Commit Graph
16876 Commits
Author SHA1 Message Date
ccurme 3f212e7a88 feat(openai): support async tools (#40208) 2026-09-04 15:49:14 -04:00
ccurme 1a3d81756f feat(openai): support configuration_update (#40201) 2026-09-04 14:28:32 -04:00
langchain-oss-model-profiles[bot]andmdrxy aac7904ff4 chore(model-profiles): refresh model profile data (#40198)
Automated refresh of model profile data for all in-monorepo partner
integrations via `langchain-profiles refresh`.

🤖 Generated by the [`refresh_model_profiles`
workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml).

## Summary of changes

**3 added · 0 removed · 9 changed** across 3 provider(s).

<details>
<summary>fireworks-ai</summary>

**✏️ 2 changed**
- `accounts/fireworks/models/glm-5p3`: last updated `2026-08-28` →
`2026-09-04`
- `accounts/fireworks/models/glm-5p3-flash`: last updated `2026-08-26` →
`2026-09-04`

</details>

<details>
<summary>huggingface</summary>

**➕ 1 added**
- `deepseek-ai/DeepSeek-V4-Flash-Vision-Exp` — 1,048,576 ctx, 384,000
out, text+image in, reasoning, tools

</details>

<details>
<summary>openrouter</summary>

**➕ 2 added**
- `inclusionai/ling-3.0-flash-fin` — 262,144 ctx, 235,929 out,
reasoning, tools
- `nvidia/nemotron-3.5-content-safety` — 131,072 ctx, 117,964 out,
text+image in, reasoning

**✏️ 7 changed**
- `deepseek/deepseek-chat`: max output tokens 16,000 → 16,384
- `deepseek/deepseek-chat-v3.1`: max output tokens 32,768 → 144,900
- `nvidia/nemotron-3-ultra-550b-a55b`: max output tokens 182,520 →
32,768
- `qwen/qwen2.5-vl-72b-instruct`: max output tokens 28,800 → 115,200
- `undi95/remm-slerp-l2-13b`: max output tokens 4,096 → 5,529
- `z-ai/glm-5.3`: max output tokens 131,072 → 262,144
- `~z-ai/glm-latest`: max output tokens 943,718 → 235,929

</details>

Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com>
2026-09-04 11:19:24 -04:00
Naomi Pentrel 0d50cbddd9 docs: add openwiki (#40183) 2026-09-04 11:03:34 +02:00
ccurme 79cab2dc7f release(anthropic): 1.7.1 (#40181) langchain-anthropic==1.7.1 langchain==1.4.0 2026-09-03 11:37:30 -04:00
langchain-oss-model-profiles[bot]andmdrxy 1e6a4f0b45 chore(model-profiles): refresh model profile data (#40171)
Automated refresh of model profile data for all in-monorepo partner
integrations via `langchain-profiles refresh`.

🤖 Generated by the [`refresh_model_profiles`
workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml).

## Summary of changes

**4 added · 0 removed · 11 changed** across 4 provider(s).

<details>
<summary>fireworks-ai</summary>

**➕ 1 added**
- `accounts/fireworks/models/deepseek-v4-flash-vision-exp` — 1,000,000
ctx, 384,000 out, text+image in, reasoning, tools

</details>

<details>
<summary>huggingface</summary>

**✏️ 1 changed**
- `tencent/Hy3`: max output tokens 64,000 → 128,000

</details>

<details>
<summary>openai</summary>

**✏️ 2 changed**
- `gpt-5.2-chat-latest`: status unset → `deprecated`
- `gpt-5.3-chat-latest`: status unset → `deprecated`

</details>

<details>
<summary>openrouter</summary>

**➕ 3 added**
- `google/gemini-3.8-flash` — 1,048,576 ctx, 65,536 out,
text+image+audio+video+pdf in, reasoning, tools
- `meta/muse-spark-1.3` — 1,048,576 ctx, 943,718 out,
text+image+audio+video+pdf in, reasoning, tools
- `meta/muse-spark-1.3-contributor` — 1,048,576 ctx, 943,718 out,
text+image+audio+video+pdf in, reasoning, tools

**✏️ 8 changed**
- `meta-llama/llama-3.3-70b-instruct`: max output tokens 115,200 →
16,384
- `meta/muse-glimmer-30b`: max output tokens 16,384 → 117,964
- `nvidia/nemotron-3-nano-30b-a3b`: max output tokens 228,000 → 235,929
- `nvidia/nemotron-3-ultra-550b-a55b`: max output tokens 32,768 →
182,520
- `qwen/qwen3.5-397b-a17b`: max output tokens 65,536 → 235,929
- `qwen/qwen3.8-2.4t-a95b`: max output tokens 131,072 → 262,144
- `z-ai/glm-4.6`: max output tokens 16,384 → 131,072
- `~z-ai/glm-flash-latest`: max output tokens 131,072 → 943,718

</details>

Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com>
2026-09-03 10:03:15 -04:00
8330dfe987 docs(langchain): runnable langchain.mcp examples (#39976)
Stacked on #39939 — review that first; this branch adds only
`libs/langchain_v1/examples/mcp/`.

Ten self-contained scripts, one idea each. Every one starts whatever MCP
server it needs, so `uv run examples/mcp/<name>.py` is the whole
workflow.

| Example | Shows | Model | Network |
|---|---|:-:|:-:|
| `transports.py` | one adapter over in-memory, stdio, and HTTP | | |
| `remote_server.py` | pointing the adapter at a public MCP server | ✅ |
✅ |
| `multi_server.py` | several servers behind one adapter, tools prefixed
per server | ✅ | |
| `graph_factory.py` | one per-user MCP fleet behind a `langgraph dev`
graph factory | ✅ | |
| `protocol_eras.py` | one agent holding tools from both MCP protocol
eras | ✅ | |
| `tool_errors.py` | a failing tool reaching the model so it can retry |
✅ | |
| `elicitation.py` | a server asking a human mid-call, via `interrupt()`
| ✅ | |
| `destructive_interrupt.py` | gating destructive tools behind approval,
from tool metadata | ✅ | |
| `auth_bearer.py` | a server behind a static bearer token | | |
| `auth_oauth.py` | a full OAuth 2.1 flow with dynamic client
registration | | |

Each was run against a real model (or a real `langgraph dev` server)
before committing, and its output is what the docstring claims.

A few choices worth knowing about:

- **Servers come from FastMCP's own `run_server_in_process`**, not
hand-rolled uvicorn plumbing, so the examples teach the adapter rather
than how to start a server.
- **HTTP appears only where it is the subject.** `multi_server.py` names
its backends over stdio, which is less machinery and a better
illustration, since a fleet addresses each backend independently.
- **`remote_server.py` hits DeepWiki**, a public MCP server, where the
URL is the entire configuration. It prints the tool call so the answer
is visibly the remote server's work rather than the model's memory.
- **`tool_errors.py` pins the model with a system prompt.** Without it
the model answers the arithmetic from memory and the error path never
runs.
- **`destructive_interrupt.py` derives the approval gate from
metadata**, reading each tool's
`metadata["mcp"]["tool"]["annotations"]["destructive_hint"]` to build
the `HumanInTheLoopMiddleware` `interrupt_on` map — so any tool a server
flags as destructive pauses for approval, no tool names hardcoded.
- **`auth_oauth.py` opens a browser tab.** The demo authorization server
auto-approves, so it redirects straight back — but it is the one example
that cannot run unattended.

`graph_factory.py` is registered by a `langgraph.json` and run under
`langgraph dev` rather than invoked directly. It shows a per-user MCP
fleet: one shared `httpx` connection pool for everyone, a per-user
`ClientGroup` built each run, and per-user discovery caching keyed on
the caller's identity read off the injected `ServerRuntime`.
`run_graph_factory_demo.py` is an end-to-end driver that stands up two
guarded MCP servers plus a `langgraph dev` server with custom auth and
runs the graph once per user; `auth.py`, `langgraph.json`, and
`_fleet_servers.py` support it. `_servers.py` holds the small MCP
servers the examples share, `_stdio_server.py` is the entry point
launched as a subprocess over stdio, and neither `_`-prefixed helper is
part of the API being demonstrated.

`examples/*` picks up the same two ruff exemptions `scripts/*` already
has, for printing and for not being a package.

## Release note

No library changes — examples only.

---

*Prepared with the assistance of an AI agent.*

---------

Co-authored-by: Hunter Lovell <hunter@hntrl.io>
Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
Co-authored-by: Sydney Runkle <sydney@langchain.dev>
2026-09-02 21:31:29 -07:00
280442b54c feat(langchain): langchain.mcp namespace, MCPAdapter (#39939)
Adds `langchain.mcp`: adapt an MCP server into LangChain tools ready for
`create_agent`.

```python
from langchain.agents import create_agent
from langchain.mcp import MCPAdapter

adapter = MCPAdapter("https://example.com/mcp")
agent = create_agent("anthropic:claude-sonnet-5", await adapter.list_tools())
```

`langchain-mcp-adapters` stays the place for the full surface
(interceptors, callbacks, prompts, resources). This is the short path
for the common case.

## Public API

`MCPAdapter(target, *, elicitation=None)`, with a `client` property,
`list_tools(*, cache_mode="use")`, and async context management.
`as_langchain_tool(tool, client, *, elicitation=None)` converts a single
tool for callers managing their own client.

`MCPAdapter` accepts anything `fastmcp.Client` accepts — a URL, `Path`,
in-process server, `ClientTransport`, `MCPConfig` (or its dict form), or
a pre-built `Client` — plus a FastMCP `ClientGroup` for a fleet of
servers behind one client. Inference is FastMCP's, so new target types
work without changes here. The target union is `MCPAdapterTarget`; it is
not part of the package's public surface (it is only useful for
annotating a `target`), but it stays importable from
`langchain.mcp.adapter` for that purpose. An `MCPConfig` naming several
servers yields one prefixed toolset from one adapter:

```python
MCPAdapter({"mcpServers": {"notes": {"command": "python", "args": ["notes.py"]},
                           "web": {"url": "https://example.com/mcp"}}})
# -> ["notes_read_note", "web_get_weather", ...]
```

## Tool conversion

Tool results are ported from `langchain-mcp-adapters`, so a call reaches
a model in the same shape either way. Results become LangChain content
blocks (audio raises `NotImplementedError`); structured content becomes
an `MCPToolArtifact`; `args_schema` is the tool's `input_schema`.

Tool *metadata* is grouped under a single `mcp` namespace so a consumer
can tell an MCP tool's provenance apart and keep tool-level fields
distinct from the serving server's identity:

```python
tool.metadata == {
    "mcp": {
        "tool": {
            "annotations": {"destructive_hint": True, ...},  # snake_case, from tool.annotations
            "_meta": {...},                                  # verbatim MCP `_meta`
        },
        "server": {"name": "files", "version": "2.1.0", ...},  # from the live client connection
    },
}
```

Server identity comes off the connection (a `Tool` carries no server
field) and is read at conversion time while the client is connected.
This metadata rides onto the LangChain tool's `metadata`, so it also
lands on the tool's traced run — `mcp.server.name` becomes filterable in
traces. The examples PR uses the destructive hint to gate a tool behind
human approval.

An `isError=True` result becomes a `ToolMessage` with `status="error"`
carrying the server's own error content, so the agent can correct itself
instead of the run ending. Transport failures and unconvertible content
still raise.

FastMCP clients are reentrant and reference-counted, so the adapter adds
no second layer — tools hold the client and stay callable after the
adapter's context exits.

## Discovery caching

`list_tools(cache_mode=...)` selects how discovery interacts with the
client-side response cache (SEP-2549): `use` (default) serves a cached
tool list within the server's TTL hint, `refresh` calls the server and
repopulates it, `bypass` skips the cache. The cache and its
per-principal isolation are configured on the client itself
(`Client(cache=...)`); this only selects how discovery reads it. The
default is `use` so a configured cache is honored — note this differs
from a bare `ClientGroup.list_tools()`, whose own default is `refresh`.

## Elicitation

Some MCP tools need input before they can finish.
`elicitation="interrupt"` surfaces the question as a LangGraph
interrupt:

```python
adapter = MCPAdapter(server, elicitation="interrupt")

paused = await agent.ainvoke({"messages": [...]}, config)
[question] = paused["__interrupt__"][0].value["requests"]
# {'key': 'date', 'message': 'What date would you like to book?', 'mode': 'form',
#  'requested_schema': {...}}

await agent.ainvoke(
    Command(resume={"responses": {question["key"]: {"action": "accept", "content": {"date": "2026-08-26"}}}}),
    config,
)
```

Answers correlate by the server's own request keys, so nothing extra is
needed on resume. Several requests in one round share one interrupt;
successive rounds each get their own. The payload types live in
`langchain.mcp.elicitation`, split so the type system carries the
protocol's rules: `mode` discriminates form from URL requests, and only
an accept can carry content, narrowed to the scalar shapes the wire
accepts.

It is opt-in because a declared capability is a promise on the wire —
servers only build flows that depend on it once a client says yes — so
left unset, a server whose tool *requires* an answer refuses the call
rather than running without one. The loop is driven through
`session.call_tool(..., allow_input_required=True)` rather than a
FastMCP handler, which would convert the `GraphInterrupt` into an MCP
error. Resuming re-issues the call from its first round, since the
interrupt unwound it; a server that asks before doing work repeats
nothing, which the tests assert by counting tool-body executions.

Scope is elicitation only. Embedded sampling and roots requests raise,
since driving the loop by hand bypasses the FastMCP callbacks that
answer them, as does a continuation round carrying only `request_state`
— that is the protocol's long-running-work channel, and serving it would
mean polling a remote server from inside a tool call.

## Building on FastMCP

Handing the client to FastMCP is what keeps this small. Most of the
protocol surface is inherited rather than written:

- **Negotiation, per server.** FastMCP speaks both the 2025-11-25
`initialize` handshake and the 2026-07-28 `server/discover` revision,
and picks per connection — so one agent can hold tools from servers on
different revisions at once, with no protocol mode to choose. There is a
test that builds exactly that agent.
- **Transports and auth.** Inference covers URLs, script paths,
in-process servers, and config dicts, while `auth="oauth"`, bearer
tokens, custom `httpx` auth, and TLS via `verify` all arrive without
code here.
- **Fleets.** A `ClientGroup` target lets one adapter serve a fleet of
servers, prefixing each server's tools and routing every call back to
the client that serves it.
- **Connection lifecycle.** Clients are reentrant and reference-counted,
so tools outlive the adapter's context without a second layer of
bookkeeping, and requests race the background session task so a dead
HTTP session raises instead of hanging a tool call.
- **The input-required flow (SEP-2322).** Elicitation intercepts a round
at the session layer instead of reimplementing the multi-round protocol.
- **In-process servers.** The whole unit suite drives real MCP servers
with no subprocess and no socket.

This requires `fastmcp>=4.0.0` — the GA line whose multi-server config
routes to modern-protocol servers, which the `MCPConfig` and
`ClientGroup` support rely on.

## Release note

New `langchain.mcp` namespace. `MCPAdapter` adapts any target
`fastmcp.Client` accepts — a URL, a local script, an in-process server,
an `MCPConfig` naming several servers, or a pre-built client — as well
as a FastMCP `ClientGroup`, into LangChain tools ready for
`create_agent`. `MCPAdapter.list_tools(cache_mode=...)` discovers tools
with optional client-side response caching. `as_langchain_tool` converts
a single MCP tool for callers managing their own client. Tool metadata
(annotations, `_meta`, and the serving server's identity) is grouped
under an `mcp` namespace on each tool. `elicitation="interrupt"`
surfaces a server's mid-call questions as LangGraph interrupts. Requires
the `mcp` extra: `pip install "langchain[mcp]"`.

## Notes for review

- A `Path` or script-path target launches a local subprocess with no
opt-in keyword. Intended, and the target comes from application code
rather than a model, but it loosens the previous default and is awkward
to walk back once released.
- Tool metadata is traced. Whatever a server puts in `_meta` reaches the
tool's LangSmith run verbatim; keeping it nested under `mcp.tool._meta`
(rather than flattened) keeps that clearly demarcated.
- Two FastMCP internals are load-bearing, and both now fail loudly
rather than silently. `elicitation="interrupt"` installs a sentinel
handler purely to trip the SDK's identity comparison against its default
callback, which is the only way the SDK lets a client declare the
capability; a test asserts the negotiated capability so a change
upstream cannot quietly stop servers asking. `_await_monitored` reaches
for FastMCP's private `_await_with_session_monitoring`, without which a
session dying mid-elicitation hangs the tool call; the fallback now
warns.
- `tests/unit_tests/mcp/conftest.py` grants `blockbuster` two narrow
allowances, both caused upstream in FastMCP: entering a server `Context`
resolves an optional dependency through `importlib.metadata` on every
in-process request, and `mcp.client.session` imports `jsonschema` lazily
on first tool call.

---

*Prepared with the assistance of an AI agent.*

---------

Signed-off-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
Co-authored-by: Hunter Lovell <hunter@hntrl.io>
Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
Co-authored-by: Sydney Runkle <sydney@langchain.dev>
2026-09-02 21:21:10 -07:00
John Kennedyandopen-swe[bot] f5ee2b65f4 chore(chroma): bump Pygments security constraint (#40162)
Chroma's development lock still selected Pygments 2.20.0, which is
affected by a published security advisory. Raise the existing transitive
dependency constraint to 2.21.0 and refresh the lockfile so development
and CI environments select the patched release.

The other recently reported Chroma lockfile dependencies were already
updated on `master`, are no longer present in the current uv dependency
graph, or do not yet have a compatible patched release.

This contribution was prepared with an AI coding agent.

Made by [Open
SWE](https://openswe.vercel.app/agents/867a14a4-e0cb-53ec-bf1a-70edcb54e89e)

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-02 19:03:27 -07:00
234255c1c7 chore(model-profiles): refresh model profile data (#40009)
Automated refresh of model profile data for all in-monorepo partner
integrations via `langchain-profiles refresh`.

🤖 Generated by the [`refresh_model_profiles`
workflow](https://github.com/langchain-ai/langchain/blob/master/.github/workflows/refresh_model_profiles.yml).

