoftReadWriteLock</code> or <code>SoftFileLease</code> acquire whose heartbeat thread fails to start now unlinks its marker and hands the claim back, instead of leaving an unrefreshed marker a peer takes while the caller believes it still holds the lock. :pr:<code>691</code></li> </ul> <hr /> <p>3.32.1 (2026-07-26)</p> <hr /> <ul> <li>Canceling an <code>AsyncSoftReadWriteLock</code> acquire now releases the claim instead of leaking a marker whose heartbeat wedges every contender. :pr:<code>686</code></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tox-dev/filelock/commit/1585dfef9355a5c77d4a9498cc34d3a98056fdb9"><code>1585dfe</code></a> Release 3.32.5</li> <li><a href="https://github.com/tox-dev/filelock/commit/00177c32686e60bc5ef9875b5841867ea08d4558"><code>00177c3</code></a> 🐛 fix(lease): clear token after failed acquire (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/721">#721</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/5aeb9b6a5fe1e86dcb1c44a927aefffd607b17b0"><code>5aeb9b6</code></a> 📝 docs: say that mode is read-only in the thread-local section (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/716">#716</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/2634dd1dcc597b319770df027491f16d07662952"><code>2634dd1</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/720">#720</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/37dccf0276f6db1520db9e3482fdf0446c14276e"><code>37dccf0</code></a> 🧪 test(fork): report where a stalled fork stops (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/715">#715</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/cb493d6684ed5d2f923384633c86fef12e29bce2"><code>cb493d6</code></a> Release 3.32.4</li> <li><a href="https://github.com/tox-dev/filelock/commit/fe07a11a7133ddd104322eb79d3c59f966b4ba15"><code>fe07a11</code></a> escape the hostname every marker publishes (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/709">#709</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/232732f49ed9d230802f527ad60b5d5ad1202a56"><code>232732f</code></a> 🔧 chore: batch dependency updates weekly on Tuesday (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/713">#713</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/2966eb51431ff8ac19eb2bec4e0b67c328437c48"><code>2966eb5</code></a> 🧪 test(fork): fork once the event loop has closed (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/714">#714</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/61511ebc1cc5d40b28f8584f1078e63f2d63fb02"><code>61511eb</code></a> build(deps): bump astral-sh/setup-uv from 10.0.0 to 10.0.1 (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/712">#712</a>)</li> <li>Additional commits viewable in <a href="https://github.com/tox-dev/py-filelock/compare/3.20.3...3.32.5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
37b937e05d |
chore(deps): bump langsmith from 0.10.16 to 0.12.1 in /libs/partners/huggingface (#40119)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from 0.10.16 to 0.12.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's releases</a>.</em></p> <blockquote> <h2>v0.12.1</h2> <h2>What's Changed</h2> <ul> <li>release(js): 0.10.0 by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3474">langchain-ai/langsmith-sdk#3474</a></li> <li>fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3475">langchain-ai/langsmith-sdk#3475</a></li> <li>release(py): 0.12.1 by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3478">langchain-ai/langsmith-sdk#3478</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1">https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1</a></p> <h2>v0.12.0</h2> <h2>What's Changed</h2> <ul> <li>ci: enable CodSpeed flame graphs and pin the benchmarks to one CPU by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3449">langchain-ai/langsmith-sdk#3449</a></li> <li>fix(py,js)!: make trace sampling deterministic by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3183">langchain-ai/langsmith-sdk#3183</a></li> <li>fix(py): suppress import-untyped on the optional langsmith_pyo3 import by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3462">langchain-ai/langsmith-sdk#3462</a></li> <li>chore(py)!: swtich to httpx2 dependency while keeping httpx as a fallback by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3406">langchain-ai/langsmith-sdk#3406</a></li> <li>fix!: fail-closed when per-function anonymization callables fail by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3328">langchain-ai/langsmith-sdk#3328</a></li> <li>fix(py): compress replica writes that carry their own credentials by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3448">langchain-ai/langsmith-sdk#3448</a></li> <li>perf(py): serialize identical replicas once, into one frame by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3450">langchain-ai/langsmith-sdk#3450</a></li> <li>release(py): 0.12.0 by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3472">langchain-ai/langsmith-sdk#3472</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0</a></p> <h2>v0.11.2</h2> <h2>What's Changed</h2> <ul> <li>fix: exclude password and email env vars from run metadata by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3417">langchain-ai/langsmith-sdk#3417</a></li> <li>feat(js): Avoid redundantly sending inputs up in patch by <a href="https://github.com/jacoblee93"><code>@jacoblee93</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3425">langchain-ai/langsmith-sdk#3425</a></li> <li>release(js): 0.9.0 by <a href="https://github.com/jacoblee93"><code>@jacoblee93</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3426">langchain-ai/langsmith-sdk#3426</a></li> <li>test(py): continuous benchmarking with CodSpeed by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3420">langchain-ai/langsmith-sdk#3420</a></li> <li>fix: point migration guide links at their new per-area pages by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3421">langchain-ai/langsmith-sdk#3421</a></li> <li>fix(js): send langsmith-js User-Agent on generated client calls by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3411">langchain-ai/langsmith-sdk#3411</a></li> <li>test(py): pin multipart ingest retry matrix and drop warning by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3377">langchain-ai/langsmith-sdk#3377</a></li> <li>chore: sync langsmith_api by <a href="https://github.com/langtions-bot"><code>@langtions-bot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3407">langchain-ai/langsmith-sdk#3407</a></li> <li>fix(py): handle 64bit+ integers without loss of precision by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3409">langchain-ai/langsmith-sdk#3409</a></li> <li>fix(py): exclude replica config from the serialized run body by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3442">langchain-ai/langsmith-sdk#3442</a></li> <li>fix(py,js): consistent (non-v7) UUID rewriting for replicas by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3445">langchain-ai/langsmith-sdk#3445</a></li> <li>ci: report Python benchmarks to Datadog Test Optimization by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3408">langchain-ai/langsmith-sdk#3408</a></li> <li>fix(js): close the argument-shape bypass in Anthropic MCP redaction by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3378">langchain-ai/langsmith-sdk#3378</a></li> <li>feat(livekit): align trace audio with the span timeline by <a href="https://github.com/carolinedivittorio"><code>@carolinedivittorio</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3452">langchain-ai/langsmith-sdk#3452</a></li> <li>release(py): 0.11.2 by <a href="https://github.com/carolinedivittorio"><code>@carolinedivittorio</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3457">langchain-ai/langsmith-sdk#3457</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2</a></p> <h2>v0.11.1</h2> <h2>What's Changed</h2> <ul> <li>release(js): 0.8.11 by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3401">langchain-ai/langsmith-sdk#3401</a></li> <li>chore: sync langsmith_api by <a href="https://github.com/langtions-bot"><code>@langtions-bot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3340">langchain-ai/langsmith-sdk#3340</a></li> <li>fix(sandbox): retry transient WebSocket upgrades in Python and JS by <a href="https://github.com/ramon-langchain"><code>@ramon-langchain</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3388">langchain-ai/langsmith-sdk#3388</a></li> <li>fix: report incomplete pytest suites accurately by <a href="https://github.com/jkennedyvz"><code>@jkennedyvz</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3398">langchain-ai/langsmith-sdk#3398</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/11093852f2fe7b4fc63b88565da37d6cb796bcda"><code>1109385</code></a> release(py): 0.12.1 (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3478">#3478</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/73ac3029c90a8d64aadb71848db87f83acaf97a5"><code>73ac302</code></a> fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3475">#3475</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/11f7208efcf2484d020ecd6d6ba4f4d6f675a606"><code>11f7208</code></a> release(js): 0.10.0 (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3474">#3474</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/a95cddfe4f406bdef6d92213e7ff30bb7c980d85"><code>a95cddf</code></a> release(py): 0.12.0 (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3472">#3472</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/4ddfa249823d102183054c750fc4ba4a9a356899"><code>4ddfa24</code></a> perf(py): serialize identical replicas once, into one frame (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3450">#3450</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/983e00acc1c7a5f944fe530db8d0aa13063a2392"><code>983e00a</code></a> fix(py): compress replica writes that carry their own credentials (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3448">#3448</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/3239181c87dbdb5815746534cd9082227a443595"><code>3239181</code></a> fix!: fail-closed when per-function anonymization callables fail (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3328">#3328</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/0d3256709ee31a73647cee4846256ecf0be38932"><code>0d32567</code></a> chore(py)!: swtich to httpx2 dependency while keeping httpx as a fallback (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3">#3</a>...</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/1b64f94fe226f07fcacc81ea8a3e7486c1fc5c14"><code>1b64f94</code></a> fix(py): suppress import-untyped on the optional langsmith_pyo3 import (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3462">#3462</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/e5360c9833cfad5dc20beeef5f42dcd7bd1b4116"><code>e5360c9</code></a> fix(py,js)!: make trace sampling deterministic (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3183">#3183</a>)</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.16...v0.12.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