## Summary of changes

**10 added · 11 removed · 27 changed** across 4 provider(s).

<details>
<summary>fireworks-ai</summary>

**➕ 2 added**
- `accounts/fireworks/models/glm-5p3` — 1,000,000 ctx, 131,072 out,
reasoning, tools
- `accounts/fireworks/models/glm-5p3-flash` — 1,000,000 ctx, 131,072
out, text+image+video+pdf in, reasoning, tools

**➖ 3 removed**
- `accounts/fireworks/models/deepseek-v4-flash`
- `accounts/fireworks/models/gpt-oss-20b`
- `accounts/fireworks/models/minimax-m2p7`

**✏️ 4 changed**
- `accounts/fireworks/models/deepseek-v4-pro`: attachments no → unset;
audio input no → unset; audio output no → unset; image input no → unset;
image output no → unset; last updated `2026-04-24` → unset; max input
tokens 1,000,000 → unset; max output tokens 384,000 → unset; display
name `DeepSeek V4 Pro` → unset; removed open weights; removed reasoning;
release date `2026-04-24` → unset; removed structured output; removed
temperature control; removed text input; removed text output; removed
tool calling; video input no → unset; video output no → unset
- `accounts/fireworks/routers/kimi-k2p6-fast`: removed attachments;
audio input no → unset; audio output no → unset; removed image input;
image output no → unset; last updated `2026-06-05` → unset; max input
tokens 262,000 → unset; max output tokens 262,000 → unset; display name
`Kimi K2.6 Fast` → unset; removed open weights; removed reasoning;
release date `2026-04-17` → unset; removed temperature control; removed
text input; removed text output; removed tool calling; video input no →
unset; video output no → unset
- `accounts/fireworks/routers/kimi-k2p6-turbo`: removed attachments;
audio input no → unset; audio output no → unset; removed image input;
image output no → unset; last updated `2026-04-17` → unset; max input
tokens 262,000 → unset; max output tokens 262,000 → unset; display name
`Kimi K2.6 Turbo` → unset; removed open weights; removed reasoning;
release date `2026-04-17` → unset; removed temperature control; removed
text input; removed text output; removed tool calling; video input no →
unset; video output no → unset
- `accounts/fireworks/routers/kimi-k2p7-code-fast`: removed attachments;
audio input no → unset; audio output no → unset; removed image input;
image output no → unset; last updated `2026-06-16` → unset; max input
tokens 262,000 → unset; max output tokens 262,000 → unset; display name
`Kimi K2.7 Code Fast` → unset; removed open weights; removed reasoning;
release date `2026-06-12` → unset; removed temperature control; removed
text input; removed text output; removed tool calling; video input no →
unset; video output no → unset

</details>

<details>
<summary>groq</summary>

**➕ 1 added**
- `qwen/qwen3.8-27b` — 131,042 ctx, 16,384 out, text+image in,
reasoning, tools

</details>

<details>
<summary>huggingface</summary>

**➕ 1 added**
- `zai-org/GLM-5.3` — 1,048,576 ctx, 131,072 out, reasoning, tools

**✏️ 1 changed**
- `zai-org/GLM-5.3-Flash`: added attachments; added image input

</details>

<details>
<summary>openrouter</summary>

**➕ 6 added**
- `anthropic/claude-fable-5.1` — 1,000,000 ctx, 128,000 out,
text+image+pdf in, reasoning, tools
- `ibm-granite/granite-4.2-8b` — 131,072 ctx, 117,964 out, reasoning,
tools
- `inception/mercury-2.5-preview` — 260,000 ctx, 65,536 out, reasoning,
tools
- `inclusionai/ling-3.0-flash-fin:free` — 262,144 ctx, 32,768 out,
reasoning, tools
- `tencent/hy4-preview` — 1,048,576 ctx, 64,000 out, reasoning, tools
- `~z-ai/glm-flash-latest` — 1,310,720 ctx, 131,072 out,
text+image+video in, reasoning, tools

**➖ 8 removed**
- `allenai/olmo-3-32b-think`
- `anthropic/claude-opus-4.7-fast`
- `anthropic/claude-opus-4.8-fast`
- `anthropic/claude-opus-5-fast`
- `arcee-ai/virtuoso-large`
- `kwaipilot/kat-coder-air-v2.5`
- `mistralai/ministral-8b`
- `thedrummer/rocinante-12b`

**✏️ 22 changed**
- `arcee-ai/trinity-large-thinking`: max output tokens 235,929 → 80,000;
removed structured output
- `deepseek/deepseek-chat-v3.1`: max output tokens 144,900 → 32,768
- `deepseek/deepseek-v3.2`: max output tokens 147,456 → 65,536
- `deepseek/deepseek-v4-flash-vision-exp`: added structured output
- `deepseek/deepseek-v4-pro-0813`: max output tokens 943,717 → 384,000
- `google/gemma-3-27b-it`: max input tokens 262,144 → 131,072
- `kwaipilot/kat-coder-pro-v2`: max output tokens 80,000 → 144,000
- `kwaipilot/kat-coder-pro-v2.5`: max input tokens 256,000 → 262,144;
max output tokens 80,000 → 235,929
- `meta-llama/llama-4-maverick`: max output tokens 16,384 → 115,200
- `meta-llama/llama-4-scout`: max output tokens 8,192 → 16,384
- `meta/muse-glimmer-30b`: max output tokens 117,964 → 16,384
- `mistralai/voxtral-small-24b-2507`: max input tokens 32,000 → 32,768;
max output tokens 25,600 → 26,214
- `nvidia/nemotron-3-ultra-550b-a55b`: max input tokens 512,288 →
262,144; max output tokens 461,059 → 32,768
- `qwen/qwen3-vl-30b-a3b-instruct`: max output tokens 32,768 → 16,384
- `qwen/qwen3.5-122b-a10b`: max output tokens 235,929 → 81,920
- `qwen/qwen3.6-27b`: max output tokens 81,920 → 235,929
- `thinkingmachines/inkling`: max output tokens 262,144 → 471,859
- `z-ai/glm-5.1`: max output tokens 182,476 → 128,000
- `z-ai/glm-5.2`: max output tokens 262,144 → 131,072
- `z-ai/glm-5.3`: max input tokens 1,048,576 → 1,310,720; added open
weights; added structured output
- `~deepseek/deepseek-v4-flash-latest`: max output tokens 131,072 →
393,216
- `~z-ai/glm-latest`: max input tokens 1,048,576 → 1,310,720; max output
tokens 131,072 → 943,718; added structured output

</details>

Made by [Open
SWE](https://openswe.vercel.app/agents/756572b6-fcc8-59ee-bd9e-7d0c13386290)

---------

Co-authored-by: mdrxy <61371264+mdrxy@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-02 14:05:45 -04:00
dependabot[bot] 79e0e4adba chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/langchain (#40149)
Bumps [mistune](https://github.com/lepture/mistune) from 3.3.0 to 3.3.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lepture/mistune/releases">mistune's
releases</a>.</em></p>
<blockquote>
<h2>v3.3.3</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Set prev token in render_list_item and add block_text to
ignore_blocks  -  by <a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a> in <a
href="https://redirect.github.com/lepture/mistune/issues/456">lepture/mistune#456</a>
<a href="https://github.com/lepture/mistune/commit/0799e19"><!-- raw
HTML omitted -->(0799e)<!-- raw HTML omitted --></a></li>
<li>Improve nested bracket link input  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/fe02f40"><!-- raw HTML
omitted -->(fe02f)<!-- raw HTML omitted --></a></li>
<li>Escape literal emphasis markers in MarkdownRenderer  -  by <a
href="https://github.com/Sanjays2402"><code>@​Sanjays2402</code></a> <a
href="https://github.com/lepture/mistune/commit/b042996"><!-- raw HTML
omitted -->(b0429)<!-- raw HTML omitted --></a></li>
<li>Use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/4009f67"><!-- raw HTML
omitted -->(4009f)<!-- raw HTML omitted --></a></li>
<li>Add max_emphasis_depth  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/0938fb7"><!-- raw HTML
omitted -->(0938f)<!-- raw HTML omitted --></a></li>
<li>Add image max depth  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/cca5ee6"><!-- raw HTML
omitted -->(cca5e)<!-- raw HTML omitted --></a></li>
<li><strong>inline</strong>: Use original run length in emphasis
multiple-of-3 rule  -  by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a> and
<strong>Claude Opus 4.8 (1M context)</strong> <a
href="https://github.com/lepture/mistune/commit/2d26bc8"><!-- raw HTML
omitted -->(2d26b)<!-- raw HTML omitted --></a></li>
</ul>
<h3>   🏎 Performance</h3>
<ul>
<li>Improve link label parsing performance  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/e001d51"><!-- raw HTML
omitted -->(e001d)<!-- raw HTML omitted --></a></li>
<li>Improve performance for math and formatting plugins  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/c2228a2"><!-- raw HTML
omitted -->(c2228)<!-- raw HTML omitted --></a></li>
<li>Improve for footnotes, ruby and spoiler  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/ae7e9d5"><!-- raw HTML
omitted -->(ae7e9)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.2...v3.3.3">View
changes on GitHub</a></h5>
<h2>v3.3.2</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Try to support python 3.8  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/c9f1a54"><!-- raw HTML
omitted -->(c9f1a)<!-- raw HTML omitted --></a></li>
<li>Resolve mypy issues for python 3.8 and 3.9+  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/29b70a9"><!-- raw HTML
omitted -->(29b70)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.1...v3.3.2">View
changes on GitHub</a></h5>
<h2>v3.3.1</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li><strong>abbr</strong>: Update process_text method in abrr, adding
parse_emphasis parameter  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/ae850f5"><!-- raw HTML
omitted -->(ae850)<!-- raw HTML omitted --></a></li>
<li><strong>directive</strong>: Use correct file path for include
directive  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/18c21d7"><!-- raw HTML
omitted -->(18c21)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.1">View
changes on GitHub</a></h5>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/lepture/mistune/blob/main/docs/changes.rst">mistune's
changelog</a>.</em></p>
<blockquote>
<h2>Version 3.3.3</h2>
<p><strong>Released on Jul 9, 2026</strong></p>
<ul>
<li>Limit deeply nested emphasis and image parsing to avoid
<code>RecursionError</code>.</li>
<li>Fix repeated link suffix and unclosed formatting marker performance
issues.</li>
<li>Fix unclosed inline spoiler performance issues.</li>
<li>Avoid recursive parsing for adjacent ruby tokens.</li>
<li>Speed up footnote reference indexing.</li>
</ul>
<h2>Version 3.3.2</h2>
<p><strong>Released on Jun 23, 2026</strong></p>
<ul>
<li>Fix Python 3.8 import compatibility in the inline parser.</li>
<li>Fix mypy compatibility for list parsing on Python 3.8 and 3.9+.</li>
</ul>
<h2>Version 3.3.1</h2>
<p><strong>Released on Jun 22, 2026</strong></p>
<ul>
<li>Fix <code>abbr</code> plugin compatibility with escaped inline
text.</li>
<li>Normalize included Markdown line endings before parsing
directives.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lepture/mistune/commit/060f73ac87e8cf6d9e9b48f2df28c0654d845a4c"><code>060f73a</code></a>
chore: release 3.3.3</li>
<li><a
href="https://github.com/lepture/mistune/commit/ae7e9d571f621b82b287ed98d421893dab87b018"><code>ae7e9d5</code></a>
perf: improve for footnotes, ruby and spoiler</li>
<li><a
href="https://github.com/lepture/mistune/commit/c2228a25ddf66baf73e452edd42bde778c1ce61a"><code>c2228a2</code></a>
perf: improve performance for math and formatting plugins</li>
<li><a
href="https://github.com/lepture/mistune/commit/e001d513a6f57c8a6ed08afcf6217c7dbd74e349"><code>e001d51</code></a>
perf: improve link label parsing performance</li>
<li><a
href="https://github.com/lepture/mistune/commit/cca5ee6d17a458b115d5e63ab95ddedcfb7a15e4"><code>cca5ee6</code></a>
fix: add image max depth</li>
<li><a
href="https://github.com/lepture/mistune/commit/0938fb781d0aded99de801b340ec1f8debeae5b2"><code>0938fb7</code></a>
fix: add max_emphasis_depth</li>
<li><a
href="https://github.com/lepture/mistune/commit/9946c9207d74a55eed872483ab3c9cdc698b89cc"><code>9946c92</code></a>
tests: update dealine time for pypy</li>
<li><a
href="https://github.com/lepture/mistune/commit/4009f67afc674225bbb3aa901614946feebfe4c9"><code>4009f67</code></a>
fix: use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS</li>
<li><a
href="https://github.com/lepture/mistune/commit/30255494bc8fdd14c7a0fd5b0e2c5fc3d4243745"><code>3025549</code></a>
Merge pull request <a
href="https://redirect.github.com/lepture/mistune/issues/462">#462</a>
from Sanjays2402/fix/markdown-renderer-escape-emphasis</li>
<li><a
href="https://github.com/lepture/mistune/commit/b042996659275aa9719d6efa37163bea62b34cd5"><code>b042996</code></a>
fix: escape literal emphasis markers in MarkdownRenderer</li>
<li>Additional commits viewable in <a
href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.3">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 17:20:34 +00:00
dependabot[bot] e90201b7af chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (#40150)
Bumps [mistune](https://github.com/lepture/mistune) from 3.3.0 to 3.3.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lepture/mistune/releases">mistune's
releases</a>.</em></p>
<blockquote>
<h2>v3.3.3</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Set prev token in render_list_item and add block_text to
ignore_blocks  -  by <a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a> in <a
href="https://redirect.github.com/lepture/mistune/issues/456">lepture/mistune#456</a>
<a href="https://github.com/lepture/mistune/commit/0799e19"><!-- raw
HTML omitted -->(0799e)<!-- raw HTML omitted --></a></li>
<li>Improve nested bracket link input  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/fe02f40"><!-- raw HTML
omitted -->(fe02f)<!-- raw HTML omitted --></a></li>
<li>Escape literal emphasis markers in MarkdownRenderer  -  by <a
href="https://github.com/Sanjays2402"><code>@​Sanjays2402</code></a> <a
href="https://github.com/lepture/mistune/commit/b042996"><!-- raw HTML
omitted -->(b0429)<!-- raw HTML omitted --></a></li>
<li>Use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/4009f67"><!-- raw HTML
omitted -->(4009f)<!-- raw HTML omitted --></a></li>
<li>Add max_emphasis_depth  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/0938fb7"><!-- raw HTML
omitted -->(0938f)<!-- raw HTML omitted --></a></li>
<li>Add image max depth  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/cca5ee6"><!-- raw HTML
omitted -->(cca5e)<!-- raw HTML omitted --></a></li>
<li><strong>inline</strong>: Use original run length in emphasis
multiple-of-3 rule  -  by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a> and
<strong>Claude Opus 4.8 (1M context)</strong> <a
href="https://github.com/lepture/mistune/commit/2d26bc8"><!-- raw HTML
omitted -->(2d26b)<!-- raw HTML omitted --></a></li>
</ul>
<h3>   🏎 Performance</h3>
<ul>
<li>Improve link label parsing performance  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/e001d51"><!-- raw HTML
omitted -->(e001d)<!-- raw HTML omitted --></a></li>
<li>Improve performance for math and formatting plugins  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/c2228a2"><!-- raw HTML
omitted -->(c2228)<!-- raw HTML omitted --></a></li>
<li>Improve for footnotes, ruby and spoiler  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/ae7e9d5"><!-- raw HTML
omitted -->(ae7e9)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.2...v3.3.3">View
changes on GitHub</a></h5>
<h2>v3.3.2</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Try to support python 3.8  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/c9f1a54"><!-- raw HTML
omitted -->(c9f1a)<!-- raw HTML omitted --></a></li>
<li>Resolve mypy issues for python 3.8 and 3.9+  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/29b70a9"><!-- raw HTML
omitted -->(29b70)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.1...v3.3.2">View
changes on GitHub</a></h5>
<h2>v3.3.1</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li><strong>abbr</strong>: Update process_text method in abrr, adding
parse_emphasis parameter  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/ae850f5"><!-- raw HTML
omitted -->(ae850)<!-- raw HTML omitted --></a></li>
<li><strong>directive</strong>: Use correct file path for include
directive  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/18c21d7"><!-- raw HTML
omitted -->(18c21)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.1">View
changes on GitHub</a></h5>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/lepture/mistune/blob/main/docs/changes.rst">mistune's
changelog</a>.</em></p>
<blockquote>
<h2>Version 3.3.3</h2>
<p><strong>Released on Jul 9, 2026</strong></p>
<ul>
<li>Limit deeply nested emphasis and image parsing to avoid
<code>RecursionError</code>.</li>
<li>Fix repeated link suffix and unclosed formatting marker performance
issues.</li>
<li>Fix unclosed inline spoiler performance issues.</li>
<li>Avoid recursive parsing for adjacent ruby tokens.</li>
<li>Speed up footnote reference indexing.</li>
</ul>
<h2>Version 3.3.2</h2>
<p><strong>Released on Jun 23, 2026</strong></p>
<ul>
<li>Fix Python 3.8 import compatibility in the inline parser.</li>
<li>Fix mypy compatibility for list parsing on Python 3.8 and 3.9+.</li>
</ul>
<h2>Version 3.3.1</h2>
<p><strong>Released on Jun 22, 2026</strong></p>
<ul>
<li>Fix <code>abbr</code> plugin compatibility with escaped inline
text.</li>
<li>Normalize included Markdown line endings before parsing
directives.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lepture/mistune/commit/060f73ac87e8cf6d9e9b48f2df28c0654d845a4c"><code>060f73a</code></a>
chore: release 3.3.3</li>
<li><a
href="https://github.com/lepture/mistune/commit/ae7e9d571f621b82b287ed98d421893dab87b018"><code>ae7e9d5</code></a>
perf: improve for footnotes, ruby and spoiler</li>
<li><a
href="https://github.com/lepture/mistune/commit/c2228a25ddf66baf73e452edd42bde778c1ce61a"><code>c2228a2</code></a>
perf: improve performance for math and formatting plugins</li>
<li><a
href="https://github.com/lepture/mistune/commit/e001d513a6f57c8a6ed08afcf6217c7dbd74e349"><code>e001d51</code></a>
perf: improve link label parsing performance</li>
<li><a
href="https://github.com/lepture/mistune/commit/cca5ee6d17a458b115d5e63ab95ddedcfb7a15e4"><code>cca5ee6</code></a>
fix: add image max depth</li>
<li><a
href="https://github.com/lepture/mistune/commit/0938fb781d0aded99de801b340ec1f8debeae5b2"><code>0938fb7</code></a>
fix: add max_emphasis_depth</li>
<li><a
href="https://github.com/lepture/mistune/commit/9946c9207d74a55eed872483ab3c9cdc698b89cc"><code>9946c92</code></a>
tests: update dealine time for pypy</li>
<li><a
href="https://github.com/lepture/mistune/commit/4009f67afc674225bbb3aa901614946feebfe4c9"><code>4009f67</code></a>
fix: use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS</li>
<li><a
href="https://github.com/lepture/mistune/commit/30255494bc8fdd14c7a0fd5b0e2c5fc3d4243745"><code>3025549</code></a>
Merge pull request <a
href="https://redirect.github.com/lepture/mistune/issues/462">#462</a>
from Sanjays2402/fix/markdown-renderer-escape-emphasis</li>
<li><a
href="https://github.com/lepture/mistune/commit/b042996659275aa9719d6efa37163bea62b34cd5"><code>b042996</code></a>
fix: escape literal emphasis markers in MarkdownRenderer</li>
<li>Additional commits viewable in <a
href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=mistune&package-manager=uv&previous-version=3.3.0&new-version=3.3.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 10:16:08 -07:00
dependabot[bot] 4240248e7b chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/text-splitters (#40148)
Bumps [mistune](https://github.com/lepture/mistune) from 3.3.0 to 3.3.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lepture/mistune/releases">mistune's
releases</a>.</em></p>
<blockquote>
<h2>v3.3.3</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Set prev token in render_list_item and add block_text to
ignore_blocks  -  by <a
href="https://github.com/gaoflow"><code>@​gaoflow</code></a> in <a
href="https://redirect.github.com/lepture/mistune/issues/456">lepture/mistune#456</a>
<a href="https://github.com/lepture/mistune/commit/0799e19"><!-- raw
HTML omitted -->(0799e)<!-- raw HTML omitted --></a></li>
<li>Improve nested bracket link input  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/fe02f40"><!-- raw HTML
omitted -->(fe02f)<!-- raw HTML omitted --></a></li>
<li>Escape literal emphasis markers in MarkdownRenderer  -  by <a
href="https://github.com/Sanjays2402"><code>@​Sanjays2402</code></a> <a
href="https://github.com/lepture/mistune/commit/b042996"><!-- raw HTML
omitted -->(b0429)<!-- raw HTML omitted --></a></li>
<li>Use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/4009f67"><!-- raw HTML
omitted -->(4009f)<!-- raw HTML omitted --></a></li>
<li>Add max_emphasis_depth  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/0938fb7"><!-- raw HTML
omitted -->(0938f)<!-- raw HTML omitted --></a></li>
<li>Add image max depth  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/cca5ee6"><!-- raw HTML
omitted -->(cca5e)<!-- raw HTML omitted --></a></li>
<li><strong>inline</strong>: Use original run length in emphasis
multiple-of-3 rule  -  by <a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a> and
<strong>Claude Opus 4.8 (1M context)</strong> <a
href="https://github.com/lepture/mistune/commit/2d26bc8"><!-- raw HTML
omitted -->(2d26b)<!-- raw HTML omitted --></a></li>
</ul>
<h3>   🏎 Performance</h3>
<ul>
<li>Improve link label parsing performance  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/e001d51"><!-- raw HTML
omitted -->(e001d)<!-- raw HTML omitted --></a></li>
<li>Improve performance for math and formatting plugins  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/c2228a2"><!-- raw HTML
omitted -->(c2228)<!-- raw HTML omitted --></a></li>
<li>Improve for footnotes, ruby and spoiler  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/ae7e9d5"><!-- raw HTML
omitted -->(ae7e9)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.2...v3.3.3">View
changes on GitHub</a></h5>
<h2>v3.3.2</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Try to support python 3.8  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/c9f1a54"><!-- raw HTML
omitted -->(c9f1a)<!-- raw HTML omitted --></a></li>
<li>Resolve mypy issues for python 3.8 and 3.9+  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/29b70a9"><!-- raw HTML
omitted -->(29b70)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.1...v3.3.2">View
changes on GitHub</a></h5>
<h2>v3.3.1</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li><strong>abbr</strong>: Update process_text method in abrr, adding
parse_emphasis parameter  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/ae850f5"><!-- raw HTML
omitted -->(ae850)<!-- raw HTML omitted --></a></li>
<li><strong>directive</strong>: Use correct file path for include
directive  -  by <a
href="https://github.com/lepture"><code>@​lepture</code></a> <a
href="https://github.com/lepture/mistune/commit/18c21d7"><!-- raw HTML
omitted -->(18c21)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.1">View
changes on GitHub</a></h5>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/lepture/mistune/blob/main/docs/changes.rst">mistune's
changelog</a>.</em></p>
<blockquote>
<h2>Version 3.3.3</h2>
<p><strong>Released on Jul 9, 2026</strong></p>
<ul>
<li>Limit deeply nested emphasis and image parsing to avoid
<code>RecursionError</code>.</li>
<li>Fix repeated link suffix and unclosed formatting marker performance
issues.</li>
<li>Fix unclosed inline spoiler performance issues.</li>
<li>Avoid recursive parsing for adjacent ruby tokens.</li>
<li>Speed up footnote reference indexing.</li>
</ul>
<h2>Version 3.3.2</h2>
<p><strong>Released on Jun 23, 2026</strong></p>
<ul>
<li>Fix Python 3.8 import compatibility in the inline parser.</li>
<li>Fix mypy compatibility for list parsing on Python 3.8 and 3.9+.</li>
</ul>
<h2>Version 3.3.1</h2>
<p><strong>Released on Jun 22, 2026</strong></p>
<ul>
<li>Fix <code>abbr</code> plugin compatibility with escaped inline
text.</li>
<li>Normalize included Markdown line endings before parsing
directives.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lepture/mistune/commit/060f73ac87e8cf6d9e9b48f2df28c0654d845a4c"><code>060f73a</code></a>
chore: release 3.3.3</li>
<li><a
href="https://github.com/lepture/mistune/commit/ae7e9d571f621b82b287ed98d421893dab87b018"><code>ae7e9d5</code></a>
perf: improve for footnotes, ruby and spoiler</li>
<li><a
href="https://github.com/lepture/mistune/commit/c2228a25ddf66baf73e452edd42bde778c1ce61a"><code>c2228a2</code></a>
perf: improve performance for math and formatting plugins</li>
<li><a
href="https://github.com/lepture/mistune/commit/e001d513a6f57c8a6ed08afcf6217c7dbd74e349"><code>e001d51</code></a>
perf: improve link label parsing performance</li>
<li><a
href="https://github.com/lepture/mistune/commit/cca5ee6d17a458b115d5e63ab95ddedcfb7a15e4"><code>cca5ee6</code></a>
fix: add image max depth</li>
<li><a
href="https://github.com/lepture/mistune/commit/0938fb781d0aded99de801b340ec1f8debeae5b2"><code>0938fb7</code></a>
fix: add max_emphasis_depth</li>
<li><a
href="https://github.com/lepture/mistune/commit/9946c9207d74a55eed872483ab3c9cdc698b89cc"><code>9946c92</code></a>
tests: update dealine time for pypy</li>
<li><a
href="https://github.com/lepture/mistune/commit/4009f67afc674225bbb3aa901614946feebfe4c9"><code>4009f67</code></a>
fix: use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS</li>
<li><a
href="https://github.com/lepture/mistune/commit/30255494bc8fdd14c7a0fd5b0e2c5fc3d4243745"><code>3025549</code></a>
Merge pull request <a
href="https://redirect.github.com/lepture/mistune/issues/462">#462</a>
from Sanjays2402/fix/markdown-renderer-escape-emphasis</li>
<li><a
href="https://github.com/lepture/mistune/commit/b042996659275aa9719d6efa37163bea62b34cd5"><code>b042996</code></a>
fix: escape literal emphasis markers in MarkdownRenderer</li>
<li>Additional commits viewable in <a
href="https://github.com/lepture/mistune/compare/v3.3.0...v3.3.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=mistune&package-manager=uv&previous-version=3.3.0&new-version=3.3.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 10:16:05 -07:00
github-actions[bot] 530290a9d4 chore(deps): bump uv to 0.12.8 (#40092)
Bumps the uv pin in `.github/actions/uv_setup/action.yml` from `0.12.1`
to [`0.12.8`](https://github.com/astral-sh/uv/releases/tag/0.12.8).