c50b358308 |
chore(deps): bump requests from 2.33.0 to 2.34.2 in /libs/partners/chroma (#40127)
Bumps [requests](https://github.com/psf/requests) from 2.33.0 to 2.34.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/psf/requests/releases">requests's releases</a>.</em></p> <blockquote> <h2>v2.34.2</h2> <h2>2.34.2 (2026-05-14)</h2> <ul> <li>Moved <code>headers</code> input type back to <code>Mapping</code> to avoid invariance issues with <code>MutableMapping</code> and inferred dict types. Users calling <code>Request.headers.update()</code> may need to narrow typing in their code. (<a href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14">https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14</a></p> <h2>v2.34.1</h2> <h2>2.34.1 (2026-05-13)</h2> <p><strong>Bugfixes</strong></p> <ul> <li>Widened <code>json</code> input type from <code>dict</code> and <code>list</code> to <code>Mapping</code> and <code>Sequence</code>. (<a href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li> <li>Changed <code>headers</code> input type to MutableMapping and removed <code>None</code> from <code>Request.headers</code> typing to improve handling for users. (<a href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li> <li><code>Response.reason</code> moved from <code>str | None</code> to <code>str</code> to improve handling for users. (<a href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li> <li>Fixed a bug where some bodies with custom <code>__getattr__</code> implementations weren't being properly detected as Iterables. (<a href="https://redirect.github.com/psf/requests/issues/7433">#7433</a>)</li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/k223kim"><code>@k223kim</code></a> made their first contribution in <a href="https://redirect.github.com/psf/requests/pull/7433">psf/requests#7433</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13">https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13</a></p> <h2>v2.34.0</h2> <h2>2.34.0 (2026-05-11)</h2> <p><strong>Announcements</strong></p> <ul> <li> <p>Requests 2.34.0 introduces inline types, replacing those provided by typeshed. Public API types should be fully compatible with mypy, pyright, and ty. <strong>We believe types are comprehensive but if you find issues, please report them to the <a href="https://redirect.github.com/psf/requests/issues/7271">pinned tracking issue</a>.</strong></p> <p>Special thanks to <a href="https://github.com/bastimeyer"><code>@bastimeyer</code></a>, <a href="https://github.com/cthoyt"><code>@cthoyt</code></a>, <a href="https://github.com/edgarrmondragon"><code>@edgarrmondragon</code></a>, and <a href="https://github.com/srittau"><code>@srittau</code></a> for helping review and test the types ahead of the release. (<a href="https://redirect.github.com/psf/requests/issues/7272">#7272</a>)</p> </li> </ul> <p><strong>Improvements</strong></p> <ul> <li>Digest Auth hashing algorithms have added <code>usedforsecurity=False</code> to clarify security considerations. (<a href="https://redirect.github.com/psf/requests/issues/7310">#7310</a>)</li> <li>Requests added support for Python 3.15 based on beta1. Downstream projects should be able to start testing prior to its release in October. (<a href="https://redirect.github.com/psf/requests/issues/7422">#7422</a>)</li> <li>Requests added support for Python 3.14t. (<a href="https://redirect.github.com/psf/requests/issues/7419">#7419</a>)</li> </ul> <p><strong>Bugfixes</strong></p> <ul> <li><code>Response.history</code> no longer contains a reference to itself, preventing accidental looping when traversing the history list. (<a href="https://redirect.github.com/psf/requests/issues/7328">#7328</a>)</li> <li>Requests no longer performs greedy matching on no_proxy domains. The</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/psf/requests/blob/main/HISTORY.md">requests's changelog</a>.</em></p> <blockquote> <h2>2.34.2 (2026-05-14)</h2> <ul> <li>Moved <code>headers</code> input type back to <code>Mapping</code> to avoid invariance issues with <code>MutableMapping</code> and inferred dict types. Users calling <code>Request.headers.update()</code> may need to narrow typing in their code. (<a href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li> </ul> <h2>2.34.1 (2026-05-13)</h2> <p><strong>Bugfixes</strong></p> <ul> <li>Widened <code>json</code> input type from <code>dict</code> and <code>list</code> to <code>Mapping</code> and <code>Sequence</code>. (<a href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li> <li>Changed <code>headers</code> input type to MutableMapping and removed <code>None</code> from <code>Request.headers</code> typing to improve handling for users. (<a href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li> <li><code>Response.reason</code> moved from <code>str | None</code> to <code>str</code> to improve handling for users. (<a href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li> <li>Fixed a bug where some bodies with custom <code>__getattr__</code> implementations weren't being properly detected as Iterables. (<a href="https://redirect.github.com/psf/requests/issues/7433">#7433</a>)</li> </ul> <h2>2.34.0 (2026-05-11)</h2> <p><strong>Announcements</strong></p> <ul> <li> <p>Requests 2.34.0 introduces inline types, replacing those provided by typeshed. Public API types should be fully compatible with mypy, pyright, and ty. We believe types are comprehensive but if you find issues, please report them to the pinned tracking issue.</p> <p>Special thanks to <a href="https://github.com/bastimeyer"><code>@bastimeyer</code></a>, <a href="https://github.com/cthoyt"><code>@cthoyt</code></a>, <a href="https://github.com/edgarrmondragon"><code>@edgarrmondragon</code></a>, and <a href="https://github.com/srittau"><code>@srittau</code></a> for helping review and test the types ahead of the release. (<a href="https://redirect.github.com/psf/requests/issues/7272">#7272</a>)</p> </li> </ul> <p><strong>Improvements</strong></p> <ul> <li>Digest Auth hashing algorithms have added <code>usedforsecurity=False</code> to clarify security considerations. (<a href="https://redirect.github.com/psf/requests/issues/7310">#7310</a>)</li> <li>Requests added support for Python 3.15 based on beta1. Downstream projects should be able to start testing prior to its release in October. (<a href="https://redirect.github.com/psf/requests/issues/7422">#7422</a>)</li> <li>Requests added support for Python 3.14t. (<a href="https://redirect.github.com/psf/requests/issues/7419">#7419</a>)</li> </ul> <p><strong>Bugfixes</strong></p> <ul> <li><code>Response.history</code> no longer contains a reference to itself, preventing accidental looping when traversing the history list. (<a href="https://redirect.github.com/psf/requests/issues/7328">#7328</a>)</li> <li>Requests no longer performs greedy matching on no_proxy domains. The proxy_bypass implementation has been updated with CPython's fix from bpo-39057. (<a href="https://redirect.github.com/psf/requests/issues/7427">#7427</a>)</li> <li>Requests no longer incorrectly strips duplicate leading slashes in URI paths. This should address user issues with specific presigned URLs. Note the full fix requires urllib3 2.7.0+. (<a href="https://redirect.github.com/psf/requests/issues/7315">#7315</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3"><code>6e83187</code></a> v2.34.2</li> <li><a href="https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b"><code>84d10f0</code></a> Move Request.headers back to Mapping (<a href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li> <li><a href="https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224"><code>b7b549b</code></a> v2.34.1</li> <li><a href="https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe"><code>e511bc7</code></a> Fix mutability issues with headers input types (<a href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li> <li><a href="https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61"><code>5691f59</code></a> Update JsonType containers to read-based collections (<a href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li> <li><a href="https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035"><code>2144213</code></a> Constrain Response.reason to str (<a href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li> <li><a href="https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232"><code>6404f34</code></a> Fix <code>prepare_body</code> stream detection for <code>__getattr__</code>-based file wrappers (<a href="https://redirect.github.com/psf/requests/issues/7">#7</a>...</li> <li><a href="https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca"><code>0b401c7</code></a> v2.34.0</li> <li><a href="https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4"><code>86b378d</code></a> Align Session.get parameters with requests.get (<a href="https://redirect.github.com/psf/requests/issues/7429">#7429</a>)</li> <li><a href="https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f"><code>a4f9a59</code></a> Port bpo-39057 to Requests (<a href="https://redirect.github.com/psf/requests/issues/7427">#7427</a>)</li> <li>Additional commits viewable in <a href="https://github.com/psf/requests/compare/v2.33.0...v2.34.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
6440c8b642 |
chore(deps): bump idna from 3.15 to 3.19 in /libs/partners/huggingface (#40121)
Bumps [idna](https://github.com/kjd/idna) from 3.15 to 3.19. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/kjd/idna/releases">idna's releases</a>.</em></p> <blockquote> <h2>v3.19</h2> <ul> <li>Restore the <code>std3_rules</code> option, which had no effect since changes to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a> processing in Unicode 16. Note that <code>uts46_remap()</code> defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again.</li> <li>Performance improvements to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a> mapping, particularly for ASCII-only domains.</li> <li>Test on free-threaded CPython with the GIL disabled and document thread safety.</li> <li>Expose the Unicode version of the generated tables as <code>idna.unicode_version</code>, and show it in <code>idna --version</code>.</li> <li>Add <code>code</code>, <code>text</code>, <code>codepoint</code> and <code>position</code> attributes to <code>IDNAError</code> so that the failed rule and the offending character can be identified without parsing the exception message.</li> <li>The deprecated <code>transitional</code> argument to <code>encode()</code> and <code>uts46_remap()</code> is now completely ignored, and gives a deprecation warning for the latter.</li> <li>Reject A-labels that are not the canonical Punycode encoding of their U-label.</li> <li>Fix CONTEXTJ violations raising <code>IDNAError</code> instead of <code>InvalidCodepointContext</code>.</li> <li>Consistently raise <code>IDNAError</code> for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec.</li> <li>Add property-based tests, extended fuzzing targets, coverage measurement, and CI checks that the data tables match the generator output.</li> <li>Various code quality and tooling improvements.</li> </ul> <p>Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for contributions to this release.</p> <h2>v3.18</h2> <p>No release notes provided.</p> <h2>v3.17</h2> <p>No release notes provided.</p> <h2>v3.16</h2> <p>No release notes provided.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/kjd/idna/blob/master/HISTORY.md">idna's changelog</a>.</em></p> <blockquote> <h2>3.19 (2026-08-18)</h2> <ul> <li>Restore the <code>std3_rules</code> option, which had no effect since changes to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a> processing in Unicode 16. Note that <code>uts46_remap()</code> defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again.</li> <li>Performance improvements to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a> mapping, particularly for ASCII-only domains.</li> <li>Test on free-threaded CPython with the GIL disabled and document thread safety.</li> <li>Expose the Unicode version of the generated tables as <code>idna.unicode_version</code>, and show it in <code>idna --version</code>.</li> <li>Add <code>code</code>, <code>text</code>, <code>codepoint</code> and <code>position</code> attributes to <code>IDNAError</code> so that the failed rule and the offending character can be identified without parsing the exception message.</li> <li>The deprecated <code>transitional</code> argument to <code>encode()</code> and <code>uts46_remap()</code> is now completely ignored, and gives a deprecation warning for the latter.</li> <li>Reject A-labels that are not the canonical Punycode encoding of their U-label.</li> <li>Fix CONTEXTJ violations raising <code>IDNAError</code> instead of <code>InvalidCodepointContext</code>.</li> <li>Consistently raise <code>IDNAError</code> for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec.</li> <li>Add property-based tests, extended fuzzing targets, coverage measurement, and CI checks that the data tables match the generator output.</li> <li>Various code quality and tooling improvements.</li> </ul> <p>Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for contributions to this release.</p> <h2>3.18 (2026-06-02)</h2> <ul> <li>When decoding a domain, add a <code>display</code> argument that will pass through invalid labels rather than raising an exception.</li> </ul> <h2>3.17 (2026-05-28)</h2> <ul> <li>Substantial 75% reduction in memory usage through new data structures and some optimization in processing speed.</li> <li>Added a general 1024-character input length cap to the public validation, conversion, and codec entry points. This is well above any legitimate domain or label and guards against pathological inputs.</li> </ul> <h2>3.16 (2026-05-22)</h2> <ul> <li>Add a command-line interface (<code>python -m idna</code>, also available as the <code>idna</code> script). Encodes or decodes one or more domains supplied</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/kjd/idna/commit/03a9a11dd8aecd4fea742cabe20f4d3d9ed82abb"><code>03a9a11</code></a> Release 3.19</li> <li><a href="https://github.com/kjd/idna/commit/2d2a7ef0c59210a48407b3dde6d884933cecf093"><code>2d2a7ef</code></a> Pre-release 3.19rc0</li> <li><a href="https://github.com/kjd/idna/commit/5cce1308d148019c5fa0febceafa13e99cdacfe7"><code>5cce130</code></a> Merge pull request <a href="https://redirect.github.com/kjd/idna/issues/268">#268</a> from kjd/fix-std3-regex-alert</li> <li><a href="https://github.com/kjd/idna/commit/3914b75f3e4cbc11e59f92eeecdb16d10871e57f"><code>3914b75</code></a> Split the STD3 disallowed-character range so uppercase is explicit</li> <li><a href="https://github.com/kjd/idna/commit/ce9fd98ac4073866db276e93834b259f2a5a4ac4"><code>ce9fd98</code></a> Merge pull request <a href="https://redirect.github.com/kjd/idna/issues/267">#267</a> from kjd/housekeeping</li> <li><a href="https://github.com/kjd/idna/commit/809240c3cc9358c9c9c79b2d12ffe39e75ccfb0f"><code>809240c</code></a> Fail CI when the license copyright year is behind the current year</li> <li><a href="https://github.com/kjd/idna/commit/d9e16c523d7d25dcc14100fa80f3e303404e09be"><code>d9e16c5</code></a> Consolidate test fixtures, prune stale gitignore entries, and fix doc typos</li> <li><a href="https://github.com/kjd/idna/commit/ef30feeed3a758e96286fdab0315a551f7f5e7d6"><code>ef30fee</code></a> Remove dead code and pare back superfluous comments</li> <li><a href="https://github.com/kjd/idna/commit/b907913f854d26cc714f721c6c2cb626d41ac468"><code>b907913</code></a> Tighten the version support and Unicode notes in the README</li> <li><a href="https://github.com/kjd/idna/commit/6204cbe343ef438df7c58bc80b94d0f960991d90"><code>6204cbe</code></a> Ignore local build artifacts and stop packaging stray tooling config</li> <li>Additional commits viewable in <a href="https://github.com/kjd/idna/compare/v3.15...v3.19">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
6935f7a4b7 |
chore(deps): bump filelock from 3.20.3 to 3.32.5 in /libs/partners/chroma (#40122)
Bumps [filelock](https://github.com/tox-dev/py-filelock) from 3.20.3 to 3.32.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/tox-dev/py-filelock/releases">filelock's releases</a>.</em></p> <blockquote> <h2>3.32.5</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🧪 test(fork): report where a stalled fork stops by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/715">tox-dev/filelock#715</a></li> <li>📝 docs: say that mode is read-only in the thread-local section by <a href="https://github.com/Gares95"><code>@Gares95</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/716">tox-dev/filelock#716</a></li> <li>🐛 fix(lease): clear token after failed acquire by <a href="https://github.com/lprnmns"><code>@lprnmns</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/721">tox-dev/filelock#721</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/lprnmns"><code>@lprnmns</code></a> made their first contribution in <a href="https://redirect.github.com/tox-dev/filelock/pull/721">tox-dev/filelock#721</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5">https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5</a></p> <h2>3.32.4</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🐛 fix: retry transient denials on open and claim read by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/705">tox-dev/filelock#705</a></li> <li>🧪 test: deflake six scheduled-run failures by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/704">tox-dev/filelock#704</a></li> <li>🧪 test: cover a reclaimed private record for real by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/706">tox-dev/filelock#706</a></li> <li>🧪 test(fork): fork once the event loop has closed by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/714">tox-dev/filelock#714</a></li> <li>🔧 chore: batch dependency updates weekly on Tuesday by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/713">tox-dev/filelock#713</a></li> <li>escape the hostname every marker publishes by <a href="https://github.com/dxbjavid"><code>@dxbjavid</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/709">tox-dev/filelock#709</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4">https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4</a></p> <h2>3.32.3</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🧪 