Opened automatically by `bump_uv_pin.yml`. Mirror availability on
`releases.astral.sh` was verified before this PR was created, so CI
should not race the fallback.

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-02 08:37:56 +00:00
1eeca8c318 chore(deps): bump the minor-and-patch group across 3 directories with 5 updates (#40085)
Bumps the minor-and-patch group with 1 update in the
/libs/model-profiles directory:
[ruff](https://github.com/astral-sh/ruff).
Bumps the minor-and-patch group with 2 updates in the
/libs/standard-tests directory:
[ruff](https://github.com/astral-sh/ruff) and
[pytest-benchmark](https://github.com/ionelmc/pytest-benchmark).
Bumps the minor-and-patch group with 4 updates in the
/libs/text-splitters directory:
[ruff](https://github.com/astral-sh/ruff),
[ty](https://github.com/astral-sh/ty),
[spacy](https://github.com/explosion/spaCy) and
[transformers](https://github.com/huggingface/transformers).

Updates `ruff` from 0.16.4 to 0.16.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<h2>Release Notes</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
<h2>Install ruff 0.16.5</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1
| iex&quot;
</code></pre>
<h2>Download ruff 0.16.5</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a>
Bump 0.16.5 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a>
Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a>
Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a>
Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a>
Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a>
Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a>
[ty] Infer lambda parameters through callable type aliases (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a>
[ty] Narrow functional enum members in <code>==</code> and
<code>match</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a>
[ty] Intersection simplifications with subtype-related generic
specialization...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a>
[ty] Bump ecosystem-analyzer for HTML escaping (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.4 to 0.16.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<h2>Release Notes</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
<h2>Install ruff 0.16.5</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1
| iex&quot;
</code></pre>
<h2>Download ruff 0.16.5</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a>
Bump 0.16.5 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a>
Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a>
Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a>
Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a>
Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a>
Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a>
[ty] Infer lambda parameters through callable type aliases (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a>
[ty] Narrow functional enum members in <code>==</code> and
<code>match</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a>
[ty] Intersection simplifications with subtype-related generic
specialization...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a>
[ty] Bump ecosystem-analyzer for HTML escaping (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.4 to 0.16.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<h2>Release Notes</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
<h2>Install ruff 0.16.5</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1
| iex&quot;
</code></pre>
<h2>Download ruff 0.16.5</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a>
Bump 0.16.5 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a>
Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a>
Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a>
Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a>
Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a>
Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a>
[ty] Infer lambda parameters through callable type aliases (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a>
[ty] Narrow functional enum members in <code>==</code> and
<code>match</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a>
[ty] Intersection simplifications with subtype-related generic
specialization...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a>
[ty] Bump ecosystem-analyzer for HTML escaping (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.4 to 0.16.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<h2>Release Notes</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
<h2>Install ruff 0.16.5</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1
| iex&quot;
</code></pre>
<h2>Download ruff 0.16.5</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a>
Bump 0.16.5 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a>
Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a>
Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a>
Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a>
Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a>
Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a>
[ty] Infer lambda parameters through callable type aliases (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a>
[ty] Narrow functional enum members in <code>==</code> and
<code>match</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a>
[ty] Intersection simplifications with subtype-related generic
specialization...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a>
[ty] Bump ecosystem-analyzer for HTML escaping (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `pytest-benchmark` from 5.2.3 to 5.3.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ionelmc/pytest-benchmark/releases">pytest-benchmark's
releases</a>.</em></p>
<blockquote>
<h2>v5.3.0</h2>
<ul>
<li>Added <code>--benchmark-precision</code> and
<code>--benchmark-confidence</code>: instead of a fixed number of
rounds, stop once the mean's relative margin of error falls below the
given fraction. Contributed by Aarni Koskela in <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/318">ionelmc/pytest-benchmark#318</a>.</li>
<li>Added compare <code>--between</code> mode. Example:
<code>pytest-benchmark compare --between=min 0001 0002</code>.
Contributed by Aarni Koskela in <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/302">ionelmc/pytest-benchmark#302</a>.</li>
<li>Modernized the CI/linting and added spellchecking. Contributed by
Aarni Koskela in <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/304">ionelmc/pytest-benchmark#304</a>,
<a
href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/306">ionelmc/pytest-benchmark#306</a>
and <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/319">ionelmc/pytest-benchmark#319</a>.</li>
<li>Defer the xdist auto-disable warning until a benchmark fixture is
collected. Contributed by xlyyddy in <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/317">ionelmc/pytest-benchmark#317</a>
(fixes <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/issues/65">ionelmc/pytest-benchmark#65</a>).</li>
<li>Replaced deprecated <code>argparse.FileType</code>. Contributed by
Sophia Castellarin in <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/310">ionelmc/pytest-benchmark#310</a>.</li>
<li>Fixed various spelling/typos. Contributed by Daniel Holth and Hugo
van Kemenade in <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/297">ionelmc/pytest-benchmark#297</a>
and <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/299">ionelmc/pytest-benchmark#299</a>.</li>
<li>Cleaned up various dead code. Contributed by Hugo van Kemenade in <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/300">ionelmc/pytest-benchmark#300</a>
and <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/pull/301">ionelmc/pytest-benchmark#301</a>.</li>
<li>CI now tests only with latest Pytest (now 9.1.1), Python 3.10-3.14
and PyPy 3.11.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/ionelmc/pytest-benchmark/blob/master/CHANGELOG.rst">pytest-benchmark's
changelog</a>.</em></p>
<blockquote>
<h2>v5.3.0 (2026-08-23)</h2>
<ul>
<li>Added <code>--benchmark-precision</code> and
<code>--benchmark-confidence</code>:
instead of a fixed number of rounds, stop once the mean's relative
margin of error falls below the given fraction.
Contributed by Aarni Koskela in
<code>[#318](https://github.com/ionelmc/pytest-benchmark/issues/318)
&lt;https://github.com/ionelmc/pytest-benchmark/pull/318&gt;</code>_.</li>
<li>Added <code>compare --between</code> mode. Example:
<code>pytest-benchmark compare --between=min 0001 0002</code>.
Contributed by Aarni Koskela in
<code>[#302](https://github.com/ionelmc/pytest-benchmark/issues/302)
&lt;https://github.com/ionelmc/pytest-benchmark/pull/302&gt;</code>_.</li>
<li>Modernized the CI/linting and added spellchecking.
Contributed by Aarni Koskela in
<code>[#304](https://github.com/ionelmc/pytest-benchmark/issues/304)
&lt;https://github.com/ionelmc/pytest-benchmark/pull/304&gt;</code><em>,
<code>[#306](https://github.com/ionelmc/pytest-benchmark/issues/306)
&lt;https://github.com/ionelmc/pytest-benchmark/pull/306&gt;</code></em>
and
<code>[#319](https://github.com/ionelmc/pytest-benchmark/issues/319)
&lt;https://github.com/ionelmc/pytest-benchmark/pull/319&gt;</code>_.</li>
<li>Defer the xdist auto-disable warning until a benchmark fixture is
collected.
Contributed by xlyyddy in
<code>[#317](https://github.com/ionelmc/pytest-benchmark/issues/317)
&lt;https://github.com/ionelmc/pytest-benchmark/pull/317&gt;</code>_
(fixes
<code>[#65](https://github.com/ionelmc/pytest-benchmark/issues/65)
&lt;https://github.com/ionelmc/pytest-benchmark/issues/65&gt;</code>_).</li>
<li>Replaced deprecated argparse.FileType.
Contributed by Sophia Castellarin in
<code>[#310](https://github.com/ionelmc/pytest-benchmark/issues/310)
&lt;https://github.com/ionelmc/pytest-benchmark/pull/310&gt;</code>_.</li>
<li>Fixed various spelling/typos.
Contributed by Daniel Holth and Hugo van Kemenade in
<code>[#297](https://github.com/ionelmc/pytest-benchmark/issues/297)
&lt;https://github.com/ionelmc/pytest-benchmark/pull/297&gt;</code>_ and
<code>[#299](https://github.com/ionelmc/pytest-benchmark/issues/299)
&lt;https://github.com/ionelmc/pytest-benchmark/pull/299&gt;</code>_.</li>
<li>Cleaned up various dead code.
Contributed by Hugo van Kemenade in
<code>[#300](https://github.com/ionelmc/pytest-benchmark/issues/300)
&lt;https://github.com/ionelmc/pytest-benchmark/pull/300&gt;</code>_ and
<code>[#301](https://github.com/ionelmc/pytest-benchmark/issues/301)
&lt;https://github.com/ionelmc/pytest-benchmark/pull/301&gt;</code>_.</li>
<li>CI now tests only with latest Pytest (now 9.1.1), Python 3.10-3.14
and PyPy 3.11.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ionelmc/pytest-benchmark/commit/07d519672687402e6c3fac1a543fbefd810d1e5b"><code>07d5196</code></a>
Bump version: 5.2.3 → 5.3.0</li>
<li><a
href="https://github.com/ionelmc/pytest-benchmark/commit/accf7331e22c0ede38ffa72081c38f3469e0c9b5"><code>accf733</code></a>
Add some details on <a
href="https://redirect.github.com/ionelmc/pytest-benchmark/issues/304">#304</a>.</li>
<li><a
href="https://github.com/ionelmc/pytest-benchmark/commit/417dd9fa275e8b9d62c469e676cdb7546d2c4b8f"><code>417dd9f</code></a>
Really update the changelog.</li>
<li><a
href="https://github.com/ionelmc/pytest-benchmark/commit/898acb34430c99ad877e94c52c8b90256a3bb4a8"><code>898acb3</code></a>
Update changelog and plan release.</li>
<li><a
href="https://github.com/ionelmc/pytest-benchmark/commit/9cc7ef0bb1ad3785a46834b24660562dd48e4a0b"><code>9cc7ef0</code></a>
Defer xdist warning until benchmark collection (<a
href="https://redirect.github.com/ionelmc/pytest-benchmark/issues/65">#65</a>)</li>
<li><a
href="https://github.com/ionelmc/pytest-benchmark/commit/ef485506f04d5510831fdbdee5be7014f4726a93"><code>ef48550</code></a>
Some minor skel updates: test only against latest pytest; bump
linting/format...</li>
<li><a
href="https://github.com/ionelmc/pytest-benchmark/commit/88eaea957d1685f604a5835555d2ce5dbec1ac29"><code>88eaea9</code></a>
Add --benchmark-precision for adaptive rounds (opt-in)</li>
<li><a
href="https://github.com/ionelmc/pytest-benchmark/commit/3b83d127127de74d9f71a3a78e5f661fac044950"><code>3b83d12</code></a>
Update and freeze GHA actions</li>
<li><a
href="https://github.com/ionelmc/pytest-benchmark/commit/4b7662fbfba046eb92dd183e005e8708ac81e6cd"><code>4b7662f</code></a>
Fix ruff complaints</li>
<li><a
href="https://github.com/ionelmc/pytest-benchmark/commit/26b011361d2c41f529a73833e1be8d3a565600fa"><code>26b0113</code></a>
Remove Taplo lint (unmaintained)</li>
<li>Additional commits viewable in <a
href="https://github.com/ionelmc/pytest-benchmark/compare/v5.2.3...v5.3.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.4 to 0.16.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<h2>Release Notes</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
<h2>Install ruff 0.16.5</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1
| iex&quot;
</code></pre>
<h2>Download ruff 0.16.5</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a>
Bump 0.16.5 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a>
Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a>
Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a>
Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a>
Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a>
Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a>
[ty] Infer lambda parameters through callable type aliases (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a>
[ty] Narrow functional enum members in <code>==</code> and
<code>match</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a>
[ty] Intersection simplifications with subtype-related generic
specialization...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a>
[ty] Bump ecosystem-analyzer for HTML escaping (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.4 to 0.16.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<h2>Release Notes</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
<h2>Install ruff 0.16.5</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1
| iex&quot;
</code></pre>
<h2>Download ruff 0.16.5</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a>
Bump 0.16.5 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a>
Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a>
Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a>
Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a>
Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a>
Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a>
[ty] Infer lambda parameters through callable type aliases (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a>
[ty] Narrow functional enum members in <code>==</code> and
<code>match</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a>
[ty] Intersection simplifications with subtype-related generic
specialization...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a>
[ty] Bump ecosystem-analyzer for HTML escaping (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.4 to 0.16.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<h2>Release Notes</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
<h2>Install ruff 0.16.5</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1
| iex&quot;
</code></pre>
<h2>Download ruff 0.16.5</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/9e4938c4a60bed3e87a11ee1e1db1bd23f4d964a"><code>9e4938c</code></a>
Bump 0.16.5 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28110">#28110</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/aad0e909ef1390f4b2a3ba8aa0a67fb8ea5cbacd"><code>aad0e90</code></a>
Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28049">#28049</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/5fdab73c5052350400c36b08c5d7710210343bc4"><code>5fdab73</code></a>
Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27877">#27877</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/29c8e5b2d0a46eb7dc4ff11c1b0a0dc5ccea52e4"><code>29c8e5b</code></a>
Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27910">#27910</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/50a4d7fd106603a5616b01ac3bef3306252b248f"><code>50a4d7f</code></a>
Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27906">#27906</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/ada87950ea188f882f69b7bd6e2213a9696e3ee2"><code>ada8795</code></a>
Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/issues/27666">#27666</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/d8947238863b61922bfc83f07edcc697c1cc07c0"><code>d894723</code></a>
[ty] Infer lambda parameters through callable type aliases (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28109">#28109</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/2685fdebbcf9938736fed8c45886a629f9c99a06"><code>2685fde</code></a>
[ty] Narrow functional enum members in <code>==</code> and
<code>match</code> (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28103">#28103</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/efcffd2178ce62e9951a53d4c50cadc225a0cfec"><code>efcffd2</code></a>
[ty] Intersection simplifications with subtype-related generic
specialization...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/eb780488037504e11f145ed778654fd8a825028b"><code>eb78048</code></a>
[ty] Bump ecosystem-analyzer for HTML escaping (<a
href="https://redirect.github.com/astral-sh/ruff/issues/28104">#28104</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.16.4 to 0.16.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<h2>Release Notes</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot; in <code>ClientOptions</code> doc
comment (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27978">#27978</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>Document rule acceptance guidelines (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27910">#27910</a>)</li>
<li>Document the new category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27906">#27906</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/AlexWaygood"><code>@​AlexWaygood</code></a></li>
<li><a href="https://github.com/sharkdp"><code>@​sharkdp</code></a></li>
<li><a
href="https://github.com/jelle-openai"><code>@​jelle-openai</code></a></li>
<li><a
href="https://github.com/charliermarsh"><code>@​charliermarsh</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
<li><a
href="https://github.com/aarushkandukoori"><code>@​aarushkandukoori</code></a></li>
</ul>
<h2>Install ruff 0.16.5</h2>
<h3>Install prebuilt binaries via shell script</h3>
<pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh
| sh
</code></pre>
<h3>Install prebuilt binaries via powershell script</h3>
<pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c &quot;irm
https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1
| iex&quot;
</code></pre>
<h2>Download ruff 0.16.5</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.16.5</h2>
<p>Released on 2026-08-27.</p>
<h3>Preview features</h3>
<ul>
<li>Allow rules without codes (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28049">#28049</a>)</li>
<li>Introduce category selectors (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27666">#27666</a>)</li>
<li>Update preview default rules and categories (<a
href="https://redirect.github.com/astral-sh/ruff/pull/27877">#27877</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>[<code>flake8-async</code>] Detect blocking generic HTTP requests
(<code>ASYNC210</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28024">#28024</a>)</li>
<li>[<code>flake8-datetimez</code>] Allow timezone-safe
<code>strptime</code> chains (<code>DTZ007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28023">#28023</a>)</li>
<li>[<code>flake8-simplify</code>] Respect side effects in
<code>lambda</code> defaults (<code>SIM401</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/28000">#28000</a>)</li>
</ul>
<h3>Server</h3>
<ul>
<li>Fix duplicated &quot;of&quot;...