test(strict): deflake close-fault injections on graalpy by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/697">tox-dev/filelock#697</a></li> <li>📄 docs: publish llms.txt from the docs build by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/700">tox-dev/filelock#700</a></li> <li>🐛 fix(fork): survive audit events during interpreter shutdown by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/703">tox-dev/filelock#703</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/filelock/compare/3.32.2...3.32.3">https://github.com/tox-dev/filelock/compare/3.32.2...3.32.3</a></p> <h2>3.32.2</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>Fix test failures on NetBSD (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/689">#689</a>) by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/693">tox-dev/filelock#693</a></li> <li>🧪 test(soft-rw): deflake writer phase-2 peer-marker test by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/694">tox-dev/filelock#694</a></li> <li>hand back the claim when a heartbeat thread fails to start by <a href="https://github.com/dxbjavid"><code>@dxbjavid</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/691">tox-dev/filelock#691</a></li> <li>🧪 test(unix): deflake sticky-bit concurrent-unlink on graalpy by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/695">tox-dev/filelock#695</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/filelock/compare/3.32.1...3.32.2">https://github.com/tox-dev/filelock/compare/3.32.1...3.32.2</a></p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst">filelock's changelog</a>.</em></p> <blockquote> <p>########### Changelog ###########</p> <p>.. towncrier-draft-entries:: Unreleased</p> <p>.. towncrier release notes start</p> <hr /> <p>3.32.5 (2026-08-31)</p> <hr /> <ul> <li><code>SoftFileLease.token</code> and <code>AsyncSoftFileLease.token</code> now read <code>None</code> after a failed acquisition, so a contender turned away by a live holder no longer reports a token for a claim it never published. :pr:<code>721</code></li> <li>Document that <code>mode</code> has no setter: unlike <code>poll_interval</code>, <code>timeout</code>, <code>blocking</code> and <code>lifetime</code>, it is fixed at construction and <code>lock.mode = ...</code> raises <code>AttributeError</code>. :pr:<code>716</code></li> </ul> <hr /> <p>3.32.4 (2026-08-23)</p> <hr /> <ul> <li><code>StrictSoftFileLock</code> always retries a claim read whose first attempt reports the claim as pending, so a first read that itself outlasts the retry grace no longer fails closed on a claim it could have read. :pr:<code>705</code></li> <li><code>WindowsFileLock</code> waits out a transient <code>STATUS_ACCESS_DENIED</code> from <code>NtCreateFile</code> for up to half a second before raising <code>PermissionError</code>, since a peer unlinking the lock file as it releases can answer that for a moment; a real denial still fails fast. :pr:<code>705</code></li> <li>Every lock class now escapes the hostname it publishes, so a host whose <code>socket.gethostname()</code> carries a space, a newline or a byte outside UTF-8 no longer writes a marker it reads back as malformed. Such a host used to lose a held <code>SoftReadWriteLock</code> read slot to a peer and could not take a write slot or a <code>StrictSoftFileLock</code> at all. :pr:<code>709</code></li> </ul> <hr /> <p>3.32.3 (2026-08-13)</p> <hr /> <ul> <li>The fork-safety audit hook no longer prints <code>Exception ignored in audit hook</code> with a <code>TypeError</code> when an audit event fires during interpreter shutdown, after CPython has already cleared the module globals. :pr:<code>701</code></li> </ul> <hr /> <p>3.32.2 (2026-07-29)</p> <hr /> <ul> <li>A <code>SoftReadWriteLock</code> or <code>SoftFileLease</code> acquire whose heartbeat thread fails to start now unlinks its marker and hands the claim back, instead of leaving an unrefreshed marker a peer takes while the caller believes it still holds the lock. :pr:<code>691</code></li> </ul> <hr /> <p>3.32.1 (2026-07-26)</p> <hr /> <ul> <li>Canceling an <code>AsyncSoftReadWriteLock</code> acquire now releases the claim instead of leaking a marker whose heartbeat wedges every contender. :pr:<code>686</code></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tox-dev/filelock/commit/1585dfef9355a5c77d4a9498cc34d3a98056fdb9"><code>1585dfe</code></a> Release 3.32.5</li> <li><a href="https://github.com/tox-dev/filelock/commit/00177c32686e60bc5ef9875b5841867ea08d4558"><code>00177c3</code></a> 🐛 fix(lease): clear token after failed acquire (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/721">#721</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/5aeb9b6a5fe1e86dcb1c44a927aefffd607b17b0"><code>5aeb9b6</code></a> 📝 docs: say that mode is read-only in the thread-local section (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/716">#716</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/2634dd1dcc597b319770df027491f16d07662952"><code>2634dd1</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/720">#720</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/37dccf0276f6db1520db9e3482fdf0446c14276e"><code>37dccf0</code></a> 🧪 test(fork): report where a stalled fork stops (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/715">#715</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/cb493d6684ed5d2f923384633c86fef12e29bce2"><code>cb493d6</code></a> Release 3.32.4</li> <li><a href="https://github.com/tox-dev/filelock/commit/fe07a11a7133ddd104322eb79d3c59f966b4ba15"><code>fe07a11</code></a> escape the hostname every marker publishes (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/709">#709</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/232732f49ed9d230802f527ad60b5d5ad1202a56"><code>232732f</code></a> 🔧 chore: batch dependency updates weekly on Tuesday (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/713">#713</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/2966eb51431ff8ac19eb2bec4e0b67c328437c48"><code>2966eb5</code></a> 🧪 test(fork): fork once the event loop has closed (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/714">#714</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/61511ebc1cc5d40b28f8584f1078e63f2d63fb02"><code>61511eb</code></a> build(deps): bump astral-sh/setup-uv from 10.0.0 to 10.0.1 (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/712">#712</a>)</li> <li>Additional commits viewable in <a href="https://github.com/tox-dev/py-filelock/compare/3.20.3...3.32.5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
3f6bfe80a6 |
chore(deps): bump langsmith from 0.10.16 to 0.12.1 in /libs/partners/chroma (#40123)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from 0.10.16 to 0.12.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's releases</a>.</em></p> <blockquote> <h2>v0.12.1</h2> <h2>What's Changed</h2> <ul> <li>release(js): 0.10.0 by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3474">langchain-ai/langsmith-sdk#3474</a></li> <li>fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3475">langchain-ai/langsmith-sdk#3475</a></li> <li>release(py): 0.12.1 by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3478">langchain-ai/langsmith-sdk#3478</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1">https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1</a></p> <h2>v0.12.0</h2> <h2>What's Changed</h2> <ul> <li>ci: enable CodSpeed flame graphs and pin the benchmarks to one CPU by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3449">langchain-ai/langsmith-sdk#3449</a></li> <li>fix(py,js)!: make trace sampling deterministic by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3183">langchain-ai/langsmith-sdk#3183</a></li> <li>fix(py): suppress import-untyped on the optional langsmith_pyo3 import by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3462">langchain-ai/langsmith-sdk#3462</a></li> <li>chore(py)!: swtich to httpx2 dependency while keeping httpx as a fallback by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3406">langchain-ai/langsmith-sdk#3406</a></li> <li>fix!: fail-closed when per-function anonymization callables fail by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3328">langchain-ai/langsmith-sdk#3328</a></li> <li>fix(py): compress replica writes that carry their own credentials by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3448">langchain-ai/langsmith-sdk#3448</a></li> <li>perf(py): serialize identical replicas once, into one frame by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3450">langchain-ai/langsmith-sdk#3450</a></li> <li>release(py): 0.12.0 by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3472">langchain-ai/langsmith-sdk#3472</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0</a></p> <h2>v0.11.2</h2> <h2>What's Changed</h2> <ul> <li>fix: exclude password and email env vars from run metadata by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3417">langchain-ai/langsmith-sdk#3417</a></li> <li>feat(js): Avoid redundantly sending inputs up in patch by <a href="https://github.com/jacoblee93"><code>@jacoblee93</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3425">langchain-ai/langsmith-sdk#3425</a></li> <li>release(js): 0.9.0 by <a href="https://github.com/jacoblee93"><code>@jacoblee93</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3426">langchain-ai/langsmith-sdk#3426</a></li> <li>test(py): continuous benchmarking with CodSpeed by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3420">langchain-ai/langsmith-sdk#3420</a></li> <li>fix: point migration guide links at their new per-area pages by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3421">langchain-ai/langsmith-sdk#3421</a></li> <li>fix(js): send langsmith-js User-Agent on generated client calls by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3411">langchain-ai/langsmith-sdk#3411</a></li> <li>test(py): pin