_Description has been truncated_

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-02 01:30:54 -07:00
dependabot[bot] 8e103b5ba7 chore(huggingface): bump transformers from 5.5.0 to 5.10.1 (#40117)
Bumps [transformers](https://github.com/huggingface/transformers) from
5.5.0 to 5.10.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/huggingface/transformers/releases">transformers's
releases</a>.</em></p>
<blockquote>
<h1>Release v5.10.1</h1>
<p>v5.10.0 was yanked as we publish on a corrupted branch. Sorry
everyone, this happens when we rush a release!!!</p>
<h2>New Model additions</h2>
<h3>Gemma4 unified+ Gemma4 MTP</h3>
<!-- raw HTML omitted -->
<p>Gemma 4 12B Unified is an <strong>encoder-free</strong> multimodal
model with pretrained and instruction-tuned variants. Unlike <a
href="https://github.com/huggingface/transformers/blob/HEAD/gemma4">standard
Gemma 4</a>, which uses dedicated encoder towers, Gemma 4 12B Unified
projects raw inputs directly into the language model's embedding space
through lightweight linear pipelines. This results in a simpler
architecture while maintaining strong multimodal performance.</p>
<p>Key differences from standard Gemma 4:</p>
<ul>
<li><strong>No Vision Tower</strong>: Raw pixel patches are projected
directly into LM space via a <code>Dense + LayerNorm</code> pipeline
with factorized 2D positional embeddings, replacing the vision
encoder.</li>
<li><strong>No Audio Tower</strong>: Raw 16 kHz waveform samples are
chunked into fixed-length frames and projected through a simple
<code>RMSNorm → Linear</code> pipeline, replacing the mel spectrogram +
Conformer encoder.</li>
<li><strong>Shared Multimodal Pipeline</strong>: Both vision and audio
use the same <code>Gemma4UnifiedMultimodalEmbedder</code> (RMSNorm →
Linear) for the final projection to text hidden space.</li>
</ul>
<p>You can find the original Gemma 4 12B Unified checkpoints under the
<a href="https://huggingface.co/collections/google/gemma-4">Gemma 4</a>
release.</p>
<ul>
<li>who needs encoders? (<a
href="https://redirect.github.com/huggingface/transformers/issues/46385">#46385</a>)
by <a
href="https://github.com/douglas-reid"><code>@​douglas-reid</code></a>
<a href="https://github.com/sgerrard"><code>@​sgerrard</code></a> <a
href="https://github.com/vasqu"><code>@​vasqu</code></a> <a
href="https://github.com/molbap"><code>@​molbap</code></a></li>
</ul>
<h3>Sapiens2</h3>
<p>Sapiens2 is a family of high-resolution vision transformers
pretrained on ~1 billion curated human images, designed for
human-centric computer vision tasks including pose estimation, body-part
segmentation, surface normal estimation, and pointmap estimation. The
models scale from 0.4B to 5B parameters and train at native 1K
resolution, with hierarchical 4K variants for extended spatial
reasoning. Sapiens2 achieves substantial improvements over its
predecessor with +4 mAP in pose estimation, +24.3 mIoU in body-part
segmentation, and 45.6% error reduction in normal estimation.</p>
<p><strong>Links:</strong> <a
href="https://huggingface.co/docs/transformers/main/en/model_doc/sapiens2">Documentation</a>
| <a href="https://huggingface.co/papers/2604.21681">Paper</a></p>
<ul>
<li>Add Sapiens2 Model (<a
href="https://redirect.github.com/huggingface/transformers/issues/45919">#45919</a>)
by <a href="https://github.com/guarin"><code>@​guarin</code></a> in <a
href="https://redirect.github.com/huggingface/transformers/pull/45919">#45919</a></li>
</ul>
<h3>DeepSeek-OCR-2</h3>
<p>DeepSeek-OCR-2 is an OCR-specialized vision-language model built on a
distinctive architecture that combines a SAM ViT-B vision encoder with a
Qwen2 hybrid attention encoder, connected through an MLP projector to a
DeepSeek-V2 Mixture-of-Experts (MoE) language model. The model features
a hybrid attention mechanism that applies bidirectional attention over
image tokens and causal attention over query tokens, enabling efficient
and accurate document understanding. It supports both plain OCR tasks
and grounding capabilities with coordinate-aware output for document
conversion to markdown format.</p>
<p><strong>Links:</strong> <a
href="https://huggingface.co/docs/transformers/main/en/model_doc/deepseek_ocr2">Documentation</a></p>
<ul>
<li>Add Deepseek-OCR-2 model (<a
href="https://redirect.github.com/huggingface/transformers/issues/45075">#45075</a>)
by <a href="https://github.com/thisisiron"><code>@​thisisiron</code></a>
in <a
href="https://redirect.github.com/huggingface/transformers/pull/45075">#45075</a></li>
</ul>
<h3>Mellum</h3>
<p>Mellum is a code-focused Mixture-of-Experts language model developed
by JetBrains. It is derived from the Qwen3-MoE architecture with
per-layer-type RoPE and interleaved sliding window attention. The model
has 12B total parameters with 2.5B active parameters per token, using 64
routed experts with 8 activated per token across 28 layers.</p>
<p><strong>Links:</strong> <a
href="https://huggingface.co/docs/transformers/main/en/model_doc/mellum">Documentation</a></p>
<ul>
<li>feat: Add support for JetBrains' <code>Mellum</code> v2 code
generation model (<a
href="https://redirect.github.com/huggingface/transformers/issues/46112">#46112</a>)
by <a href="https://github.com/shadeMe"><code>@​shadeMe</code></a> in <a
href="https://redirect.github.com/huggingface/transformers/pull/46112">#46112</a></li>
</ul>
<h2>Breaking changes</h2>
<p>The Gemma4 vision pooler now casts inputs to float32 before scaling
to prevent float16 overflow (inf saturation) with large checkpoints,
which may cause minor numerical differences in outputs for users running
Gemma-4 vision models in float16.</p>
<ul>
<li>🚨 Fix float16 overflow in Gemma4 vision pooler (<a
href="https://redirect.github.com/huggingface/transformers/issues/46277">#46277</a>)
by <a
href="https://github.com/Bluear7878"><code>@​Bluear7878</code></a></li>
</ul>
<p>Audio Language Models (ALMs) now have a dedicated base model class
without a language modeling head, aligning them with the design of
Vision Language Models (VLMs); users relying on the previous model class
structure should update their code to use the new base model class where
appropriate.</p>
<ul>
<li>🚨 [ALM] Add base model without head (<a
href="https://redirect.github.com/huggingface/transformers/issues/45534">#45534</a>)
by <a href="https://github.com/eustlb"><code>@​eustlb</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/huggingface/transformers/commit/90c3ae54d448d4906b6167317ea5a7f5d48a232d"><code>90c3ae5</code></a>
Patch because we had to yank 5.10 because the release branch was not up
to date</li>
<li><a
href="https://github.com/huggingface/transformers/commit/0bd94b37db639d8f29a094dce2fde06f86af8968"><code>0bd94b3</code></a>
v5.10.0</li>
<li><a
href="https://github.com/huggingface/transformers/commit/1423d22f7a3b62e8c70ad67b58ec25cd9b675897"><code>1423d22</code></a>
who needs encoders? (<a
href="https://redirect.github.com/huggingface/transformers/issues/46385">#46385</a>)</li>
<li><a
href="https://github.com/huggingface/transformers/commit/50eb20a24f9dd512e6770072f422e4b86ca3cd98"><code>50eb20a</code></a>
Fix dsv4 dequant + tp/ep (<a
href="https://redirect.github.com/huggingface/transformers/issues/46378">#46378</a>)</li>
<li><a
href="https://github.com/huggingface/transformers/commit/74464e8c49c91b574c30cc3cb3c5a44000237299"><code>74464e8</code></a>
Fix wrong changes produced by style/repo. check bot (<a
href="https://redirect.github.com/huggingface/transformers/issues/46371">#46371</a>)</li>
<li><a
href="https://github.com/huggingface/transformers/commit/1b8ec344fb6c277235fc76c37e7a5c156a1f0ddc"><code>1b8ec34</code></a>
Fix path traversal when saving Bark voice preset embeddings (<a
href="https://redirect.github.com/huggingface/transformers/issues/46237">#46237</a>)</li>
<li><a
href="https://github.com/huggingface/transformers/commit/e820678256f22e7647e39e8b7ed040fa81b7b872"><code>e820678</code></a>
Add Sapiens2 Model (<a
href="https://redirect.github.com/huggingface/transformers/issues/45919">#45919</a>)</li>
<li><a
href="https://github.com/huggingface/transformers/commit/595721c44cb14db37fa504903e2edd5e9f0eba43"><code>595721c</code></a>
Pass library_name/version to Hub calls via a shared HfApi (<a
href="https://redirect.github.com/huggingface/transformers/issues/46318">#46318</a>)</li>
<li><a
href="https://github.com/huggingface/transformers/commit/0f0036c888ed81b714cb04aa6fe6689eb36bce0a"><code>0f0036c</code></a>
docs: update ACL Anthology URL in CITATION.cff (<a
href="https://redirect.github.com/huggingface/transformers/issues/46352">#46352</a>)</li>
<li><a
href="https://github.com/huggingface/transformers/commit/fa6c8308e22dade298c10c72d44937e41b962353"><code>fa6c830</code></a>
DeepGEMM BF16 + mixed FP8/FP4 + MegaMoE + refactor (<a
href="https://redirect.github.com/huggingface/transformers/issues/45634">#45634</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/huggingface/transformers/compare/v5.5.0...v5.10.1">compare
view</a></li>
</ul>
</details>
<br />

Made by [Open
SWE](https://openswe.vercel.app/agents/ac1ed59d-d5b3-5bef-b44a-3af86e5e14ab)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:24:16 -07:00
dependabot[bot] 5b9d7e9dbf chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/partners/huggingface (#40110)
[//]: # (dependabot-start)
⚠️  **Dependabot is rebasing this PR** ⚠️ 

Rebasing might not happen immediately, so don't worry if this takes some
time.

Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.

---

[//]: # (dependabot-end)

Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.7 to
6.5.8.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's
changelog</a>.</em></p>
<blockquote>
<h1>Release notes</h1>
<p>.. toctree::
:maxdepth: 2</p>
<p>releases/v6.5.8
releases/v6.5.7
releases/v6.5.6
releases/v6.5.5
releases/v6.5.4
releases/v6.5.3
releases/v6.5.2
releases/v6.5.1
releases/v6.5.0
releases/v6.4.2
releases/v6.4.1
releases/v6.4.0
releases/v6.3.3
releases/v6.3.2
releases/v6.3.1
releases/v6.3.0
releases/v6.2.0
releases/v6.1.0
releases/v6.0.4
releases/v6.0.3
releases/v6.0.2
releases/v6.0.1
releases/v6.0.0
releases/v5.1.1
releases/v5.1.0
releases/v5.0.2
releases/v5.0.1
releases/v5.0.0
releases/v4.5.3
releases/v4.5.2
releases/v4.5.1
releases/v4.5.0
releases/v4.4.3
releases/v4.4.2
releases/v4.4.1
releases/v4.4.0
releases/v4.3.0
releases/v4.2.1
releases/v4.2.0
releases/v4.1.0
releases/v4.0.2
releases/v4.0.1
releases/v4.0.0
releases/v3.2.2</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7"><code>a55abe3</code></a>
Merge pull request <a
href="https://redirect.github.com/tornadoweb/tornado/issues/3704">#3704</a>
from bdarnell/security-6.5.8</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c"><code>fc79488</code></a>
docs: add additional credit to release notes</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129"><code>7b01763</code></a>
Fix test_strip_headers_on_redirect's URL-embedded-credentials cases</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c"><code>d72fff8</code></a>
release notes and version bump for 6.5.8</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e"><code>b168818</code></a>
auth: Formally deprecated OpenIDMixin</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7"><code>da28476</code></a>
web: Also check for semicolons in deprecated mixed-case cookie args</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de"><code>8d6363e</code></a>
httputil: Enforce a new limit on the number of arguments in a
request</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05"><code>de85b3f</code></a>
httputil: Apply multipart max_parts limit earlier</li>
<li>See full diff in <a
href="https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=tornado&package-manager=uv&previous-version=6.5.7&new-version=6.5.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 08:09:07 +00:00
dependabot[bot] ef548a8435 chore(deps): bump the major group across 2 directories with 1 update (#40086)
Bumps the major group with 1 update in the /libs/model-profiles
directory: [syrupy](https://github.com/syrupy-project/syrupy).
Bumps the major group with 1 update in the /libs/standard-tests
directory: [syrupy](https://github.com/syrupy-project/syrupy).

Updates `syrupy` from 5.5.3 to 6.0.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/syrupy-project/syrupy/releases">syrupy's
releases</a>.</em></p>
<blockquote>
<h2>v6.0.0</h2>
<h1>Syrupy 6.0.0</h1>
<p><em>(2026-08-22)</em></p>
<p>Syrupy 6 focuses on better built-in serialization, clearer snapshot
workflows, and large-suite performance. Please review the
<strong>breaking changes</strong> before upgrading.</p>
<p>Most suites should not need significant snapshot updates on upgrade —
the main exception is <strong>dataclass</strong> usage (see below).
Syrupy v6 does <strong>not</strong> change the required Python version
or other package dependencies. Support for Python 3.10 will instead be
dropped in the next Syrupy major version (v7).</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0">https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0</a></p>
<hr />
<h2>Breaking Changes</h2>
<h3>Built-in dataclass serialization (removed
<code>DataclassPlugin</code>)</h3>
<p>stdlib dataclasses are now serialized natively by the Amber
serializer. The separate <code>DataclassPlugin</code> has been
<strong>removed</strong>.</p>
<ul>
<li><strong>If you used <code>DataclassPlugin</code>:</strong> remove
imports and plugin wiring. Behavior should match what the plugin
produced; no snapshot rewrite should be needed for the dataclass shape
itself.</li>
<li><strong>If you did <em>not</em> use the plugin:</strong> dataclass
snapshots may change from a <code>repr</code>-style string to structured
Amber form (field-by-field). Re-run with <code>--snapshot-update</code>
where those assertions fail.</li>
</ul>
<p>Example of what to remove:</p>
<pre lang="python"><code># Before (v5)
from syrupy.extensions.amber.dataclasses_plugin import DataclassPlugin
<p>class MySerializer(AmberDataSerializer):
serializer_plugins = [DataclassPlugin, ...]
</code></pre></p>
<pre lang="python"><code># After (v6) — dataclasses work with the
default Amber extension
assert MyDataclass(...) == snapshot
</code></pre>
<p>Attrs and Pydantic models are unchanged and still need their
serializer plugins. See the <a
href="https://github.com/syrupy-project/syrupy/blob/main/tests/syrupy/extensions/amber/test_amber_serializer_plugins.py">serializer
plugins example</a>.</p>
<p>(<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1220">#1220</a>,
closes <a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1048">#1048</a>)</p>
<h3>JSON <code>datetime.date</code> snapshots</h3>
<p>The JSON extension now serializes <code>datetime.date</code> as
<code>YYYY-MM-DD</code> instead of a <code>repr</code> string. Existing
JSON snapshots that contain dates will need an update.</p>
<p>(<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1216">#1216</a>,
closes <a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1058">#1058</a>)</p>
<h3><code>path_value</code> nested path replacement in default (literal)
mode</h3>
<p><code>path_value(..., regex=False)</code> now correctly replaces
values at nested paths such as <code>user.token</code>. Previously, the
default-mode lookup missed escaped path keys, so nested values were left
unchanged (and could leak into committed snapshots).</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/syrupy-project/syrupy/blob/main/CHANGELOG.md">syrupy's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v6.0.0">v6.0.0</a>
(2026-08-22)</h2>
<h2>What's Changed</h2>
<ul>
<li>chore(deps): bump pygments from 2.19.2 to 2.20.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1151">syrupy-project/syrupy#1151</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.5 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1152">syrupy-project/syrupy#1152</a></li>
<li>chore(deps): update dependency ruff to v0.15.21 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1153">syrupy-project/syrupy#1153</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.6 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1154">syrupy-project/syrupy#1154</a></li>
<li>chore(deps): update dependency coverage to v7.15.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1157">syrupy-project/syrupy#1157</a></li>
<li>chore(deps): update dependency mypy to v2.3.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1158">syrupy-project/syrupy#1158</a></li>
<li>fix: make set/dict serialization deterministic for partial-order
elements by <a
href="https://github.com/chuenchen309"><code>@​chuenchen309</code></a>
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1159">syrupy-project/syrupy#1159</a></li>
<li>docs: add chuenchen309 as a contributor for bug by <a
href="https://github.com/allcontributors"><code>@​allcontributors</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1160">syrupy-project/syrupy#1160</a></li>
<li>chore(deps): update dependency coverage to v7.15.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1163">syrupy-project/syrupy#1163</a></li>
<li>chore(deps): update dependency ruff to v0.15.22 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1164">syrupy-project/syrupy#1164</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.7 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1165">syrupy-project/syrupy#1165</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.9 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1166">syrupy-project/syrupy#1166</a></li>
<li>chore(deps): update dependency hypothesis to v6.157.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1167">syrupy-project/syrupy#1167</a></li>
<li>fix(matchers): replace values at nested paths in path_value default
mode by <a
href="https://github.com/chuenchen309"><code>@​chuenchen309</code></a>
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1162">syrupy-project/syrupy#1162</a></li>
<li>fix: preserve skipped single-file snapshots by <a
href="https://github.com/KSmanis"><code>@​KSmanis</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1161">syrupy-project/syrupy#1161</a></li>
<li>docs: add KSmanis as a contributor for bug by <a
href="https://github.com/allcontributors"><code>@​allcontributors</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1168">syrupy-project/syrupy#1168</a></li>
<li>chore(deps): update pypa/gh-action-pypi-publish action to v1.14.1 by
<a href="https://github.com/renovate"><code>@​renovate</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1169">syrupy-project/syrupy#1169</a></li>
<li>chore(deps): update dependency hypothesis to v6.157.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1171">syrupy-project/syrupy#1171</a></li>
<li>chore(deps): update actions/checkout action to v7.0.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1170">syrupy-project/syrupy#1170</a></li>
<li>chore(deps): update dependency hypothesis to v6.158.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1172">syrupy-project/syrupy#1172</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v9 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1174">syrupy-project/syrupy#1174</a></li>
<li>chore(deps): update dependency hypothesis to v6.158.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1173">syrupy-project/syrupy#1173</a></li>
<li>chore(deps): update dependency hypothesis to v6.160.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1176">syrupy-project/syrupy#1176</a></li>
<li>feat: support in-memory snapshot diff data by <a
href="https://github.com/yangfan-yf-yf"><code>@​yangfan-yf-yf</code></a>
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1175">syrupy-project/syrupy#1175</a></li>
<li>docs: add yangfan-yf-yf as a contributor for code by <a
href="https://github.com/allcontributors"><code>@​allcontributors</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1178">syrupy-project/syrupy#1178</a></li>
<li>chore(deps): update dependency hypothesis to v6.161.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1177">syrupy-project/syrupy#1177</a></li>
<li>chore(deps): update dependency hypothesis to v6.161.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1180">syrupy-project/syrupy#1180</a></li>
<li>chore(deps): update dependency hypothesis to v6.161.4 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1182">syrupy-project/syrupy#1182</a></li>
<li>chore(deps): update dependency hypothesis to v6.161.6 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1183">syrupy-project/syrupy#1183</a></li>
<li>chore(deps): update dependency ruff to &gt;=0.16,&lt;0.17 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1179">syrupy-project/syrupy#1179</a></li>
<li>chore(deps): update dependency hypothesis to v6.161.7 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1184">syrupy-project/syrupy#1184</a></li>
<li>chore(deps): update pypa/gh-action-pypi-publish action to v1.14.2 by
<a href="https://github.com/renovate"><code>@​renovate</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1186">syrupy-project/syrupy#1186</a></li>
<li>perf: compress xdist snapshot reports by <a
href="https://github.com/w3lld1"><code>@​w3lld1</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1188">syrupy-project/syrupy#1188</a></li>
<li>docs: add w3lld1 as a contributor for code by <a
href="https://github.com/allcontributors"><code>@​allcontributors</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1190">syrupy-project/syrupy#1190</a></li>
<li>chore(deps): update dependency ruff to v0.16.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1189">syrupy-project/syrupy#1189</a></li>
<li>chore(deps): update dependency hypothesis to v6.164.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1187">syrupy-project/syrupy#1187</a></li>
<li>chore(deps): update dependency hypothesis to v6.165.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1191">syrupy-project/syrupy#1191</a></li>
<li>chore(deps): update dependency coverage to v7.15.3 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1192">syrupy-project/syrupy#1192</a></li>
<li>chore(deps): update python docker tag to v3.14.7 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1195">syrupy-project/syrupy#1195</a></li>
<li>chore(deps): update dependency coverage to v7.15.4 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1197">syrupy-project/syrupy#1197</a></li>
<li>chore(deps): update dependency hypothesis to v6.165.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1194">syrupy-project/syrupy#1194</a></li>
<li>chore(deps): update dependency ruff to v0.16.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1198">syrupy-project/syrupy#1198</a></li>
<li>chore(deps): update dependency hypothesis to v6.165.3 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1199">syrupy-project/syrupy#1199</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v10 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1200">syrupy-project/syrupy#1200</a></li>
<li>chore(deps): update dependency hypothesis to v6.165.5 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1201">syrupy-project/syrupy#1201</a></li>
<li>chore(deps): update dependency ruff to v0.16.3 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1202">syrupy-project/syrupy#1202</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v10.0.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1205">syrupy-project/syrupy#1205</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/621af75dd8dfa3301b503099b204a3d874e787d7"><code>621af75</code></a>
chore(release): 6.0.0 [skip ci]</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/3a9f69182366401c372dd0a1690177e70e994fec"><code>3a9f691</code></a>
fix: single file snapshot no longer buffers in memory (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1223">#1223</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/ab13f8d4a9eeba10572a6a12f485f79a6e0a1b23"><code>ab13f8d</code></a>
chore: sponsorship (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1224">#1224</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/98f989c42a7c1c9cf49e031e9b97374bf97a6b6d"><code>98f989c</code></a>
feat: add --snapshot-declaration-order for respecting declaration order
(<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1222">#1222</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/b549b4b6329cca03f871162748b3ea8597add1a3"><code>b549b4b</code></a>
feat: built-in support for Dataclasses (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1220">#1220</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/d34933fce2d8eb65c24a89f29f5900b413775b5e"><code>d34933f</code></a>
chore: use the benchmarks git branch (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1221">#1221</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/f6eda020d8671fc1648c0d94ed436805d5548978"><code>f6eda02</code></a>
chore(ci): permissions for gh-pages</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/a5ce0492e68525f499f5cb395e273d3ac5a1f8e3"><code>a5ce049</code></a>
chore(deps): update actions/configure-pages action to v6 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1219">#1219</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/c0cb162f5fbaca6eeda43937152db314e0313c82"><code>c0cb162</code></a>
chore: update github pages</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/4d59bde91c87f6a2fb3b476ea995246a43449bc2"><code>4d59bde</code></a>
chore: update docs for v6 release (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1218">#1218</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `syrupy` from 5.5.3 to 6.0.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/syrupy-project/syrupy/releases">syrupy's
releases</a>.</em></p>
<blockquote>
<h2>v6.0.0</h2>
<h1>Syrupy 6.0.0</h1>
<p><em>(2026-08-22)</em></p>
<p>Syrupy 6 focuses on better built-in serialization, clearer snapshot
workflows, and large-suite performance. Please review the
<strong>breaking changes</strong> before upgrading.</p>
<p>Most suites should not need significant snapshot updates on upgrade —
the main exception is <strong>dataclass</strong> usage (see below).
Syrupy v6 does <strong>not</strong> change the required Python version
or other package dependencies. Support for Python 3.10 will instead be
dropped in the next Syrupy major version (v7).</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0">https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0</a></p>
<hr />
<h2>Breaking Changes</h2>
<h3>Built-in dataclass serialization (removed
<code>DataclassPlugin</code>)</h3>
<p>stdlib dataclasses are now serialized natively by the Amber
serializer. The separate <code>DataclassPlugin</code> has been
<strong>removed</strong>.</p>
<ul>
<li><strong>If you used <code>DataclassPlugin</code>:</strong> remove
imports and plugin wiring. Behavior should match what the plugin
produced; no snapshot rewrite should be needed for the dataclass shape
itself.</li>
<li><strong>If you did <em>not</em> use the plugin:</strong> dataclass
snapshots may change from a <code>repr</code>-style string to structured
Amber form (field-by-field). Re-run with <code>--snapshot-update</code>
where those assertions fail.</li>
</ul>
<p>Example of what to remove:</p>
<pre lang="python"><code># Before (v5)
from syrupy.extensions.amber.dataclasses_plugin import DataclassPlugin
<p>class MySerializer(AmberDataSerializer):
serializer_plugins = [DataclassPlugin, ...]
</code></pre></p>
<pre lang="python"><code># After (v6) — dataclasses work with the
default Amber extension
assert MyDataclass(...) == snapshot
</code></pre>
<p>Attrs and Pydantic models are unchanged and still need their
serializer plugins. See the <a
href="https://github.com/syrupy-project/syrupy/blob/main/tests/syrupy/extensions/amber/test_amber_serializer_plugins.py">serializer
plugins example</a>.</p>
<p>(<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1220">#1220</a>,
closes <a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1048">#1048</a>)</p>
<h3>JSON <code>datetime.date</code> snapshots</h3>
<p>The JSON extension now serializes <code>datetime.date</code> as
<code>YYYY-MM-DD</code> instead of a <code>repr</code> string. Existing
JSON snapshots that contain dates will need an update.</p>
<p>(<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1216">#1216</a>,
closes <a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1058">#1058</a>)</p>
<h3><code>path_value</code> nested path replacement in default (literal)
mode</h3>
<p><code>path_value(..., regex=False)</code> now correctly replaces
values at nested paths such as <code>user.token</code>. Previously, the
default-mode lookup missed escaped path keys, so nested values were left
unchanged (and could leak into committed snapshots).</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/syrupy-project/syrupy/blob/main/CHANGELOG.md">syrupy's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/syrupy-project/syrupy/releases/tag/v6.0.0">v6.0.0</a>
(2026-08-22)</h2>
<h2>What's Changed</h2>
<ul>
<li>chore(deps): bump pygments from 2.19.2 to 2.20.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1151">syrupy-project/syrupy#1151</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.5 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1152">syrupy-project/syrupy#1152</a></li>
<li>chore(deps): update dependency ruff to v0.15.21 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1153">syrupy-project/syrupy#1153</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.6 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1154">syrupy-project/syrupy#1154</a></li>
<li>chore(deps): update dependency coverage to v7.15.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1157">syrupy-project/syrupy#1157</a></li>
<li>chore(deps): update dependency mypy to v2.3.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1158">syrupy-project/syrupy#1158</a></li>
<li>fix: make set/dict serialization deterministic for partial-order
elements by <a
href="https://github.com/chuenchen309"><code>@​chuenchen309</code></a>
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1159">syrupy-project/syrupy#1159</a></li>
<li>docs: add chuenchen309 as a contributor for bug by <a
href="https://github.com/allcontributors"><code>@​allcontributors</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1160">syrupy-project/syrupy#1160</a></li>
<li>chore(deps): update dependency coverage to v7.15.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1163">syrupy-project/syrupy#1163</a></li>
<li>chore(deps): update dependency ruff to v0.15.22 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1164">syrupy-project/syrupy#1164</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.7 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1165">syrupy-project/syrupy#1165</a></li>
<li>chore(deps): update dependency hypothesis to v6.156.9 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1166">syrupy-project/syrupy#1166</a></li>
<li>chore(deps): update dependency hypothesis to v6.157.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1167">syrupy-project/syrupy#1167</a></li>
<li>fix(matchers): replace values at nested paths in path_value default
mode by <a
href="https://github.com/chuenchen309"><code>@​chuenchen309</code></a>
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1162">syrupy-project/syrupy#1162</a></li>
<li>fix: preserve skipped single-file snapshots by <a
href="https://github.com/KSmanis"><code>@​KSmanis</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1161">syrupy-project/syrupy#1161</a></li>
<li>docs: add KSmanis as a contributor for bug by <a
href="https://github.com/allcontributors"><code>@​allcontributors</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1168">syrupy-project/syrupy#1168</a></li>
<li>chore(deps): update pypa/gh-action-pypi-publish action to v1.14.1 by
<a href="https://github.com/renovate"><code>@​renovate</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1169">syrupy-project/syrupy#1169</a></li>
<li>chore(deps): update dependency hypothesis to v6.157.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1171">syrupy-project/syrupy#1171</a></li>
<li>chore(deps): update actions/checkout action to v7.0.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1170">syrupy-project/syrupy#1170</a></li>
<li>chore(deps): update dependency hypothesis to v6.158.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1172">syrupy-project/syrupy#1172</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v9 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1174">syrupy-project/syrupy#1174</a></li>
<li>chore(deps): update dependency hypothesis to v6.158.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1173">syrupy-project/syrupy#1173</a></li>
<li>chore(deps): update dependency hypothesis to v6.160.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1176">syrupy-project/syrupy#1176</a></li>
<li>feat: support in-memory snapshot diff data by <a
href="https://github.com/yangfan-yf-yf"><code>@​yangfan-yf-yf</code></a>
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1175">syrupy-project/syrupy#1175</a></li>
<li>docs: add yangfan-yf-yf as a contributor for code by <a
href="https://github.com/allcontributors"><code>@​allcontributors</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1178">syrupy-project/syrupy#1178</a></li>
<li>chore(deps): update dependency hypothesis to v6.161.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1177">syrupy-project/syrupy#1177</a></li>
<li>chore(deps): update dependency hypothesis to v6.161.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1180">syrupy-project/syrupy#1180</a></li>
<li>chore(deps): update dependency hypothesis to v6.161.4 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1182">syrupy-project/syrupy#1182</a></li>
<li>chore(deps): update dependency hypothesis to v6.161.6 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1183">syrupy-project/syrupy#1183</a></li>
<li>chore(deps): update dependency ruff to &gt;=0.16,&lt;0.17 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1179">syrupy-project/syrupy#1179</a></li>
<li>chore(deps): update dependency hypothesis to v6.161.7 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1184">syrupy-project/syrupy#1184</a></li>
<li>chore(deps): update pypa/gh-action-pypi-publish action to v1.14.2 by
<a href="https://github.com/renovate"><code>@​renovate</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1186">syrupy-project/syrupy#1186</a></li>
<li>perf: compress xdist snapshot reports by <a
href="https://github.com/w3lld1"><code>@​w3lld1</code></a> in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1188">syrupy-project/syrupy#1188</a></li>
<li>docs: add w3lld1 as a contributor for code by <a
href="https://github.com/allcontributors"><code>@​allcontributors</code></a>[bot]
in <a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1190">syrupy-project/syrupy#1190</a></li>
<li>chore(deps): update dependency ruff to v0.16.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1189">syrupy-project/syrupy#1189</a></li>
<li>chore(deps): update dependency hypothesis to v6.164.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1187">syrupy-project/syrupy#1187</a></li>
<li>chore(deps): update dependency hypothesis to v6.165.0 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1191">syrupy-project/syrupy#1191</a></li>
<li>chore(deps): update dependency coverage to v7.15.3 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1192">syrupy-project/syrupy#1192</a></li>
<li>chore(deps): update python docker tag to v3.14.7 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1195">syrupy-project/syrupy#1195</a></li>
<li>chore(deps): update dependency coverage to v7.15.4 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1197">syrupy-project/syrupy#1197</a></li>
<li>chore(deps): update dependency hypothesis to v6.165.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1194">syrupy-project/syrupy#1194</a></li>
<li>chore(deps): update dependency ruff to v0.16.2 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1198">syrupy-project/syrupy#1198</a></li>
<li>chore(deps): update dependency hypothesis to v6.165.3 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1199">syrupy-project/syrupy#1199</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v10 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1200">syrupy-project/syrupy#1200</a></li>
<li>chore(deps): update dependency hypothesis to v6.165.5 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1201">syrupy-project/syrupy#1201</a></li>
<li>chore(deps): update dependency ruff to v0.16.3 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1202">syrupy-project/syrupy#1202</a></li>
<li>chore(deps): update astral-sh/setup-uv action to v10.0.1 by <a
href="https://github.com/renovate"><code>@​renovate</code></a>[bot] in
<a
href="https://redirect.github.com/syrupy-project/syrupy/pull/1205">syrupy-project/syrupy#1205</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/621af75dd8dfa3301b503099b204a3d874e787d7"><code>621af75</code></a>
chore(release): 6.0.0 [skip ci]</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/3a9f69182366401c372dd0a1690177e70e994fec"><code>3a9f691</code></a>
fix: single file snapshot no longer buffers in memory (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1223">#1223</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/ab13f8d4a9eeba10572a6a12f485f79a6e0a1b23"><code>ab13f8d</code></a>
chore: sponsorship (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1224">#1224</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/98f989c42a7c1c9cf49e031e9b97374bf97a6b6d"><code>98f989c</code></a>
feat: add --snapshot-declaration-order for respecting declaration order
(<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1222">#1222</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/b549b4b6329cca03f871162748b3ea8597add1a3"><code>b549b4b</code></a>
feat: built-in support for Dataclasses (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1220">#1220</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/d34933fce2d8eb65c24a89f29f5900b413775b5e"><code>d34933f</code></a>
chore: use the benchmarks git branch (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1221">#1221</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/f6eda020d8671fc1648c0d94ed436805d5548978"><code>f6eda02</code></a>
chore(ci): permissions for gh-pages</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/a5ce0492e68525f499f5cb395e273d3ac5a1f8e3"><code>a5ce049</code></a>
chore(deps): update actions/configure-pages action to v6 (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1219">#1219</a>)</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/c0cb162f5fbaca6eeda43937152db314e0313c82"><code>c0cb162</code></a>
chore: update github pages</li>
<li><a
href="https://github.com/syrupy-project/syrupy/commit/4d59bde91c87f6a2fb3b476ea995246a43449bc2"><code>4d59bde</code></a>
chore: update docs for v6 release (<a
href="https://redirect.github.com/syrupy-project/syrupy/issues/1218">#1218</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/syrupy-project/syrupy/compare/v5.5.3...v6.0.0">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:07:05 -07:00
dependabot[bot] 4662366268 chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (#40113)
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.7 to
6.5.8.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's
changelog</a>.</em></p>
<blockquote>
<h1>Release notes</h1>
<p>.. toctree::
:maxdepth: 2</p>
<p>releases/v6.5.8
releases/v6.5.7
releases/v6.5.6
releases/v6.5.5
releases/v6.5.4
releases/v6.5.3
releases/v6.5.2
releases/v6.5.1
releases/v6.5.0
releases/v6.4.2
releases/v6.4.1
releases/v6.4.0
releases/v6.3.3
releases/v6.3.2
releases/v6.3.1
releases/v6.3.0
releases/v6.2.0
releases/v6.1.0
releases/v6.0.4
releases/v6.0.3
releases/v6.0.2
releases/v6.0.1
releases/v6.0.0
releases/v5.1.1
releases/v5.1.0
releases/v5.0.2
releases/v5.0.1
releases/v5.0.0
releases/v4.5.3
releases/v4.5.2
releases/v4.5.1
releases/v4.5.0
releases/v4.4.3
releases/v4.4.2
releases/v4.4.1
releases/v4.4.0
releases/v4.3.0
releases/v4.2.1
releases/v4.2.0
releases/v4.1.0
releases/v4.0.2
releases/v4.0.1
releases/v4.0.0
releases/v3.2.2</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7"><code>a55abe3</code></a>
Merge pull request <a
href="https://redirect.github.com/tornadoweb/tornado/issues/3704">#3704</a>
from bdarnell/security-6.5.8</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c"><code>fc79488</code></a>
docs: add additional credit to release notes</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129"><code>7b01763</code></a>
Fix test_strip_headers_on_redirect's URL-embedded-credentials cases</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c"><code>d72fff8</code></a>
release notes and version bump for 6.5.8</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e"><code>b168818</code></a>
auth: Formally deprecated OpenIDMixin</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7"><code>da28476</code></a>
web: Also check for semicolons in deprecated mixed-case cookie args</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de"><code>8d6363e</code></a>
httputil: Enforce a new limit on the number of arguments in a
request</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05"><code>de85b3f</code></a>
httputil: Apply multipart max_parts limit earlier</li>
<li>See full diff in <a
href="https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=tornado&package-manager=uv&previous-version=6.5.7&new-version=6.5.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:05:43 -07:00
dependabot[bot] 673b9c5981 chore(deps): update lxml requirement from <7.0,>=6.1.0 to >=6.1.2,<7.0 in /libs/text-splitters (#40087)
Updates the requirements on [lxml](https://github.com/lxml/lxml) to
permit the latest version.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/lxml/lxml/blob/master/CHANGES.txt">lxml's
changelog</a>.</em></p>
<blockquote>
<h1>6.1.2 (2026-08-18)</h1>
<ul>
<li>
<p>GH#526: Some build files were missing in the sdist.
Patch by Nicola Soranzo.</p>
</li>
<li>
<p>Some minor corrections for error handling cases.</p>
</li>
</ul>
<h2>Other changes</h2>
<ul>
<li>Built with Cython 3.2.9.</li>
</ul>
<h1>6.1.1 (2026-05-18)</h1>
<h2>Bugs fixed</h2>
<ul>
<li>
<p>The known link attributes in <code>lxml.html.defs.link_attrs</code>
were missing <code>xlink:href</code>,
which can be used for URL bypass attacks in embedded SVG/MathML/etc.
content.
<a
href="https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f">https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f</a></p>
</li>
<li>
<p>The Linux wheels use a patched libxslt 1.1.43, fixing CVE-2025-7424
and CVE-2025-11731.</p>
</li>
<li>
<p>The Windows wheels use libxslt 1.1.45, fixing CVE-2025-7424 and
CVE-2025-11731.</p>
</li>
</ul>
<h1>6.1.0 (2026-04-17)</h1>
<p>This release fixes a possible external entity injection (XXE)
vulnerability in
<code>iterparse()</code> and the <code>ETCompatXMLParser</code>.</p>
<h2>Features added</h2>
<ul>
<li>
<p>GH#486: The HTML ARIA accessibility attributes were added to the set
of safe attributes
in <code>lxml.html.defs</code>. This allows <code>lxml_html_clean</code>
to pass them through.
Patch by oomsveta.</p>
</li>
<li>
<p>The default chunk size for reading from file-likes in
<code>iterparse()</code> is now configurable
with a new <code>chunk_size</code> argument.</p>
</li>
</ul>
<h2>Bugs fixed</h2>
<ul>
<li>LP#2146291: The <code>resolve_entities</code> option was still set
to <code>True</code> for
<code>iterparse</code> and <code>ETCompatXMLParser</code>, allowing for
external entity injection (XXE)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lxml/lxml/commit/f2874e9008c83d2d26e0b7292772eb74d2b83ce3"><code>f2874e9</code></a>
Update release date.</li>
<li><a
href="https://github.com/lxml/lxml/commit/687a295a4c19288b95ec1b74c31a620acaabdf9d"><code>687a295</code></a>
Build: Exclude Py3.8 from windows-arm builds.</li>
<li><a
href="https://github.com/lxml/lxml/commit/acadc56553ff74e6ea296158e118b08ac6ec9f4b"><code>acadc56</code></a>
Build: Remove outdated build target.</li>
<li><a
href="https://github.com/lxml/lxml/commit/59f93eb420a988bc61e7c5b8f4d97869c0536be7"><code>59f93eb</code></a>
Build: Split old-Linux and other-Py3.8 builds.</li>
<li><a
href="https://github.com/lxml/lxml/commit/923df83ed6a40ca5aab267b1c3fe073ff13a00ab"><code>923df83</code></a>
Build: Fix manylinux2014 build.</li>
<li><a
href="https://github.com/lxml/lxml/commit/975cc83e4626117e36adb6d336ac9a6f6cc0ca42"><code>975cc83</code></a>
Build: Fix Px3.8 build setup.</li>
<li><a
href="https://github.com/lxml/lxml/commit/09e5d3e968f380d7a790c2b47f59f7937e00942e"><code>09e5d3e</code></a>
Build: Fix cibuildwheel version.</li>
<li><a
href="https://github.com/lxml/lxml/commit/998cf504a3b0da7f316861c5a552c5c16069d91f"><code>998cf50</code></a>
Build: Build Py3.8 wheels only once, not in every build job.</li>
<li><a
href="https://github.com/lxml/lxml/commit/55670370cd68117ff2b3b71e0f20a7f275d1baeb"><code>5567037</code></a>
Build: Exclude Py3.15 from 32bit builds.</li>
<li><a
href="https://github.com/lxml/lxml/commit/904db40b04ef590ae1ca8fc84be863fc0f8196dc"><code>904db40</code></a>
Build: Update cibuildwheel to include Py3.15.</li>
<li>Additional commits viewable in <a
href="https://github.com/lxml/lxml/compare/lxml-6.1.0...lxml-6.1.2">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:04:45 -07:00
dependabot[bot] 0cac488d0b chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/langchain (#40111)
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.7 to
6.5.8.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's
changelog</a>.</em></p>
<blockquote>
<h1>Release notes</h1>
<p>.. toctree::
:maxdepth: 2</p>
<p>releases/v6.5.8
releases/v6.5.7
releases/v6.5.6
releases/v6.5.5
releases/v6.5.4
releases/v6.5.3
releases/v6.5.2
releases/v6.5.1
releases/v6.5.0
releases/v6.4.2
releases/v6.4.1
releases/v6.4.0
releases/v6.3.3
releases/v6.3.2
releases/v6.3.1
releases/v6.3.0
releases/v6.2.0
releases/v6.1.0
releases/v6.0.4
releases/v6.0.3
releases/v6.0.2
releases/v6.0.1
releases/v6.0.0
releases/v5.1.1
releases/v5.1.0
releases/v5.0.2
releases/v5.0.1
releases/v5.0.0
releases/v4.5.3
releases/v4.5.2
releases/v4.5.1
releases/v4.5.0
releases/v4.4.3
releases/v4.4.2
releases/v4.4.1
releases/v4.4.0
releases/v4.3.0
releases/v4.2.1
releases/v4.2.0
releases/v4.1.0
releases/v4.0.2
releases/v4.0.1
releases/v4.0.0
releases/v3.2.2</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7"><code>a55abe3</code></a>
Merge pull request <a
href="https://redirect.github.com/tornadoweb/tornado/issues/3704">#3704</a>
from bdarnell/security-6.5.8</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c"><code>fc79488</code></a>
docs: add additional credit to release notes</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129"><code>7b01763</code></a>
Fix test_strip_headers_on_redirect's URL-embedded-credentials cases</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c"><code>d72fff8</code></a>
release notes and version bump for 6.5.8</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e"><code>b168818</code></a>
auth: Formally deprecated OpenIDMixin</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7"><code>da28476</code></a>
web: Also check for semicolons in deprecated mixed-case cookie args</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de"><code>8d6363e</code></a>
httputil: Enforce a new limit on the number of arguments in a
request</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05"><code>de85b3f</code></a>
httputil: Apply multipart max_parts limit earlier</li>
<li>See full diff in <a
href="https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=tornado&package-manager=uv&previous-version=6.5.7&new-version=6.5.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:04:36 -07:00
dependabot[bot] 1490686e09 chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/text-splitters (#40112)
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.7 to
6.5.8.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst">tornado's
changelog</a>.</em></p>
<blockquote>
<h1>Release notes</h1>
<p>.. toctree::
:maxdepth: 2</p>
<p>releases/v6.5.8
releases/v6.5.7
releases/v6.5.6
releases/v6.5.5
releases/v6.5.4
releases/v6.5.3
releases/v6.5.2
releases/v6.5.1
releases/v6.5.0
releases/v6.4.2
releases/v6.4.1
releases/v6.4.0
releases/v6.3.3
releases/v6.3.2
releases/v6.3.1
releases/v6.3.0
releases/v6.2.0
releases/v6.1.0
releases/v6.0.4
releases/v6.0.3
releases/v6.0.2
releases/v6.0.1
releases/v6.0.0
releases/v5.1.1
releases/v5.1.0
releases/v5.0.2
releases/v5.0.1
releases/v5.0.0
releases/v4.5.3
releases/v4.5.2
releases/v4.5.1
releases/v4.5.0
releases/v4.4.3
releases/v4.4.2
releases/v4.4.1
releases/v4.4.0
releases/v4.3.0
releases/v4.2.1
releases/v4.2.0
releases/v4.1.0
releases/v4.0.2
releases/v4.0.1
releases/v4.0.0
releases/v3.2.2</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7"><code>a55abe3</code></a>
Merge pull request <a
href="https://redirect.github.com/tornadoweb/tornado/issues/3704">#3704</a>
from bdarnell/security-6.5.8</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c"><code>fc79488</code></a>
docs: add additional credit to release notes</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129"><code>7b01763</code></a>
Fix test_strip_headers_on_redirect's URL-embedded-credentials cases</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c"><code>d72fff8</code></a>
release notes and version bump for 6.5.8</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e"><code>b168818</code></a>
auth: Formally deprecated OpenIDMixin</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7"><code>da28476</code></a>
web: Also check for semicolons in deprecated mixed-case cookie args</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de"><code>8d6363e</code></a>
httputil: Enforce a new limit on the number of arguments in a
request</li>
<li><a
href="https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05"><code>de85b3f</code></a>
httputil: Apply multipart max_parts limit earlier</li>
<li>See full diff in <a
href="https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=tornado&package-manager=uv&previous-version=6.5.7&new-version=6.5.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:04:33 -07:00
dependabot[bot] 07b2085c8a chore(deps): bump orjson from 3.11.6 to 3.12.0 in /libs/partners/huggingface (#40115)
[//]: # (dependabot-start)
⚠️  **Dependabot is rebasing this PR** ⚠️ 