multipart ingest retry matrix and drop warning by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3377">langchain-ai/langsmith-sdk#3377</a></li> <li>chore: sync langsmith_api by <a href="https://github.com/langtions-bot"><code>@langtions-bot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3407">langchain-ai/langsmith-sdk#3407</a></li> <li>fix(py): handle 64bit+ integers without loss of precision by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3409">langchain-ai/langsmith-sdk#3409</a></li> <li>fix(py): exclude replica config from the serialized run body by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3442">langchain-ai/langsmith-sdk#3442</a></li> <li>fix(py,js): consistent (non-v7) UUID rewriting for replicas by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3445">langchain-ai/langsmith-sdk#3445</a></li> <li>ci: report Python benchmarks to Datadog Test Optimization by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3408">langchain-ai/langsmith-sdk#3408</a></li> <li>fix(js): close the argument-shape bypass in Anthropic MCP redaction by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3378">langchain-ai/langsmith-sdk#3378</a></li> <li>feat(livekit): align trace audio with the span timeline by <a href="https://github.com/carolinedivittorio"><code>@carolinedivittorio</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3452">langchain-ai/langsmith-sdk#3452</a></li> <li>release(py): 0.11.2 by <a href="https://github.com/carolinedivittorio"><code>@carolinedivittorio</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3457">langchain-ai/langsmith-sdk#3457</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2</a></p> <h2>v0.11.1</h2> <h2>What's Changed</h2> <ul> <li>release(js): 0.8.11 by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3401">langchain-ai/langsmith-sdk#3401</a></li> <li>chore: sync langsmith_api by <a href="https://github.com/langtions-bot"><code>@langtions-bot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3340">langchain-ai/langsmith-sdk#3340</a></li> <li>fix(sandbox): retry transient WebSocket upgrades in Python and JS by <a href="https://github.com/ramon-langchain"><code>@ramon-langchain</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3388">langchain-ai/langsmith-sdk#3388</a></li> <li>fix: report incomplete pytest suites accurately by <a href="https://github.com/jkennedyvz"><code>@jkennedyvz</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3398">langchain-ai/langsmith-sdk#3398</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/11093852f2fe7b4fc63b88565da37d6cb796bcda"><code>1109385</code></a> release(py): 0.12.1 (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3478">#3478</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/73ac3029c90a8d64aadb71848db87f83acaf97a5"><code>73ac302</code></a> fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3475">#3475</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/11f7208efcf2484d020ecd6d6ba4f4d6f675a606"><code>11f7208</code></a> release(js): 0.10.0 (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3474">#3474</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/a95cddfe4f406bdef6d92213e7ff30bb7c980d85"><code>a95cddf</code></a> release(py): 0.12.0 (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3472">#3472</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/4ddfa249823d102183054c750fc4ba4a9a356899"><code>4ddfa24</code></a> perf(py): serialize identical replicas once, into one frame (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3450">#3450</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/983e00acc1c7a5f944fe530db8d0aa13063a2392"><code>983e00a</code></a> fix(py): compress replica writes that carry their own credentials (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3448">#3448</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/3239181c87dbdb5815746534cd9082227a443595"><code>3239181</code></a> fix!: fail-closed when per-function anonymization callables fail (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3328">#3328</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/0d3256709ee31a73647cee4846256ecf0be38932"><code>0d32567</code></a> chore(py)!: swtich to httpx2 dependency while keeping httpx as a fallback (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3">#3</a>...</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/1b64f94fe226f07fcacc81ea8a3e7486c1fc5c14"><code>1b64f94</code></a> fix(py): suppress import-untyped on the optional langsmith_pyo3 import (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3462">#3462</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/e5360c9833cfad5dc20beeef5f42dcd7bd1b4116"><code>e5360c9</code></a> fix(py,js)!: make trace sampling deterministic (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3183">#3183</a>)</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.16...v0.12.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
dca0ae4913 |
chore(deps): bump protobuf from 6.33.5 to 6.33.6 in /libs/partners/chroma (#40124)
Bumps [protobuf](https://github.com/protocolbuffers/protobuf) from 6.33.5 to 6.33.6. <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/protocolbuffers/protobuf/commits">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1eebed2c37 |
chore(deps): bump orjson from 3.11.6 to 3.12.0 in /libs/partners/chroma (#40125)
Bumps [orjson](https://github.com/ijl/orjson) from 3.11.6 to 3.12.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ijl/orjson/releases">orjson's releases</a>.</em></p> <blockquote> <h2>3.12.0</h2> <h3>Changed</h3> <ul> <li>Serialization implementation substantially rewritten.</li> <li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later, <code>manylinux_2_39</code> (2024) is targeted instead of <code>manylinux_2_17</code> (2012).</li> <li>No longer publish PyPI wheels for ppc64le and s390x.</li> </ul> <h2>3.11.9</h2> <h3>Changed</h3> <ul> <li>Build now depends on Rust 1.95 or later instead of 1.89.</li> </ul> <h3>Fixed</h3> <ul> <li>Fix building on Rust 1.95.</li> </ul> <h2>3.11.8</h2> <h3>Changed</h3> <ul> <li>Build and compatibility improvements.</li> </ul> <h2>3.11.7</h2> <h3>Changed</h3> <ul> <li>Use a faster library to serialize <code>float</code>. Users with byte-exact regression tests should note positive exponents are now written using a <code>+</code>, e.g., <code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are spec-compliant.</li> <li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/ijl/orjson/blob/master/CHANGELOG.md">orjson's changelog</a>.</em></p> <blockquote> <h2>3.12.0 - 2026-08-14</h2> <h3>Changed</h3> <ul> <li>Serialization implementation substantially rewritten.</li> <li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later, <code>manylinux_2_39</code> (2024) is targeted instead of <code>manylinux_2_17</code> (2012).</li> <li>No longer publish PyPI wheels for ppc64le and s390x.</li> </ul> <h2>3.11.9 - 2026-05-06</h2> <h3>Changed</h3> <ul> <li>Build now depends on Rust 1.95 or later instead of 1.89.</li> </ul> <h3>Fixed</h3> <ul> <li>Fix building on Rust 1.95.</li> </ul> <h2>3.11.8 - 2026-03-31</h2> <h3>Changed</h3> <ul> <li>Build and compatibility improvements.</li> </ul> <h2>3.11.7 - 2026-02-02</h2> <h3>Changed</h3> <ul> <li>Use a faster library to serialize <code>float</code>. Users with byte-exact regression tests should note positive exponents are now written using a <code>+</code>, e.g., <code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are spec-compliant.</li> <li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/ijl/orjson/commit/6737895a1a4e3e26df0569a40147893a786f9a58"><code>6737895</code></a> 3.12.0</li> <li><a href="https://github.com/ijl/orjson/commit/c2a6e8ff7b898635fb68a85bd5a62df1edf61cfc"><code>c2a6e8f</code></a> JsonWriter, iterators</li> <li><a href="https://github.com/ijl/orjson/commit/6a2d7a7d66dc3c5698625a7b334c40db459e46ae"><code>6a2d7a7</code></a> yyjson 1ea2fb0</li> <li><a href="https://github.com/ijl/orjson/commit/97bf170d9726e91c891f35eae4892801520b9dce"><code>97bf170</code></a> build update</li> <li><a href="https://github.com/ijl/orjson/commit/705515d77b28429d0b7c30c3d781abe52e8a1e5a"><code>705515d</code></a> 3.11.9</li> <li><a href="https://github.com/ijl/orjson/commit/d19055d5bab432f98d53b71606a9c6c23fb21bf6"><code>d19055d</code></a> build update</li> <li><a href="https://github.com/ijl/orjson/commit/77e2d96c3febe099cde2447856fe2523d68c71b0"><code>77e2d96</code></a> MSRV 1.95, remove compiler feature detection</li> <li><a href="https://github.com/ijl/orjson/commit/5cbb3d0398a2f42de51210270286fecd798c5d78"><code>5cbb3d0</code></a> 3.11.8</li> <li><a href="https://github.com/ijl/orjson/commit/4195d7f263e33076295b75efdcbaf6a55af8674e"><code>4195d7f</code></a> writer::half</li> <li><a href="https://github.com/ijl/orjson/commit/d00641b69410728a735f0855eb1c2843b0a5819b"><code>d00641b</code></a> writer::uuid</li> <li>Additional commits viewable in <a href="https://github.com/ijl/orjson/compare/3.11.6...3.12.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
c583b5b043 |
chore(deps): bump python-dotenv from 1.2.2 to 1.2.3 in /libs/partners/chroma (#40126)