Rebasing might not happen immediately, so don't worry if this takes some
time.

Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.

---

[//]: # (dependabot-end)

Bumps [orjson](https://github.com/ijl/orjson) from 3.11.6 to 3.12.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ijl/orjson/releases">orjson's
releases</a>.</em></p>
<blockquote>
<h2>3.12.0</h2>
<h3>Changed</h3>
<ul>
<li>Serialization implementation substantially rewritten.</li>
<li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later,
<code>manylinux_2_39</code> (2024) is targeted instead of
<code>manylinux_2_17</code> (2012).</li>
<li>No longer publish PyPI wheels for ppc64le and s390x.</li>
</ul>
<h2>3.11.9</h2>
<h3>Changed</h3>
<ul>
<li>Build now depends on Rust 1.95 or later instead of 1.89.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fix building on Rust 1.95.</li>
</ul>
<h2>3.11.8</h2>
<h3>Changed</h3>
<ul>
<li>Build and compatibility improvements.</li>
</ul>
<h2>3.11.7</h2>
<h3>Changed</h3>
<ul>
<li>Use a faster library to serialize <code>float</code>. Users with
byte-exact regression
tests should note positive exponents are now written using a
<code>+</code>, e.g.,
<code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are
spec-compliant.</li>
<li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/ijl/orjson/blob/master/CHANGELOG.md">orjson's
changelog</a>.</em></p>
<blockquote>
<h2>3.12.0 - 2026-08-14</h2>
<h3>Changed</h3>
<ul>
<li>Serialization implementation substantially rewritten.</li>
<li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later,
<code>manylinux_2_39</code> (2024) is targeted instead of
<code>manylinux_2_17</code> (2012).</li>
<li>No longer publish PyPI wheels for ppc64le and s390x.</li>
</ul>
<h2>3.11.9 - 2026-05-06</h2>
<h3>Changed</h3>
<ul>
<li>Build now depends on Rust 1.95 or later instead of 1.89.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fix building on Rust 1.95.</li>
</ul>
<h2>3.11.8 - 2026-03-31</h2>
<h3>Changed</h3>
<ul>
<li>Build and compatibility improvements.</li>
</ul>
<h2>3.11.7 - 2026-02-02</h2>
<h3>Changed</h3>
<ul>
<li>Use a faster library to serialize <code>float</code>. Users with
byte-exact regression
tests should note positive exponents are now written using a
<code>+</code>, e.g.,
<code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are
spec-compliant.</li>
<li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ijl/orjson/commit/6737895a1a4e3e26df0569a40147893a786f9a58"><code>6737895</code></a>
3.12.0</li>
<li><a
href="https://github.com/ijl/orjson/commit/c2a6e8ff7b898635fb68a85bd5a62df1edf61cfc"><code>c2a6e8f</code></a>
JsonWriter, iterators</li>
<li><a
href="https://github.com/ijl/orjson/commit/6a2d7a7d66dc3c5698625a7b334c40db459e46ae"><code>6a2d7a7</code></a>
yyjson 1ea2fb0</li>
<li><a
href="https://github.com/ijl/orjson/commit/97bf170d9726e91c891f35eae4892801520b9dce"><code>97bf170</code></a>
build update</li>
<li><a
href="https://github.com/ijl/orjson/commit/705515d77b28429d0b7c30c3d781abe52e8a1e5a"><code>705515d</code></a>
3.11.9</li>
<li><a
href="https://github.com/ijl/orjson/commit/d19055d5bab432f98d53b71606a9c6c23fb21bf6"><code>d19055d</code></a>
build update</li>
<li><a
href="https://github.com/ijl/orjson/commit/77e2d96c3febe099cde2447856fe2523d68c71b0"><code>77e2d96</code></a>
MSRV 1.95, remove compiler feature detection</li>
<li><a
href="https://github.com/ijl/orjson/commit/5cbb3d0398a2f42de51210270286fecd798c5d78"><code>5cbb3d0</code></a>
3.11.8</li>
<li><a
href="https://github.com/ijl/orjson/commit/4195d7f263e33076295b75efdcbaf6a55af8674e"><code>4195d7f</code></a>
writer::half</li>
<li><a
href="https://github.com/ijl/orjson/commit/d00641b69410728a735f0855eb1c2843b0a5819b"><code>d00641b</code></a>
writer::uuid</li>
<li>Additional commits viewable in <a
href="https://github.com/ijl/orjson/compare/3.11.6...3.12.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=orjson&package-manager=uv&previous-version=3.11.6&new-version=3.12.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:04:25 -07:00
dependabot[bot] 379bdc448c chore(deps): bump requests from 2.33.0 to 2.34.2 in /libs/partners/huggingface (#40116)
[//]: # (dependabot-start)
⚠️  **Dependabot is rebasing this PR** ⚠️ 

Rebasing might not happen immediately, so don't worry if this takes some
time.

Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.

---

[//]: # (dependabot-end)

Bumps [requests](https://github.com/psf/requests) from 2.33.0 to 2.34.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/psf/requests/releases">requests's
releases</a>.</em></p>
<blockquote>
<h2>v2.34.2</h2>
<h2>2.34.2 (2026-05-14)</h2>
<ul>
<li>Moved <code>headers</code> input type back to <code>Mapping</code>
to avoid invariance issues with <code>MutableMapping</code> and inferred
dict types. Users calling <code>Request.headers.update()</code> may need
to narrow typing in their code. (<a
href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14">https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14</a></p>
<h2>v2.34.1</h2>
<h2>2.34.1 (2026-05-13)</h2>
<p><strong>Bugfixes</strong></p>
<ul>
<li>Widened <code>json</code> input type from <code>dict</code> and
<code>list</code> to <code>Mapping</code>
and <code>Sequence</code>. (<a
href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li>
<li>Changed <code>headers</code> input type to MutableMapping and
removed <code>None</code> from
<code>Request.headers</code> typing to improve handling for users. (<a
href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li>
<li><code>Response.reason</code> moved from <code>str | None</code> to
<code>str</code> to improve handling
for users. (<a
href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li>
<li>Fixed a bug where some bodies with custom <code>__getattr__</code>
implementations
weren't being properly detected as Iterables. (<a
href="https://redirect.github.com/psf/requests/issues/7433">#7433</a>)</li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/k223kim"><code>@​k223kim</code></a> made
their first contribution in <a
href="https://redirect.github.com/psf/requests/pull/7433">psf/requests#7433</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13">https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13</a></p>
<h2>v2.34.0</h2>
<h2>2.34.0 (2026-05-11)</h2>
<p><strong>Announcements</strong></p>
<ul>
<li>
<p>Requests 2.34.0 introduces inline types, replacing those provided by
typeshed. Public API types should be fully compatible with mypy,
pyright,
and ty. <strong>We believe types are comprehensive but if you find
issues, please
report them to the <a
href="https://redirect.github.com/psf/requests/issues/7271">pinned
tracking issue</a>.</strong></p>
<p>Special thanks to <a
href="https://github.com/bastimeyer"><code>@​bastimeyer</code></a>, <a
href="https://github.com/cthoyt"><code>@​cthoyt</code></a>, <a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>,
and <a href="https://github.com/srittau"><code>@​srittau</code></a> for
helping review and test the types ahead of the release. (<a
href="https://redirect.github.com/psf/requests/issues/7272">#7272</a>)</p>
</li>
</ul>
<p><strong>Improvements</strong></p>
<ul>
<li>Digest Auth hashing algorithms have added
<code>usedforsecurity=False</code> to clarify
security considerations. (<a
href="https://redirect.github.com/psf/requests/issues/7310">#7310</a>)</li>
<li>Requests added support for Python 3.15 based on beta1. Downstream
projects
should be able to start testing prior to its release in October. (<a
href="https://redirect.github.com/psf/requests/issues/7422">#7422</a>)</li>
<li>Requests added support for Python 3.14t. (<a
href="https://redirect.github.com/psf/requests/issues/7419">#7419</a>)</li>
</ul>
<p><strong>Bugfixes</strong></p>
<ul>
<li><code>Response.history</code> no longer contains a reference to
itself, preventing
accidental looping when traversing the history list. (<a
href="https://redirect.github.com/psf/requests/issues/7328">#7328</a>)</li>
<li>Requests no longer performs greedy matching on no_proxy domains.
The</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/psf/requests/blob/main/HISTORY.md">requests's
changelog</a>.</em></p>
<blockquote>
<h2>2.34.2 (2026-05-14)</h2>
<ul>
<li>Moved <code>headers</code> input type back to <code>Mapping</code>
to avoid invariance issues
with <code>MutableMapping</code> and inferred dict types. Users calling
<code>Request.headers.update()</code> may need to narrow typing in their
code. (<a
href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li>
</ul>
<h2>2.34.1 (2026-05-13)</h2>
<p><strong>Bugfixes</strong></p>
<ul>
<li>Widened <code>json</code> input type from <code>dict</code> and
<code>list</code> to <code>Mapping</code>
and <code>Sequence</code>. (<a
href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li>
<li>Changed <code>headers</code> input type to MutableMapping and
removed <code>None</code> from
<code>Request.headers</code> typing to improve handling for users. (<a
href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li>
<li><code>Response.reason</code> moved from <code>str | None</code> to
<code>str</code> to improve handling
for users. (<a
href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li>
<li>Fixed a bug where some bodies with custom <code>__getattr__</code>
implementations
weren't being properly detected as Iterables. (<a
href="https://redirect.github.com/psf/requests/issues/7433">#7433</a>)</li>
</ul>
<h2>2.34.0 (2026-05-11)</h2>
<p><strong>Announcements</strong></p>
<ul>
<li>
<p>Requests 2.34.0 introduces inline types, replacing those provided by
typeshed. Public API types should be fully compatible with mypy,
pyright,
and ty. We believe types are comprehensive but if you find issues,
please
report them to the pinned tracking issue.</p>
<p>Special thanks to <a
href="https://github.com/bastimeyer"><code>@​bastimeyer</code></a>, <a
href="https://github.com/cthoyt"><code>@​cthoyt</code></a>, <a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>,
and <a href="https://github.com/srittau"><code>@​srittau</code></a> for
helping review and test the types ahead of the release. (<a
href="https://redirect.github.com/psf/requests/issues/7272">#7272</a>)</p>
</li>
</ul>
<p><strong>Improvements</strong></p>
<ul>
<li>Digest Auth hashing algorithms have added
<code>usedforsecurity=False</code> to clarify
security considerations. (<a
href="https://redirect.github.com/psf/requests/issues/7310">#7310</a>)</li>
<li>Requests added support for Python 3.15 based on beta1. Downstream
projects
should be able to start testing prior to its release in October. (<a
href="https://redirect.github.com/psf/requests/issues/7422">#7422</a>)</li>
<li>Requests added support for Python 3.14t. (<a
href="https://redirect.github.com/psf/requests/issues/7419">#7419</a>)</li>
</ul>
<p><strong>Bugfixes</strong></p>
<ul>
<li><code>Response.history</code> no longer contains a reference to
itself, preventing
accidental looping when traversing the history list. (<a
href="https://redirect.github.com/psf/requests/issues/7328">#7328</a>)</li>
<li>Requests no longer performs greedy matching on no_proxy domains. The
proxy_bypass implementation has been updated with CPython's fix from
bpo-39057. (<a
href="https://redirect.github.com/psf/requests/issues/7427">#7427</a>)</li>
<li>Requests no longer incorrectly strips duplicate leading slashes in
URI paths. This should address user issues with specific presigned
URLs. Note the full fix requires urllib3 2.7.0+. (<a
href="https://redirect.github.com/psf/requests/issues/7315">#7315</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3"><code>6e83187</code></a>
v2.34.2</li>
<li><a
href="https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b"><code>84d10f0</code></a>
Move Request.headers back to Mapping (<a
href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li>
<li><a
href="https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224"><code>b7b549b</code></a>
v2.34.1</li>
<li><a
href="https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe"><code>e511bc7</code></a>
Fix mutability issues with headers input types (<a
href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li>
<li><a
href="https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61"><code>5691f59</code></a>
Update JsonType containers to read-based collections (<a
href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li>
<li><a
href="https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035"><code>2144213</code></a>
Constrain Response.reason to str (<a
href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li>
<li><a
href="https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232"><code>6404f34</code></a>
Fix <code>prepare_body</code> stream detection for
<code>__getattr__</code>-based file wrappers (<a
href="https://redirect.github.com/psf/requests/issues/7">#7</a>...</li>
<li><a
href="https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca"><code>0b401c7</code></a>
v2.34.0</li>
<li><a
href="https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4"><code>86b378d</code></a>
Align Session.get parameters with requests.get (<a
href="https://redirect.github.com/psf/requests/issues/7429">#7429</a>)</li>
<li><a
href="https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f"><code>a4f9a59</code></a>
Port bpo-39057 to Requests (<a
href="https://redirect.github.com/psf/requests/issues/7427">#7427</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/psf/requests/compare/v2.33.0...v2.34.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=requests&package-manager=uv&previous-version=2.33.0&new-version=2.34.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:04:22 -07:00
dependabot[bot] 7c1e6ab62a chore(deps): bump filelock from 3.20.3 to 3.32.5 in /libs/partners/huggingface (#40118)
[//]: # (dependabot-start)
⚠️  **Dependabot is rebasing this PR** ⚠️ 

Rebasing might not happen immediately, so don't worry if this takes some
time.

Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.

---

[//]: # (dependabot-end)