Bumps [python-dotenv](https://github.com/theskumar/python-dotenv) from 1.2.2 to 1.2.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/theskumar/python-dotenv/releases">python-dotenv's releases</a>.</em></p> <blockquote> <h2>v1.2.3</h2> <h3>Fixed</h3> <ul> <li>Strip a leading UTF-8 BOM from <code>.env</code> file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [<a href="https://github.com/h1whelan"><code>@h1whelan</code></a>] in <a href="https://redirect.github.com/theskumar/python-dotenv/issues/640">#640</a></li> <li><code>set_key</code> now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [<a href="https://github.com/dchaudhari7177"><code>@dchaudhari7177</code></a>] in <a href="https://redirect.github.com/theskumar/python-dotenv/issues/680">#680</a></li> <li><code>dotenv run</code> now prints a friendly error instead of a traceback when no command is given by [<a href="https://github.com/bbc2"><code>@bbc2</code></a>] in <a href="https://redirect.github.com/theskumar/python-dotenv/issues/606">#606</a></li> <li>Cache the parsed result for empty <code>.env</code> files so repeated <code>dotenv_values</code>/<code>load_dotenv</code> calls no longer re-read the file by [<a href="https://github.com/ReinerBRO"><code>@ReinerBRO</code></a>] in <a href="https://redirect.github.com/theskumar/python-dotenv/issues/638">#638</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md">python-dotenv's changelog</a>.</em></p> <blockquote> <h2>[1.2.3] - 2026-08-16</h2> <h3>Fixed</h3> <ul> <li>Strip a leading UTF-8 BOM from <code>.env</code> file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [<a href="https://github.com/h1whelan"><code>@h1whelan</code></a>] in <a href="https://redirect.github.com/theskumar/python-dotenv/issues/640">#640</a></li> <li><code>set_key</code> now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [<a href="https://github.com/dchaudhari7177"><code>@dchaudhari7177</code></a>] in <a href="https://redirect.github.com/theskumar/python-dotenv/issues/680">#680</a></li> <li><code>dotenv run</code> now prints a friendly error instead of a traceback when no command is given by [<a href="https://github.com/bbc2"><code>@bbc2</code></a>] in <a href="https://redirect.github.com/theskumar/python-dotenv/issues/606">#606</a></li> <li>Cache the parsed result for empty <code>.env</code> files so repeated <code>dotenv_values</code>/<code>load_dotenv</code> calls no longer re-read the file by [<a href="https://github.com/ReinerBRO"><code>@ReinerBRO</code></a>] in <a href="https://redirect.github.com/theskumar/python-dotenv/issues/638">#638</a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59"><code>49515af</code></a> Bump version: 1.2.2 → 1.2.3</li> <li><a href="https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1"><code>8ac846f</code></a> chore: add release runbook (RELEASING.md) and make release target</li> <li><a href="https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166"><code>bb31c94</code></a> docs: add 1.2.3 release notes (<a href="https://redirect.github.com/theskumar/python-dotenv/issues/606">#606</a>, <a href="https://redirect.github.com/theskumar/python-dotenv/issues/638">#638</a>, <a href="https://redirect.github.com/theskumar/python-dotenv/issues/680">#680</a>)</li> <li><a href="https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266"><code>f7b18d9</code></a> fix: round-trip backslashes through set_key (<a href="https://redirect.github.com/theskumar/python-dotenv/issues/680">#680</a>)</li> <li><a href="https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124"><code>751f8c1</code></a> ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...</li> <li><a href="https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb"><code>f1937b6</code></a> chore(deps): update mkdocs-include-markdown-plugin requirement from >=6.0.0 t...</li> <li><a href="https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8"><code>45b9372</code></a> chore(deps): update pytest requirement from >=3.9 to >=9.0.3 (<a href="https://redirect.github.com/theskumar/python-dotenv/issues/653">#653</a>)</li> <li><a href="https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a"><code>72896e9</code></a> docs: fix broken mkdocs link in CONTRIBUTING.md (<a href="https://redirect.github.com/theskumar/python-dotenv/issues/636">#636</a>)</li> <li><a href="https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d"><code>72754a1</code></a> ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...</li> <li><a href="https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c"><code>078325e</code></a> ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...</li> <li>Additional commits viewable in <a href="https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b0d66d19d9 |
chore(deps): bump idna from 3.15 to 3.19 in /libs/partners/chroma (#40128)
Bumps [idna](https://github.com/kjd/idna) from 3.15 to 3.19. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/kjd/idna/releases">idna's releases</a>.</em></p> <blockquote> <h2>v3.19</h2> <ul> <li>Restore the <code>std3_rules</code> option, which had no effect since changes to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a> processing in Unicode 16. Note that <code>uts46_remap()</code> defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again.</li> <li>Performance improvements to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a> mapping, particularly for ASCII-only domains.</li> <li>Test on free-threaded CPython with the GIL disabled and document thread safety.</li> <li>Expose the Unicode version of the generated tables as <code>idna.unicode_version</code>, and show it in <code>idna --version</code>.</li> <li>Add <code>code</code>, <code>text</code>, <code>codepoint</code> and <code>position</code> attributes to <code>IDNAError</code> so that the failed rule and the offending character can be identified without parsing the exception message.</li> <li>The deprecated <code>transitional</code> argument to <code>encode()</code> and <code>uts46_remap()</code> is now completely ignored, and gives a deprecation warning for the latter.</li> <li>Reject A-labels that are not the canonical Punycode encoding of their U-label.</li> <li>Fix CONTEXTJ violations raising <code>IDNAError</code> instead of <code>InvalidCodepointContext</code>.</li> <li>Consistently raise <code>IDNAError</code> for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec.</li> <li>Add property-based tests, extended fuzzing targets, coverage measurement, and CI checks that the data tables match the generator output.</li> <li>Various code quality and tooling improvements.</li> </ul> <p>Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for contributions to this release.</p> <h2>v3.18</h2> <p>No release notes provided.</p> <h2>v3.17</h2> <p>No release notes provided.</p> <h2>v3.16</h2> <p>No release notes provided.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/kjd/idna/blob/master/HISTORY.md">idna's changelog</a>.</em></p> <blockquote> <h2>3.19 (2026-08-18)</h2> <ul> <li>Restore the <code>std3_rules</code> option, which had no effect since changes to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a> processing in Unicode 16. Note that <code>uts46_remap()</code> defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again.</li> <li>Performance improvements to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a> mapping, particularly for ASCII-only domains.</li> <li>Test on free-threaded CPython with the GIL disabled and document thread safety.</li> <li>Expose the Unicode version of the generated tables as <code>idna.unicode_version</code>, and show it in <code>idna --version</code>.</li> <li>Add <code>code</code>, <code>text</code>, <code>codepoint</code> and <code>position</code> attributes to <code>IDNAError</code> so that the failed rule and the offending character can be identified without parsing the exception message.</li> <li>The deprecated <code>transitional</code> argument to <code>encode()</code> and <code>uts46_remap()</code> is now completely ignored, and gives a deprecation warning for the latter.</li> <li>Reject A-labels that are not the canonical Punycode encoding of their U-label.</li> <li>Fix CONTEXTJ violations raising <code>IDNAError</code> instead of <code>InvalidCodepointContext</code>.</li> <li>Consistently raise <code>IDNAError</code> for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec.</li> <li>Add property-based tests, extended fuzzing targets, coverage measurement, and CI checks that the data tables match the generator output.</li> <li>Various code quality and tooling improvements.</li> </ul> <p>Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for contributions to this release.</p> <h2>3.18 (2026-06-02)</h2> <ul> <li>When decoding a domain, add a <code>display</code> argument that will pass through invalid labels rather than raising an exception.</li> </ul> <h2>3.17 (2026-05-28)</h2> <ul> <li>Substantial 75% reduction in memory usage through new data structures and some optimization in processing speed.</li> <li>Added a general 1024-character input length cap to the public validation, conversion, and codec entry points. This is well above any legitimate domain or label and guards against pathological inputs.</li> </ul> <h2>3.16 (2026-05-22)</h2> <ul> <li>Add a command-line interface (<code>python -m idna</code>, also available as the <code>idna</code> script). Encodes or decodes one or more domains supplied</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/kjd/idna/commit/03a9a11dd8aecd4fea742cabe20f4d3d9ed82abb"><code>03a9a11</code></a> Release 3.19</li> <li><a href="https://github.com/kjd/idna/commit/2d2a7ef0c59210a48407b3dde6d884933cecf093"><code>2d2a7ef</code></a> Pre-release 3.19rc0</li> <li><a href="https://github.com/kjd/idna/commit/5cce1308d148019c5fa0febceafa13e99cdacfe7"><code>5cce130</code></a> Merge pull request <a href="https://redirect.github.com/kjd/idna/issues/268">#268</a> from kjd/fix-std3-regex-alert</li> <li><a href="https://github.com/kjd/idna/commit/3914b75f3e4cbc11e59f92eeecdb16d10871e57f"><code>3914b75</code></a> Split the STD3 disallowed-character range so uppercase is explicit</li> <li><a href="https://github.com/kjd/idna/commit/ce9fd98ac4073866db276e93834b259f2a5a4ac4"><code>ce9fd98</code></a> Merge pull request <a href="https://redirect.github.com/kjd/idna/issues/267">#267</a> from kjd/housekeeping</li> <li><a href="https://github.com/kjd/idna/commit/809240c3cc9358c9c9c79b2d12ffe39e75ccfb0f"><code>809240c</code></a> Fail CI when the license copyright year is behind the current year</li> <li><a href="https://github.com/kjd/idna/commit/d9e16c523d7d25dcc14100fa80f3e303404e09be"><code>d9e16c5</code></a> Consolidate test fixtures, prune stale gitignore entries, and fix doc typos</li> <li><a href="https://github.com/kjd/idna/commit/ef30feeed3a758e96286fdab0315a551f7f5e7d6"><code>ef30fee</code></a> Remove dead code and pare back superfluous comments</li> <li><a href="https://github.com/kjd/idna/commit/b907913f854d26cc714f721c6c2cb626d41ac468"><code>b907913</code></a> Tighten the version support and Unicode notes in the README</li> <li><a href="https://github.com/kjd/idna/commit/6204cbe343ef438df7c58bc80b94d0f960991d90"><code>6204cbe</code></a> Ignore local build artifacts and stop packaging stray tooling config</li> <li>Additional commits viewable in <a href="https://github.com/kjd/idna/compare/v3.15...v3.19">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
620aea77ec |
chore(deps): bump orjson from 3.11.6 to 3.12.0 in /libs/partners/fireworks (#40129)
Bumps [orjson](https://github.com/ijl/orjson) from 3.11.6 to 3.12.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ijl/orjson/releases">orjson's releases</a>.</em></p> <blockquote> <h2>3.12.0</h2> <h3>Changed</h3> <ul> <li>Serialization implementation substantially rewritten.</li> <li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later, <code>manylinux_2_39</code> (2024) is targeted instead of <code>manylinux_2_17</code> (2012).</li> <li>No longer publish PyPI wheels for ppc64le and s390x.</li> </ul> <h2>3.11.9</h2> <h3>Changed</h3> <ul> <li>Build now depends on Rust 1.95 or later instead of 1.89.</li> </ul> <h3>Fixed</h3> <ul> <li>Fix building on Rust 1.95.</li> </ul> <h2>3.11.8</h2> <h3>Changed</h3> <ul> <li>Build and compatibility improvements.</li> </ul> <h2>3.11.7</h2> <h3>Changed</h3> <ul> <li>Use a faster library to serialize <code>float</code>. Users with byte-exact regression tests should note positive exponents are now written using a <code>+</code>, e.g., <code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are spec-compliant.</li> <li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/ijl/orjson/blob/master/CHANGELOG.md">orjson's changelog</a>.</em></p> <blockquote> <h2>3.12.0 - 2026-08-14</h2> <h3>Changed</h3> <ul> <li>Serialization implementation substantially rewritten.</li> <li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later, <code>manylinux_2_39</code> (2024) is targeted instead of <code>manylinux_2_17</code> (2012).</li> <li>No longer publish PyPI wheels for ppc64le and s390x.</li> </ul> <h2>3.11.9 - 2026-05-06</h2> <h3>Changed</h3> <ul> <li>Build now depends on Rust 1.95 or later instead of 1.89.</li> </ul> <h3>Fixed</h3> <ul> <li>Fix building on Rust 1.95.</li> </ul> <h2>3.11.8 - 2026-03-31</h2> <h3>Changed</h3> <ul> <li>Build and compatibility improvements.</li> </ul> <h2>3.11.7 - 2026-02-02</h2> <h3>Changed</h3> <ul> <li>Use a faster library to serialize <code>float</code>. Users with byte-exact regression tests should note positive exponents are now written using a <code>+</code>, e.g., <code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are spec-compliant.</li> <li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/ijl/orjson/commit/6737895a1a4e3e26df0569a40147893a786f9a58"><code>6737895</code></a> 3.12.0</li> <li><a href="https://github.com/ijl/orjson/commit/c2a6e8ff7b898635fb68a85bd5a62df1edf61cfc"><code>c2a6e8f</code></a> JsonWriter, iterators</li> <li><a href="https://github.com/ijl/orjson/commit/6a2d7a7d66dc3c5698625a7b334c40db459e46ae"><code>6a2d7a7</code></a> yyjson 1ea2fb0</li> <li><a href="https://github.com/ijl/orjson/commit/97bf170d9726e91c891f35eae4892801520b9dce"><code>97bf170</code></a> build update</li> <li><a href="https://github.com/ijl/orjson/commit/705515d77b28429d0b7c30c3d781abe52e8a1e5a"><code>705515d</code></a> 3.11.9</li> <li><a href="https://github.com/ijl/orjson/commit/d19055d5bab432f98d53b71606a9c6c23fb21bf6"><code>d19055d</code></a> build update</li> <li><a href="https://github.com/ijl/orjson/commit/77e2d96c3febe099cde2447856fe2523d68c71b0"><code>77e2d96</code></a> MSRV 1.95, remove compiler feature detection</li> <li><a href="https://github.com/ijl/orjson/commit/5cbb3d0398a2f42de51210270286fecd798c5d78"><code>5cbb3d0</code></a> 3.11.8</li> <li><a href="https://github.com/ijl/orjson/commit/4195d7f263e33076295b75efdcbaf6a55af8674e"><code>4195d7f</code></a> writer::half</li> <li><a href="https://github.com/ijl/orjson/commit/d00641b69410728a735f0855eb1c2843b0a5819b"><code>d00641b</code></a> writer::uuid</li> <li>Additional commits viewable in <a href="https://github.com/ijl/orjson/compare/3.11.6...3.12.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
5b0f646b77 |
chore(deps): bump langsmith from 0.10.16 to 0.12.1 in /libs/partners/fireworks (#40130)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from 0.10.16 to 0.12.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's releases</a>.</em></p> <blockquote> <h2>v0.12.1</h2> <h2>What's Changed</h2> <ul> <li>release(js): 0.10.0 by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3474">langchain-ai/langsmith-sdk#3474</a></li> <li>fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3475">langchain-ai/langsmith-sdk#3475</a></li> <li>release(py): 0.12.1 by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3478">langchain-ai/langsmith-sdk#3478</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1">https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1</a></p> <h2>v0.12.0</h2> <h2>What's Changed</h2> <ul> <li>ci: enable CodSpeed flame graphs and pin the benchmarks to one CPU by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3449">langchain-ai/langsmith-sdk#3449</a></li> <li>fix(py,js)!: make trace sampling deterministic by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3183">langchain-ai/langsmith-sdk#3183</a></li> <li>fix(py): suppress import-untyped on the optional langsmith_pyo3 import by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3462">langchain-ai/langsmith-sdk#3462</a></li> <li>chore(py)!: swtich to httpx2 dependency while keeping httpx as a fallback by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3406">langchain-ai/langsmith-sdk#3406</a></li> <li>fix!: fail-closed when per-function anonymization callables fail by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3328">langchain-ai/langsmith-sdk#3328</a></li> <li>fix(py): compress replica writes that carry their own credentials by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3448">langchain-ai/langsmith-sdk#3448</a></li> <li>perf(py): serialize identical replicas once, into one frame by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3450">langchain-ai/langsmith-sdk#3450</a></li> <li>release(py): 0.12.0 by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3472">langchain-ai/langsmith-sdk#3472</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0</a></p> <h2>v0.11.2</h2> <h2>What's Changed</h2> <ul> <li>fix: exclude password and email env vars from run metadata by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3417">langchain-ai/langsmith-sdk#3417</a></li> <li>feat(js): Avoid redundantly sending inputs up in patch by <a href="https://github.com/jacoblee93"><code>@jacoblee93</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3425">langchain-ai/langsmith-sdk#3425</a></li> <li>release(js): 0.9.0 by <a href="https://github.com/jacoblee93"><code>@jacoblee93</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3426">langchain-ai/langsmith-sdk#3426</a></li> <li>test(py): continuous benchmarking with CodSpeed by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3420">langchain-ai/langsmith-sdk#3420</a></li> <li>fix: point migration guide links at their new per-area pages by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3421">langchain-ai/langsmith-sdk#3421</a></li> <li>fix(js): send langsmith-js User-Agent on generated client calls by <a href="https://github.com/KiewanVillatel"><code>@KiewanVillatel</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3411">langchain-ai/langsmith-sdk#3411</a></li> <li>test(py): pin multipart ingest retry matrix and drop warning by <a href="https://github.com/QuentinBrosse"><code>@QuentinBrosse</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3377">langchain-ai/langsmith-sdk#3377</a></li> <li>chore: sync langsmith_api by <a href="https://github.com/langtions-bot"><code>@langtions-bot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3407">langchain-ai/langsmith-sdk#3407</a></li> <li>fix(py): handle 64bit+ integers without loss of precision by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3409">langchain-ai/langsmith-sdk#3409</a></li> <li>fix(py): exclude replica config from the serialized run body by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3442">langchain-ai/langsmith-sdk#3442</a></li> <li>fix(py,js): consistent (non-v7) UUID rewriting for replicas by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3445">langchain-ai/langsmith-sdk#3445</a></li> <li>ci: report Python benchmarks to Datadog Test Optimization by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3408">langchain-ai/langsmith-sdk#3408</a></li> <li>fix(js): close the argument-shape bypass in Anthropic MCP redaction by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3378">langchain-ai/langsmith-sdk#3378</a></li> <li>feat(livekit): align trace audio with the span timeline by <a href="https://github.com/carolinedivittorio"><code>@carolinedivittorio</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3452">langchain-ai/langsmith-sdk#3452</a></li> <li>release(py): 0.11.2 by <a href="https://github.com/carolinedivittorio"><code>@carolinedivittorio</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3457">langchain-ai/langsmith-sdk#3457</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2</a></p> <h2>v0.11.1</h2> <h2>What's