Bumps [filelock](https://github.com/tox-dev/py-filelock) from 3.20.3 to
3.32.5.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/tox-dev/py-filelock/releases">filelock's
releases</a>.</em></p>
<blockquote>
<h2>3.32.5</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>🧪 test(fork): report where a stalled fork stops by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/715">tox-dev/filelock#715</a></li>
<li>📝 docs: say that mode is read-only in the thread-local section by <a
href="https://github.com/Gares95"><code>@​Gares95</code></a> in <a
href="https://redirect.github.com/tox-dev/filelock/pull/716">tox-dev/filelock#716</a></li>
<li>🐛 fix(lease): clear token after failed acquire by <a
href="https://github.com/lprnmns"><code>@​lprnmns</code></a> in <a
href="https://redirect.github.com/tox-dev/filelock/pull/721">tox-dev/filelock#721</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/lprnmns"><code>@​lprnmns</code></a> made
their first contribution in <a
href="https://redirect.github.com/tox-dev/filelock/pull/721">tox-dev/filelock#721</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5">https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5</a></p>
<h2>3.32.4</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>🐛 fix: retry transient denials on open and claim read by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/705">tox-dev/filelock#705</a></li>
<li>🧪 test: deflake six scheduled-run failures by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/704">tox-dev/filelock#704</a></li>
<li>🧪 test: cover a reclaimed private record for real by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/706">tox-dev/filelock#706</a></li>
<li>🧪 test(fork): fork once the event loop has closed by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/714">tox-dev/filelock#714</a></li>
<li>🔧 chore: batch dependency updates weekly on Tuesday by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/713">tox-dev/filelock#713</a></li>
<li>escape the hostname every marker publishes by <a
href="https://github.com/dxbjavid"><code>@​dxbjavid</code></a> in <a
href="https://redirect.github.com/tox-dev/filelock/pull/709">tox-dev/filelock#709</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4">https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4</a></p>
<h2>3.32.3</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>🧪 test(strict): deflake close-fault injections on graalpy by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/697">tox-dev/filelock#697</a></li>
<li>📄 docs: publish llms.txt from the docs build by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/700">tox-dev/filelock#700</a></li>
<li>🐛 fix(fork): survive audit events during interpreter shutdown by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/703">tox-dev/filelock#703</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/tox-dev/filelock/compare/3.32.2...3.32.3">https://github.com/tox-dev/filelock/compare/3.32.2...3.32.3</a></p>
<h2>3.32.2</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>Fix test failures on NetBSD (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/689">#689</a>)
by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/693">tox-dev/filelock#693</a></li>
<li>🧪 test(soft-rw): deflake writer phase-2 peer-marker test by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/694">tox-dev/filelock#694</a></li>
<li>hand back the claim when a heartbeat thread fails to start by <a
href="https://github.com/dxbjavid"><code>@​dxbjavid</code></a> in <a
href="https://redirect.github.com/tox-dev/filelock/pull/691">tox-dev/filelock#691</a></li>
<li>🧪 test(unix): deflake sticky-bit concurrent-unlink on graalpy by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/695">tox-dev/filelock#695</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/tox-dev/filelock/compare/3.32.1...3.32.2">https://github.com/tox-dev/filelock/compare/3.32.1...3.32.2</a></p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst">filelock's
changelog</a>.</em></p>
<blockquote>
<p>###########
Changelog
###########</p>
<p>.. towncrier-draft-entries:: Unreleased</p>
<p>.. towncrier release notes start</p>
<hr />
<p>3.32.5 (2026-08-31)</p>
<hr />
<ul>
<li><code>SoftFileLease.token</code> and
<code>AsyncSoftFileLease.token</code> now read <code>None</code> after a
failed acquisition, so a contender
turned away by a live holder no longer reports a token for a claim it
never published. :pr:<code>721</code></li>
<li>Document that <code>mode</code> has no setter: unlike
<code>poll_interval</code>, <code>timeout</code>, <code>blocking</code>
and <code>lifetime</code>, it is fixed at construction and
<code>lock.mode = ...</code> raises <code>AttributeError</code>.
:pr:<code>716</code></li>
</ul>
<hr />
<p>3.32.4 (2026-08-23)</p>
<hr />
<ul>
<li><code>StrictSoftFileLock</code> always retries a claim read whose
first attempt reports the claim as pending, so a first read
that itself outlasts the retry grace no longer fails closed on a claim
it could have read. :pr:<code>705</code></li>
<li><code>WindowsFileLock</code> waits out a transient
<code>STATUS_ACCESS_DENIED</code> from <code>NtCreateFile</code> for up
to half a second
before raising <code>PermissionError</code>, since a peer unlinking the
lock file as it releases can answer that for a moment; a
real denial still fails fast. :pr:<code>705</code></li>
<li>Every lock class now escapes the hostname it publishes, so a host
whose <code>socket.gethostname()</code> carries a space, a
newline or a byte outside UTF-8 no longer writes a marker it reads back
as malformed. Such a host used to lose a held
<code>SoftReadWriteLock</code> read slot to a peer and could not take a
write slot or a <code>StrictSoftFileLock</code> at all.
:pr:<code>709</code></li>
</ul>
<hr />
<p>3.32.3 (2026-08-13)</p>
<hr />
<ul>
<li>The fork-safety audit hook no longer prints <code>Exception ignored
in audit hook</code> with a <code>TypeError</code> when an audit
event fires during interpreter shutdown, after CPython has already
cleared the module globals. :pr:<code>701</code></li>
</ul>
<hr />
<p>3.32.2 (2026-07-29)</p>
<hr />
<ul>
<li>A <code>SoftReadWriteLock</code> or <code>SoftFileLease</code>
acquire whose heartbeat thread fails to start now unlinks its marker and
hands the claim back, instead of leaving an unrefreshed marker a peer
takes while the caller believes it still holds
the lock. :pr:<code>691</code></li>
</ul>
<hr />
<p>3.32.1 (2026-07-26)</p>
<hr />
<ul>
<li>Canceling an <code>AsyncSoftReadWriteLock</code> acquire now
releases the claim instead of leaking a marker whose heartbeat
wedges every contender. :pr:<code>686</code></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/tox-dev/filelock/commit/1585dfef9355a5c77d4a9498cc34d3a98056fdb9"><code>1585dfe</code></a>
Release 3.32.5</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/00177c32686e60bc5ef9875b5841867ea08d4558"><code>00177c3</code></a>
🐛 fix(lease): clear token after failed acquire (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/721">#721</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/5aeb9b6a5fe1e86dcb1c44a927aefffd607b17b0"><code>5aeb9b6</code></a>
📝 docs: say that mode is read-only in the thread-local section (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/716">#716</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/2634dd1dcc597b319770df027491f16d07662952"><code>2634dd1</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/720">#720</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/37dccf0276f6db1520db9e3482fdf0446c14276e"><code>37dccf0</code></a>
🧪 test(fork): report where a stalled fork stops (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/715">#715</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/cb493d6684ed5d2f923384633c86fef12e29bce2"><code>cb493d6</code></a>
Release 3.32.4</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/fe07a11a7133ddd104322eb79d3c59f966b4ba15"><code>fe07a11</code></a>
escape the hostname every marker publishes (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/709">#709</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/232732f49ed9d230802f527ad60b5d5ad1202a56"><code>232732f</code></a>
🔧 chore: batch dependency updates weekly on Tuesday (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/713">#713</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/2966eb51431ff8ac19eb2bec4e0b67c328437c48"><code>2966eb5</code></a>
🧪 test(fork): fork once the event loop has closed (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/714">#714</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/61511ebc1cc5d40b28f8584f1078e63f2d63fb02"><code>61511eb</code></a>
build(deps): bump astral-sh/setup-uv from 10.0.0 to 10.0.1 (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/712">#712</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/tox-dev/py-filelock/compare/3.20.3...3.32.5">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=filelock&package-manager=uv&previous-version=3.20.3&new-version=3.32.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:04:15 -07:00
dependabot[bot] 37b937e05d chore(deps): bump langsmith from 0.10.16 to 0.12.1 in /libs/partners/huggingface (#40119)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from
0.10.16 to 0.12.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's
releases</a>.</em></p>
<blockquote>
<h2>v0.12.1</h2>
<h2>What's Changed</h2>
<ul>
<li>release(js): 0.10.0 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3474">langchain-ai/langsmith-sdk#3474</a></li>
<li>fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3475">langchain-ai/langsmith-sdk#3475</a></li>
<li>release(py): 0.12.1 by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3478">langchain-ai/langsmith-sdk#3478</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1">https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1</a></p>
<h2>v0.12.0</h2>
<h2>What's Changed</h2>
<ul>
<li>ci: enable CodSpeed flame graphs and pin the benchmarks to one CPU
by <a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3449">langchain-ai/langsmith-sdk#3449</a></li>
<li>fix(py,js)!: make trace sampling deterministic by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3183">langchain-ai/langsmith-sdk#3183</a></li>
<li>fix(py): suppress import-untyped on the optional langsmith_pyo3
import by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3462">langchain-ai/langsmith-sdk#3462</a></li>
<li>chore(py)!: swtich to httpx2 dependency while keeping httpx as a
fallback by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3406">langchain-ai/langsmith-sdk#3406</a></li>
<li>fix!: fail-closed when per-function anonymization callables fail by
<a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3328">langchain-ai/langsmith-sdk#3328</a></li>
<li>fix(py): compress replica writes that carry their own credentials by
<a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3448">langchain-ai/langsmith-sdk#3448</a></li>
<li>perf(py): serialize identical replicas once, into one frame by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3450">langchain-ai/langsmith-sdk#3450</a></li>
<li>release(py): 0.12.0 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3472">langchain-ai/langsmith-sdk#3472</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0</a></p>
<h2>v0.11.2</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: exclude password and email env vars from run metadata by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3417">langchain-ai/langsmith-sdk#3417</a></li>
<li>feat(js): Avoid redundantly sending inputs up in patch by <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3425">langchain-ai/langsmith-sdk#3425</a></li>
<li>release(js): 0.9.0 by <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3426">langchain-ai/langsmith-sdk#3426</a></li>
<li>test(py): continuous benchmarking with CodSpeed by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3420">langchain-ai/langsmith-sdk#3420</a></li>
<li>fix: point migration guide links at their new per-area pages by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3421">langchain-ai/langsmith-sdk#3421</a></li>
<li>fix(js): send langsmith-js User-Agent on generated client calls by
<a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3411">langchain-ai/langsmith-sdk#3411</a></li>
<li>test(py): pin multipart ingest retry matrix and drop warning by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3377">langchain-ai/langsmith-sdk#3377</a></li>
<li>chore: sync langsmith_api by <a
href="https://github.com/langtions-bot"><code>@​langtions-bot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3407">langchain-ai/langsmith-sdk#3407</a></li>
<li>fix(py): handle 64bit+ integers without loss of precision by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3409">langchain-ai/langsmith-sdk#3409</a></li>
<li>fix(py): exclude replica config from the serialized run body by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3442">langchain-ai/langsmith-sdk#3442</a></li>
<li>fix(py,js): consistent (non-v7) UUID rewriting for replicas by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3445">langchain-ai/langsmith-sdk#3445</a></li>
<li>ci: report Python benchmarks to Datadog Test Optimization by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3408">langchain-ai/langsmith-sdk#3408</a></li>
<li>fix(js): close the argument-shape bypass in Anthropic MCP redaction
by <a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3378">langchain-ai/langsmith-sdk#3378</a></li>
<li>feat(livekit): align trace audio with the span timeline by <a
href="https://github.com/carolinedivittorio"><code>@​carolinedivittorio</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3452">langchain-ai/langsmith-sdk#3452</a></li>
<li>release(py): 0.11.2 by <a
href="https://github.com/carolinedivittorio"><code>@​carolinedivittorio</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3457">langchain-ai/langsmith-sdk#3457</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2</a></p>
<h2>v0.11.1</h2>
<h2>What's Changed</h2>
<ul>
<li>release(js): 0.8.11 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3401">langchain-ai/langsmith-sdk#3401</a></li>
<li>chore: sync langsmith_api by <a
href="https://github.com/langtions-bot"><code>@​langtions-bot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3340">langchain-ai/langsmith-sdk#3340</a></li>
<li>fix(sandbox): retry transient WebSocket upgrades in Python and JS by
<a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3388">langchain-ai/langsmith-sdk#3388</a></li>
<li>fix: report incomplete pytest suites accurately by <a
href="https://github.com/jkennedyvz"><code>@​jkennedyvz</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3398">langchain-ai/langsmith-sdk#3398</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/11093852f2fe7b4fc63b88565da37d6cb796bcda"><code>1109385</code></a>
release(py): 0.12.1 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3478">#3478</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/73ac3029c90a8d64aadb71848db87f83acaf97a5"><code>73ac302</code></a>
fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3475">#3475</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/11f7208efcf2484d020ecd6d6ba4f4d6f675a606"><code>11f7208</code></a>
release(js): 0.10.0 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3474">#3474</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/a95cddfe4f406bdef6d92213e7ff30bb7c980d85"><code>a95cddf</code></a>
release(py): 0.12.0 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3472">#3472</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/4ddfa249823d102183054c750fc4ba4a9a356899"><code>4ddfa24</code></a>
perf(py): serialize identical replicas once, into one frame (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3450">#3450</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/983e00acc1c7a5f944fe530db8d0aa13063a2392"><code>983e00a</code></a>
fix(py): compress replica writes that carry their own credentials (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3448">#3448</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/3239181c87dbdb5815746534cd9082227a443595"><code>3239181</code></a>
fix!: fail-closed when per-function anonymization callables fail (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3328">#3328</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/0d3256709ee31a73647cee4846256ecf0be38932"><code>0d32567</code></a>
chore(py)!: swtich to httpx2 dependency while keeping httpx as a
fallback (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3">#3</a>...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/1b64f94fe226f07fcacc81ea8a3e7486c1fc5c14"><code>1b64f94</code></a>
fix(py): suppress import-untyped on the optional langsmith_pyo3 import
(<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3462">#3462</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/e5360c9833cfad5dc20beeef5f42dcd7bd1b4116"><code>e5360c9</code></a>
fix(py,js)!: make trace sampling deterministic (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3183">#3183</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.16...v0.12.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=langsmith&package-manager=uv&previous-version=0.10.16&new-version=0.12.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:04:05 -07:00
dependabot[bot] c50b358308 chore(deps): bump requests from 2.33.0 to 2.34.2 in /libs/partners/chroma (#40127)
Bumps [requests](https://github.com/psf/requests) from 2.33.0 to 2.34.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/psf/requests/releases">requests's
releases</a>.</em></p>
<blockquote>
<h2>v2.34.2</h2>
<h2>2.34.2 (2026-05-14)</h2>
<ul>
<li>Moved <code>headers</code> input type back to <code>Mapping</code>
to avoid invariance issues with <code>MutableMapping</code> and inferred
dict types. Users calling <code>Request.headers.update()</code> may need
to narrow typing in their code. (<a
href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14">https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14</a></p>
<h2>v2.34.1</h2>
<h2>2.34.1 (2026-05-13)</h2>
<p><strong>Bugfixes</strong></p>
<ul>
<li>Widened <code>json</code> input type from <code>dict</code> and
<code>list</code> to <code>Mapping</code>
and <code>Sequence</code>. (<a
href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li>
<li>Changed <code>headers</code> input type to MutableMapping and
removed <code>None</code> from
<code>Request.headers</code> typing to improve handling for users. (<a
href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li>
<li><code>Response.reason</code> moved from <code>str | None</code> to
<code>str</code> to improve handling
for users. (<a
href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li>
<li>Fixed a bug where some bodies with custom <code>__getattr__</code>
implementations
weren't being properly detected as Iterables. (<a
href="https://redirect.github.com/psf/requests/issues/7433">#7433</a>)</li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/k223kim"><code>@​k223kim</code></a> made
their first contribution in <a
href="https://redirect.github.com/psf/requests/pull/7433">psf/requests#7433</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13">https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13</a></p>
<h2>v2.34.0</h2>
<h2>2.34.0 (2026-05-11)</h2>
<p><strong>Announcements</strong></p>
<ul>
<li>
<p>Requests 2.34.0 introduces inline types, replacing those provided by
typeshed. Public API types should be fully compatible with mypy,
pyright,
and ty. <strong>We believe types are comprehensive but if you find
issues, please
report them to the <a
href="https://redirect.github.com/psf/requests/issues/7271">pinned
tracking issue</a>.</strong></p>
<p>Special thanks to <a
href="https://github.com/bastimeyer"><code>@​bastimeyer</code></a>, <a
href="https://github.com/cthoyt"><code>@​cthoyt</code></a>, <a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>,
and <a href="https://github.com/srittau"><code>@​srittau</code></a> for
helping review and test the types ahead of the release. (<a
href="https://redirect.github.com/psf/requests/issues/7272">#7272</a>)</p>
</li>
</ul>
<p><strong>Improvements</strong></p>
<ul>
<li>Digest Auth hashing algorithms have added
<code>usedforsecurity=False</code> to clarify
security considerations. (<a
href="https://redirect.github.com/psf/requests/issues/7310">#7310</a>)</li>
<li>Requests added support for Python 3.15 based on beta1. Downstream
projects
should be able to start testing prior to its release in October. (<a
href="https://redirect.github.com/psf/requests/issues/7422">#7422</a>)</li>
<li>Requests added support for Python 3.14t. (<a
href="https://redirect.github.com/psf/requests/issues/7419">#7419</a>)</li>
</ul>
<p><strong>Bugfixes</strong></p>
<ul>
<li><code>Response.history</code> no longer contains a reference to
itself, preventing
accidental looping when traversing the history list. (<a
href="https://redirect.github.com/psf/requests/issues/7328">#7328</a>)</li>
<li>Requests no longer performs greedy matching on no_proxy domains.
The</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/psf/requests/blob/main/HISTORY.md">requests's
changelog</a>.</em></p>
<blockquote>
<h2>2.34.2 (2026-05-14)</h2>
<ul>
<li>Moved <code>headers</code> input type back to <code>Mapping</code>
to avoid invariance issues
with <code>MutableMapping</code> and inferred dict types. Users calling
<code>Request.headers.update()</code> may need to narrow typing in their
code. (<a
href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li>
</ul>
<h2>2.34.1 (2026-05-13)</h2>
<p><strong>Bugfixes</strong></p>
<ul>
<li>Widened <code>json</code> input type from <code>dict</code> and
<code>list</code> to <code>Mapping</code>
and <code>Sequence</code>. (<a
href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li>
<li>Changed <code>headers</code> input type to MutableMapping and
removed <code>None</code> from
<code>Request.headers</code> typing to improve handling for users. (<a
href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li>
<li><code>Response.reason</code> moved from <code>str | None</code> to
<code>str</code> to improve handling
for users. (<a
href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li>
<li>Fixed a bug where some bodies with custom <code>__getattr__</code>
implementations
weren't being properly detected as Iterables. (<a
href="https://redirect.github.com/psf/requests/issues/7433">#7433</a>)</li>
</ul>
<h2>2.34.0 (2026-05-11)</h2>
<p><strong>Announcements</strong></p>
<ul>
<li>
<p>Requests 2.34.0 introduces inline types, replacing those provided by
typeshed. Public API types should be fully compatible with mypy,
pyright,
and ty. We believe types are comprehensive but if you find issues,
please
report them to the pinned tracking issue.</p>
<p>Special thanks to <a
href="https://github.com/bastimeyer"><code>@​bastimeyer</code></a>, <a
href="https://github.com/cthoyt"><code>@​cthoyt</code></a>, <a
href="https://github.com/edgarrmondragon"><code>@​edgarrmondragon</code></a>,
and <a href="https://github.com/srittau"><code>@​srittau</code></a> for
helping review and test the types ahead of the release. (<a
href="https://redirect.github.com/psf/requests/issues/7272">#7272</a>)</p>
</li>
</ul>
<p><strong>Improvements</strong></p>
<ul>
<li>Digest Auth hashing algorithms have added
<code>usedforsecurity=False</code> to clarify
security considerations. (<a
href="https://redirect.github.com/psf/requests/issues/7310">#7310</a>)</li>
<li>Requests added support for Python 3.15 based on beta1. Downstream
projects
should be able to start testing prior to its release in October. (<a
href="https://redirect.github.com/psf/requests/issues/7422">#7422</a>)</li>
<li>Requests added support for Python 3.14t. (<a
href="https://redirect.github.com/psf/requests/issues/7419">#7419</a>)</li>
</ul>
<p><strong>Bugfixes</strong></p>
<ul>
<li><code>Response.history</code> no longer contains a reference to
itself, preventing
accidental looping when traversing the history list. (<a
href="https://redirect.github.com/psf/requests/issues/7328">#7328</a>)</li>
<li>Requests no longer performs greedy matching on no_proxy domains. The
proxy_bypass implementation has been updated with CPython's fix from
bpo-39057. (<a
href="https://redirect.github.com/psf/requests/issues/7427">#7427</a>)</li>
<li>Requests no longer incorrectly strips duplicate leading slashes in
URI paths. This should address user issues with specific presigned
URLs. Note the full fix requires urllib3 2.7.0+. (<a
href="https://redirect.github.com/psf/requests/issues/7315">#7315</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3"><code>6e83187</code></a>
v2.34.2</li>
<li><a
href="https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b"><code>84d10f0</code></a>
Move Request.headers back to Mapping (<a
href="https://redirect.github.com/psf/requests/issues/7441">#7441</a>)</li>
<li><a
href="https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224"><code>b7b549b</code></a>
v2.34.1</li>
<li><a
href="https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe"><code>e511bc7</code></a>
Fix mutability issues with headers input types (<a
href="https://redirect.github.com/psf/requests/issues/7431">#7431</a>)</li>
<li><a
href="https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61"><code>5691f59</code></a>
Update JsonType containers to read-based collections (<a
href="https://redirect.github.com/psf/requests/issues/7436">#7436</a>)</li>
<li><a
href="https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035"><code>2144213</code></a>
Constrain Response.reason to str (<a
href="https://redirect.github.com/psf/requests/issues/7437">#7437</a>)</li>
<li><a
href="https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232"><code>6404f34</code></a>
Fix <code>prepare_body</code> stream detection for
<code>__getattr__</code>-based file wrappers (<a
href="https://redirect.github.com/psf/requests/issues/7">#7</a>...</li>
<li><a