Changed</h2> <ul> <li>release(js): 0.8.11 by <a href="https://github.com/emil-lc"><code>@emil-lc</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3401">langchain-ai/langsmith-sdk#3401</a></li> <li>chore: sync langsmith_api by <a href="https://github.com/langtions-bot"><code>@langtions-bot</code></a>[bot] in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3340">langchain-ai/langsmith-sdk#3340</a></li> <li>fix(sandbox): retry transient WebSocket upgrades in Python and JS by <a href="https://github.com/ramon-langchain"><code>@ramon-langchain</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3388">langchain-ai/langsmith-sdk#3388</a></li> <li>fix: report incomplete pytest suites accurately by <a href="https://github.com/jkennedyvz"><code>@jkennedyvz</code></a> in <a href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3398">langchain-ai/langsmith-sdk#3398</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/11093852f2fe7b4fc63b88565da37d6cb796bcda"><code>1109385</code></a> release(py): 0.12.1 (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3478">#3478</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/73ac3029c90a8d64aadb71848db87f83acaf97a5"><code>73ac302</code></a> fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3475">#3475</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/11f7208efcf2484d020ecd6d6ba4f4d6f675a606"><code>11f7208</code></a> release(js): 0.10.0 (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3474">#3474</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/a95cddfe4f406bdef6d92213e7ff30bb7c980d85"><code>a95cddf</code></a> release(py): 0.12.0 (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3472">#3472</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/4ddfa249823d102183054c750fc4ba4a9a356899"><code>4ddfa24</code></a> perf(py): serialize identical replicas once, into one frame (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3450">#3450</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/983e00acc1c7a5f944fe530db8d0aa13063a2392"><code>983e00a</code></a> fix(py): compress replica writes that carry their own credentials (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3448">#3448</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/3239181c87dbdb5815746534cd9082227a443595"><code>3239181</code></a> fix!: fail-closed when per-function anonymization callables fail (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3328">#3328</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/0d3256709ee31a73647cee4846256ecf0be38932"><code>0d32567</code></a> chore(py)!: swtich to httpx2 dependency while keeping httpx as a fallback (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3">#3</a>...</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/1b64f94fe226f07fcacc81ea8a3e7486c1fc5c14"><code>1b64f94</code></a> fix(py): suppress import-untyped on the optional langsmith_pyo3 import (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3462">#3462</a>)</li> <li><a href="https://github.com/langchain-ai/langsmith-sdk/commit/e5360c9833cfad5dc20beeef5f42dcd7bd1b4116"><code>e5360c9</code></a> fix(py,js)!: make trace sampling deterministic (<a href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3183">#3183</a>)</li> <li>Additional commits viewable in <a href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.16...v0.12.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/langchain-ai/langchain/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
49da5817a8 |
fix(openai): route gpt-5.6-sol to responses API (#40133)
`ChatOpenAI` recognized `gpt-5.6-sol` as a reasoning model but did not infer that it requires the Responses API. Requests using function tools and reasoning were therefore sent to Chat Completions and rejected by OpenAI. This adds `gpt-5.6-sol` and its dated snapshots to the Responses-only model inference, with focused unit coverage. Made by [Open SWE](https://openswe.vercel.app/agents/2eaa47e3-35c8-5a06-b3af-ad8671c0b584) Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
8973dbc6f5 |
perf(anthropic,langchain): omit middleware trace inputs (#40098)
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
cf22b84d75 |
feat(anthropic): add Claude Fable 5.1 support (#40106)
### Summary - add the `claude-fable-5-1` model profile with its 1M-token context window, 128K output limit, structured output, and adaptive-reasoning capabilities - validate Fable 5-family unsupported sampling and thinking configurations before requests are sent - omit default sampling values from Fable request payloads ### Testing - `uv run --group test pytest tests/unit_tests/test_chat_models.py -q --no-header --no-summary -k 'fable_5_1 or claude_fable_5_1'` - `uv run --group lint ruff format --check langchain_anthropic/chat_models.py langchain_anthropic/data/_profiles.py tests/unit_tests/test_chat_models.py` - `uv run --group lint ruff check langchain_anthropic/chat_models.py langchain_anthropic/data/_profiles.py tests/unit_tests/test_chat_models.py` Made by [Open SWE](https://openswe.vercel.app/agents/ad6c064d-f1de-5f1e-b46d-6b2c5b5c333f) --------- Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
b4d46a503e | docs(xai): point structured outputs guide link to official xAI docs (#40026) | ||
|
|
e92c8a08bf |
fix(core): avoid mutation in google-genai standard content (#40023)
Co-authored-by: Hotragn Pettugani <103170876+Hotragn@users.noreply.github.com> |
||
|
|
36f0d10348 |
fix(core): avoid mutation in bedrock converse standard content (#40022)
Co-authored-by: Zhewen Tan <127607634+tandede@users.noreply.github.com> |
||
|
|
1e1e238703 |
fix(langchain): include model destination in agent tool routing (#38355)
Fixes #38351 This PR fixes `create_agent` conditional edge routing when middleware injects synthetic `ToolMessage` objects for already-satisfied tool calls. Previously, `_make_model_to_tools_edge` could return the model loop entry destination, but that destination was not always included in `model_to_tools_destinations`. This caused LangGraph to raise `KeyError("model")`. Changes: * Include `loop_entry_node` in `model_to_tools_destinations`. * Add a regression test covering synthetic `ToolMessage` injection through `wrap_model_call` middleware using `ExtendedModelResponse` and `Command(update={"messages": ...})`. Test: * `uv run --group test pytest tests/unit_tests/agents/middleware/core/test_framework.py::test_create_agent_synthetic_tool_messages_reroute_to_model` Result: * Passed --------- Co-authored-by: ccurme <26529506+ccurme@users.noreply.github.com> Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
5893459c4f |
chore(langchain): bump vcrpy test dependency minimum to >=8.2.0 (#39942)
Raises the minimum `vcrpy` version from `>=8.0.0` to `>=8.2.0` in the integration-test dependencies of `langchain-classic` and `langchain`, aligning them with `langchain-openai` (`>=8.2.0`) and `langchain-tests` (`>=8.2.1`), which already require newer versions. Made by [Open SWE](https://openswe.vercel.app/agents/cedc18ba-0856-5697-949e-3c6616845c60) --------- Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
67fa96ffad |
docs(groq): remove duplicate method block from with_structured_output docstring (#39978)
Closes #39977 --- Anyone reading the `ChatGroq.with_structured_output` reference sees the `method` argument documented twice, and the two blocks disagree with each other. The first block is the current one. It lists three options and matches how the sibling `langchain-openai` package documents the same argument. The second block is older. It says the argument is `'function_calling'` or `'json_mode'`, which stopped being true when `'json_schema'` support was added. A reader who stops at the second block will not know `'json_schema'` exists, and the duplicate key also breaks API reference rendering. This removes the stale block. The one thing it said that the surviving block did not was the warning that `'json_mode'` does not support streaming responses or stop sequences, so that warning moves up rather than being dropped. Everything else in it was already covered above. No behaviour changes, docstring only. The added unit test asserts `method` appears once and that `json_schema` is still described. It fails on the current `master` and passes with this change. --- Disclaimer: this contribution was prepared with the assistance of an AI agent. I reviewed the change, verified the reproduction from the issue against `master`, and ran the package unit tests and `ruff` locally before opening it. --------- Signed-off-by: Mason Daugherty <github@mdrxy.com> Co-authored-by: Mason Daugherty <github@mdrxy.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
885e858ac4 |
release(fireworks): 1.6.1 (#39975)
Bumps `langchain-fireworks` to 1.6.1, a patch release carrying one fix since 1.6.0: - `fix(fireworks): drop reasoning history blocks` (#39973)langchain-fireworks==1.6.1 |
||
|
|
033ff67b33 |
fix(fireworks): drop reasoning history blocks (#39973)
Fixed Fireworks requests failing after switching from a model that stores reasoning blocks in conversation history. --- Users switching from an OpenAI Responses model to Fireworks could receive a 400 because canonical `reasoning` blocks remained in conversation history. `ChatFireworks` now drops those provider-specific blocks before serializing Chat Completions requests, matching its handling of other unsupported reasoning formats. Made by [Open SWE](https://openswe.vercel.app/agents/15bd8573-dbbf-55f8-8f22-d5295ec6de11) --------- Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com> |
||
|
|
4fe9d3062f | chore(openai): fix tests (#39972) langchain-core==1.6.1 | ||
|
|
8fa38dc143 | revert: release(core): 1.6.2 (#39971) | ||
|
|
122030d79e | release(core): 1.6.2 (#39967) |