href="https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca"><code>0b401c7</code></a>
v2.34.0</li>
<li><a
href="https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4"><code>86b378d</code></a>
Align Session.get parameters with requests.get (<a
href="https://redirect.github.com/psf/requests/issues/7429">#7429</a>)</li>
<li><a
href="https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f"><code>a4f9a59</code></a>
Port bpo-39057 to Requests (<a
href="https://redirect.github.com/psf/requests/issues/7427">#7427</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/psf/requests/compare/v2.33.0...v2.34.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=requests&package-manager=uv&previous-version=2.33.0&new-version=2.34.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:03:48 -07:00
dependabot[bot] 6440c8b642 chore(deps): bump idna from 3.15 to 3.19 in /libs/partners/huggingface (#40121)
Bumps [idna](https://github.com/kjd/idna) from 3.15 to 3.19.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/kjd/idna/releases">idna's
releases</a>.</em></p>
<blockquote>
<h2>v3.19</h2>
<ul>
<li>Restore the <code>std3_rules</code> option, which had no effect
since changes
to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a>
processing in Unicode 16. Note that <code>uts46_remap()</code>
defaults to enabling STD3 rules, so direct callers will see input
containing non-LDH ASCII characters rejected again.</li>
<li>Performance improvements to UTS <a
href="https://redirect.github.com/kjd/idna/issues/46">#46</a> mapping,
particularly for
ASCII-only domains.</li>
<li>Test on free-threaded CPython with the GIL disabled and document
thread safety.</li>
<li>Expose the Unicode version of the generated tables as
<code>idna.unicode_version</code>, and show it in <code>idna
--version</code>.</li>
<li>Add <code>code</code>, <code>text</code>, <code>codepoint</code> and
<code>position</code> attributes to
<code>IDNAError</code> so that the failed rule and the offending
character can
be identified without parsing the exception message.</li>
<li>The deprecated <code>transitional</code> argument to
<code>encode()</code> and
<code>uts46_remap()</code> is now completely ignored, and gives a
deprecation warning
for the latter.</li>
<li>Reject A-labels that are not the canonical Punycode encoding of
their U-label.</li>
<li>Fix CONTEXTJ violations raising <code>IDNAError</code> instead of
<code>InvalidCodepointContext</code>.</li>
<li>Consistently raise <code>IDNAError</code> for empty labels and
non-ASCII bytes
passed to label helper functions and the incremental codec.</li>
<li>Add property-based tests, extended fuzzing targets, coverage
measurement, and CI checks that the data tables match the generator
output.</li>
<li>Various code quality and tooling improvements.</li>
</ul>
<p>Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for
contributions to this release.</p>
<h2>v3.18</h2>
<p>No release notes provided.</p>
<h2>v3.17</h2>
<p>No release notes provided.</p>
<h2>v3.16</h2>
<p>No release notes provided.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/kjd/idna/blob/master/HISTORY.md">idna's
changelog</a>.</em></p>
<blockquote>
<h2>3.19 (2026-08-18)</h2>
<ul>
<li>Restore the <code>std3_rules</code> option, which had no effect
since changes
to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a>
processing in Unicode 16. Note that <code>uts46_remap()</code>
defaults to enabling STD3 rules, so direct callers will see input
containing non-LDH ASCII characters rejected again.</li>
<li>Performance improvements to UTS <a
href="https://redirect.github.com/kjd/idna/issues/46">#46</a> mapping,
particularly for
ASCII-only domains.</li>
<li>Test on free-threaded CPython with the GIL disabled and document
thread safety.</li>
<li>Expose the Unicode version of the generated tables as
<code>idna.unicode_version</code>, and show it in <code>idna
--version</code>.</li>
<li>Add <code>code</code>, <code>text</code>, <code>codepoint</code> and
<code>position</code> attributes to
<code>IDNAError</code> so that the failed rule and the offending
character can
be identified without parsing the exception message.</li>
<li>The deprecated <code>transitional</code> argument to
<code>encode()</code> and
<code>uts46_remap()</code> is now completely ignored, and gives a
deprecation warning
for the latter.</li>
<li>Reject A-labels that are not the canonical Punycode encoding of
their U-label.</li>
<li>Fix CONTEXTJ violations raising <code>IDNAError</code> instead of
<code>InvalidCodepointContext</code>.</li>
<li>Consistently raise <code>IDNAError</code> for empty labels and
non-ASCII bytes
passed to label helper functions and the incremental codec.</li>
<li>Add property-based tests, extended fuzzing targets, coverage
measurement, and CI checks that the data tables match the generator
output.</li>
<li>Various code quality and tooling improvements.</li>
</ul>
<p>Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for
contributions to this release.</p>
<h2>3.18 (2026-06-02)</h2>
<ul>
<li>When decoding a domain, add a <code>display</code> argument that
will pass
through invalid labels rather than raising an exception.</li>
</ul>
<h2>3.17 (2026-05-28)</h2>
<ul>
<li>Substantial 75% reduction in memory usage through new data
structures and some optimization in processing speed.</li>
<li>Added a general 1024-character input length cap to the public
validation, conversion, and codec entry points. This is well above
any legitimate domain or label and guards against pathological
inputs.</li>
</ul>
<h2>3.16 (2026-05-22)</h2>
<ul>
<li>Add a command-line interface (<code>python -m idna</code>, also
available as
the <code>idna</code> script). Encodes or decodes one or more domains
supplied</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/kjd/idna/commit/03a9a11dd8aecd4fea742cabe20f4d3d9ed82abb"><code>03a9a11</code></a>
Release 3.19</li>
<li><a
href="https://github.com/kjd/idna/commit/2d2a7ef0c59210a48407b3dde6d884933cecf093"><code>2d2a7ef</code></a>
Pre-release 3.19rc0</li>
<li><a
href="https://github.com/kjd/idna/commit/5cce1308d148019c5fa0febceafa13e99cdacfe7"><code>5cce130</code></a>
Merge pull request <a
href="https://redirect.github.com/kjd/idna/issues/268">#268</a> from
kjd/fix-std3-regex-alert</li>
<li><a
href="https://github.com/kjd/idna/commit/3914b75f3e4cbc11e59f92eeecdb16d10871e57f"><code>3914b75</code></a>
Split the STD3 disallowed-character range so uppercase is explicit</li>
<li><a
href="https://github.com/kjd/idna/commit/ce9fd98ac4073866db276e93834b259f2a5a4ac4"><code>ce9fd98</code></a>
Merge pull request <a
href="https://redirect.github.com/kjd/idna/issues/267">#267</a> from
kjd/housekeeping</li>
<li><a
href="https://github.com/kjd/idna/commit/809240c3cc9358c9c9c79b2d12ffe39e75ccfb0f"><code>809240c</code></a>
Fail CI when the license copyright year is behind the current year</li>
<li><a
href="https://github.com/kjd/idna/commit/d9e16c523d7d25dcc14100fa80f3e303404e09be"><code>d9e16c5</code></a>
Consolidate test fixtures, prune stale gitignore entries, and fix doc
typos</li>
<li><a
href="https://github.com/kjd/idna/commit/ef30feeed3a758e96286fdab0315a551f7f5e7d6"><code>ef30fee</code></a>
Remove dead code and pare back superfluous comments</li>
<li><a
href="https://github.com/kjd/idna/commit/b907913f854d26cc714f721c6c2cb626d41ac468"><code>b907913</code></a>
Tighten the version support and Unicode notes in the README</li>
<li><a
href="https://github.com/kjd/idna/commit/6204cbe343ef438df7c58bc80b94d0f960991d90"><code>6204cbe</code></a>
Ignore local build artifacts and stop packaging stray tooling
config</li>
<li>Additional commits viewable in <a
href="https://github.com/kjd/idna/compare/v3.15...v3.19">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=idna&package-manager=uv&previous-version=3.15&new-version=3.19)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:03:36 -07:00
dependabot[bot] 6935f7a4b7 chore(deps): bump filelock from 3.20.3 to 3.32.5 in /libs/partners/chroma (#40122)
Bumps [filelock](https://github.com/tox-dev/py-filelock) from 3.20.3 to
3.32.5.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/tox-dev/py-filelock/releases">filelock's
releases</a>.</em></p>
<blockquote>
<h2>3.32.5</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>🧪 test(fork): report where a stalled fork stops by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/715">tox-dev/filelock#715</a></li>
<li>📝 docs: say that mode is read-only in the thread-local section by <a
href="https://github.com/Gares95"><code>@​Gares95</code></a> in <a
href="https://redirect.github.com/tox-dev/filelock/pull/716">tox-dev/filelock#716</a></li>
<li>🐛 fix(lease): clear token after failed acquire by <a
href="https://github.com/lprnmns"><code>@​lprnmns</code></a> in <a
href="https://redirect.github.com/tox-dev/filelock/pull/721">tox-dev/filelock#721</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/lprnmns"><code>@​lprnmns</code></a> made
their first contribution in <a
href="https://redirect.github.com/tox-dev/filelock/pull/721">tox-dev/filelock#721</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5">https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5</a></p>
<h2>3.32.4</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>🐛 fix: retry transient denials on open and claim read by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/705">tox-dev/filelock#705</a></li>
<li>🧪 test: deflake six scheduled-run failures by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/704">tox-dev/filelock#704</a></li>
<li>🧪 test: cover a reclaimed private record for real by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/706">tox-dev/filelock#706</a></li>
<li>🧪 test(fork): fork once the event loop has closed by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/714">tox-dev/filelock#714</a></li>
<li>🔧 chore: batch dependency updates weekly on Tuesday by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/713">tox-dev/filelock#713</a></li>
<li>escape the hostname every marker publishes by <a
href="https://github.com/dxbjavid"><code>@​dxbjavid</code></a> in <a
href="https://redirect.github.com/tox-dev/filelock/pull/709">tox-dev/filelock#709</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4">https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4</a></p>
<h2>3.32.3</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>🧪 test(strict): deflake close-fault injections on graalpy by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/697">tox-dev/filelock#697</a></li>
<li>📄 docs: publish llms.txt from the docs build by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/700">tox-dev/filelock#700</a></li>
<li>🐛 fix(fork): survive audit events during interpreter shutdown by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/703">tox-dev/filelock#703</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/tox-dev/filelock/compare/3.32.2...3.32.3">https://github.com/tox-dev/filelock/compare/3.32.2...3.32.3</a></p>
<h2>3.32.2</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>Fix test failures on NetBSD (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/689">#689</a>)
by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/693">tox-dev/filelock#693</a></li>
<li>🧪 test(soft-rw): deflake writer phase-2 peer-marker test by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/694">tox-dev/filelock#694</a></li>
<li>hand back the claim when a heartbeat thread fails to start by <a
href="https://github.com/dxbjavid"><code>@​dxbjavid</code></a> in <a
href="https://redirect.github.com/tox-dev/filelock/pull/691">tox-dev/filelock#691</a></li>
<li>🧪 test(unix): deflake sticky-bit concurrent-unlink on graalpy by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/695">tox-dev/filelock#695</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/tox-dev/filelock/compare/3.32.1...3.32.2">https://github.com/tox-dev/filelock/compare/3.32.1...3.32.2</a></p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst">filelock's
changelog</a>.</em></p>
<blockquote>
<p>###########
Changelog
###########</p>
<p>.. towncrier-draft-entries:: Unreleased</p>
<p>.. towncrier release notes start</p>
<hr />
<p>3.32.5 (2026-08-31)</p>
<hr />
<ul>
<li><code>SoftFileLease.token</code> and
<code>AsyncSoftFileLease.token</code> now read <code>None</code> after a
failed acquisition, so a contender
turned away by a live holder no longer reports a token for a claim it
never published. :pr:<code>721</code></li>
<li>Document that <code>mode</code> has no setter: unlike
<code>poll_interval</code>, <code>timeout</code>, <code>blocking</code>
and <code>lifetime</code>, it is fixed at construction and
<code>lock.mode = ...</code> raises <code>AttributeError</code>.
:pr:<code>716</code></li>
</ul>
<hr />
<p>3.32.4 (2026-08-23)</p>
<hr />
<ul>
<li><code>StrictSoftFileLock</code> always retries a claim read whose
first attempt reports the claim as pending, so a first read
that itself outlasts the retry grace no longer fails closed on a claim
it could have read. :pr:<code>705</code></li>
<li><code>WindowsFileLock</code> waits out a transient
<code>STATUS_ACCESS_DENIED</code> from <code>NtCreateFile</code> for up
to half a second
before raising <code>PermissionError</code>, since a peer unlinking the
lock file as it releases can answer that for a moment; a
real denial still fails fast. :pr:<code>705</code></li>
<li>Every lock class now escapes the hostname it publishes, so a host
whose <code>socket.gethostname()</code> carries a space, a
newline or a byte outside UTF-8 no longer writes a marker it reads back
as malformed. Such a host used to lose a held
<code>SoftReadWriteLock</code> read slot to a peer and could not take a
write slot or a <code>StrictSoftFileLock</code> at all.
:pr:<code>709</code></li>
</ul>
<hr />
<p>3.32.3 (2026-08-13)</p>
<hr />
<ul>
<li>The fork-safety audit hook no longer prints <code>Exception ignored
in audit hook</code> with a <code>TypeError</code> when an audit
event fires during interpreter shutdown, after CPython has already
cleared the module globals. :pr:<code>701</code></li>
</ul>
<hr />
<p>3.32.2 (2026-07-29)</p>
<hr />
<ul>
<li>A <code>SoftReadWriteLock</code> or <code>SoftFileLease</code>
acquire whose heartbeat thread fails to start now unlinks its marker and
hands the claim back, instead of leaving an unrefreshed marker a peer
takes while the caller believes it still holds
the lock. :pr:<code>691</code></li>
</ul>
<hr />
<p>3.32.1 (2026-07-26)</p>
<hr />
<ul>
<li>Canceling an <code>AsyncSoftReadWriteLock</code> acquire now
releases the claim instead of leaking a marker whose heartbeat
wedges every contender. :pr:<code>686</code></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/tox-dev/filelock/commit/1585dfef9355a5c77d4a9498cc34d3a98056fdb9"><code>1585dfe</code></a>
Release 3.32.5</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/00177c32686e60bc5ef9875b5841867ea08d4558"><code>00177c3</code></a>
🐛 fix(lease): clear token after failed acquire (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/721">#721</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/5aeb9b6a5fe1e86dcb1c44a927aefffd607b17b0"><code>5aeb9b6</code></a>
📝 docs: say that mode is read-only in the thread-local section (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/716">#716</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/2634dd1dcc597b319770df027491f16d07662952"><code>2634dd1</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/720">#720</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/37dccf0276f6db1520db9e3482fdf0446c14276e"><code>37dccf0</code></a>
🧪 test(fork): report where a stalled fork stops (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/715">#715</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/cb493d6684ed5d2f923384633c86fef12e29bce2"><code>cb493d6</code></a>
Release 3.32.4</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/fe07a11a7133ddd104322eb79d3c59f966b4ba15"><code>fe07a11</code></a>
escape the hostname every marker publishes (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/709">#709</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/232732f49ed9d230802f527ad60b5d5ad1202a56"><code>232732f</code></a>
🔧 chore: batch dependency updates weekly on Tuesday (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/713">#713</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/2966eb51431ff8ac19eb2bec4e0b67c328437c48"><code>2966eb5</code></a>
🧪 test(fork): fork once the event loop has closed (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/714">#714</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/61511ebc1cc5d40b28f8584f1078e63f2d63fb02"><code>61511eb</code></a>
build(deps): bump astral-sh/setup-uv from 10.0.0 to 10.0.1 (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/712">#712</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/tox-dev/py-filelock/compare/3.20.3...3.32.5">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=filelock&package-manager=uv&previous-version=3.20.3&new-version=3.32.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:03:22 -07:00
dependabot[bot] 3f6bfe80a6 chore(deps): bump langsmith from 0.10.16 to 0.12.1 in /libs/partners/chroma (#40123)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from
0.10.16 to 0.12.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's
releases</a>.</em></p>
<blockquote>
<h2>v0.12.1</h2>
<h2>What's Changed</h2>
<ul>
<li>release(js): 0.10.0 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3474">langchain-ai/langsmith-sdk#3474</a></li>
<li>fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3475">langchain-ai/langsmith-sdk#3475</a></li>
<li>release(py): 0.12.1 by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3478">langchain-ai/langsmith-sdk#3478</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1">https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1</a></p>
<h2>v0.12.0</h2>
<h2>What's Changed</h2>
<ul>
<li>ci: enable CodSpeed flame graphs and pin the benchmarks to one CPU
by <a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3449">langchain-ai/langsmith-sdk#3449</a></li>
<li>fix(py,js)!: make trace sampling deterministic by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3183">langchain-ai/langsmith-sdk#3183</a></li>
<li>fix(py): suppress import-untyped on the optional langsmith_pyo3
import by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3462">langchain-ai/langsmith-sdk#3462</a></li>
<li>chore(py)!: swtich to httpx2 dependency while keeping httpx as a
fallback by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3406">langchain-ai/langsmith-sdk#3406</a></li>
<li>fix!: fail-closed when per-function anonymization callables fail by
<a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3328">langchain-ai/langsmith-sdk#3328</a></li>
<li>fix(py): compress replica writes that carry their own credentials by
<a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3448">langchain-ai/langsmith-sdk#3448</a></li>
<li>perf(py): serialize identical replicas once, into one frame by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3450">langchain-ai/langsmith-sdk#3450</a></li>
<li>release(py): 0.12.0 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3472">langchain-ai/langsmith-sdk#3472</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0</a></p>
<h2>v0.11.2</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: exclude password and email env vars from run metadata by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3417">langchain-ai/langsmith-sdk#3417</a></li>
<li>feat(js): Avoid redundantly sending inputs up in patch by <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3425">langchain-ai/langsmith-sdk#3425</a></li>
<li>release(js): 0.9.0 by <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3426">langchain-ai/langsmith-sdk#3426</a></li>
<li>test(py): continuous benchmarking with CodSpeed by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3420">langchain-ai/langsmith-sdk#3420</a></li>
<li>fix: point migration guide links at their new per-area pages by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3421">langchain-ai/langsmith-sdk#3421</a></li>
<li>fix(js): send langsmith-js User-Agent on generated client calls by
<a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3411">langchain-ai/langsmith-sdk#3411</a></li>
<li>test(py): pin multipart ingest retry matrix and drop warning by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3377">langchain-ai/langsmith-sdk#3377</a></li>
<li>chore: sync langsmith_api by <a
href="https://github.com/langtions-bot"><code>@​langtions-bot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3407">langchain-ai/langsmith-sdk#3407</a></li>
<li>fix(py): handle 64bit+ integers without loss of precision by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3409">langchain-ai/langsmith-sdk#3409</a></li>
<li>fix(py): exclude replica config from the serialized run body by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3442">langchain-ai/langsmith-sdk#3442</a></li>
<li>fix(py,js): consistent (non-v7) UUID rewriting for replicas by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3445">langchain-ai/langsmith-sdk#3445</a></li>
<li>ci: report Python benchmarks to Datadog Test Optimization by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3408">langchain-ai/langsmith-sdk#3408</a></li>
<li>fix(js): close the argument-shape bypass in Anthropic MCP redaction
by <a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3378">langchain-ai/langsmith-sdk#3378</a></li>
<li>feat(livekit): align trace audio with the span timeline by <a
href="https://github.com/carolinedivittorio"><code>@​carolinedivittorio</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3452">langchain-ai/langsmith-sdk#3452</a></li>
<li>release(py): 0.11.2 by <a
href="https://github.com/carolinedivittorio"><code>@​carolinedivittorio</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3457">langchain-ai/langsmith-sdk#3457</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2</a></p>
<h2>v0.11.1</h2>
<h2>What's Changed</h2>
<ul>
<li>release(js): 0.8.11 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3401">langchain-ai/langsmith-sdk#3401</a></li>
<li>chore: sync langsmith_api by <a
href="https://github.com/langtions-bot"><code>@​langtions-bot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3340">langchain-ai/langsmith-sdk#3340</a></li>
<li>fix(sandbox): retry transient WebSocket upgrades in Python and JS by
<a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3388">langchain-ai/langsmith-sdk#3388</a></li>
<li>fix: report incomplete pytest suites accurately by <a
href="https://github.com/jkennedyvz"><code>@​jkennedyvz</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3398">langchain-ai/langsmith-sdk#3398</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/11093852f2fe7b4fc63b88565da37d6cb796bcda"><code>1109385</code></a>
release(py): 0.12.1 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3478">#3478</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/73ac3029c90a8d64aadb71848db87f83acaf97a5"><code>73ac302</code></a>
fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3475">#3475</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/11f7208efcf2484d020ecd6d6ba4f4d6f675a606"><code>11f7208</code></a>
release(js): 0.10.0 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3474">#3474</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/a95cddfe4f406bdef6d92213e7ff30bb7c980d85"><code>a95cddf</code></a>
release(py): 0.12.0 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3472">#3472</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/4ddfa249823d102183054c750fc4ba4a9a356899"><code>4ddfa24</code></a>
perf(py): serialize identical replicas once, into one frame (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3450">#3450</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/983e00acc1c7a5f944fe530db8d0aa13063a2392"><code>983e00a</code></a>
fix(py): compress replica writes that carry their own credentials (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3448">#3448</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/3239181c87dbdb5815746534cd9082227a443595"><code>3239181</code></a>
fix!: fail-closed when per-function anonymization callables fail (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3328">#3328</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/0d3256709ee31a73647cee4846256ecf0be38932"><code>0d32567</code></a>
chore(py)!: swtich to httpx2 dependency while keeping httpx as a
fallback (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3">#3</a>...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/1b64f94fe226f07fcacc81ea8a3e7486c1fc5c14"><code>1b64f94</code></a>
fix(py): suppress import-untyped on the optional langsmith_pyo3 import
(<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3462">#3462</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/e5360c9833cfad5dc20beeef5f42dcd7bd1b4116"><code>e5360c9</code></a>
fix(py,js)!: make trace sampling deterministic (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3183">#3183</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.16...v0.12.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=langsmith&package-manager=uv&previous-version=0.10.16&new-version=0.12.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:03:13 -07:00
dependabot[bot] dca0ae4913 chore(deps): bump protobuf from 6.33.5 to 6.33.6 in /libs/partners/chroma (#40124)
Bumps [protobuf](https://github.com/protocolbuffers/protobuf) from
6.33.5 to 6.33.6.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/protocolbuffers/protobuf/commits">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=protobuf&package-manager=uv&previous-version=6.33.5&new-version=6.33.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:03:05 -07:00
dependabot[bot] 1eebed2c37 chore(deps): bump orjson from 3.11.6 to 3.12.0 in /libs/partners/chroma (#40125)
Bumps [orjson](https://github.com/ijl/orjson) from 3.11.6 to 3.12.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ijl/orjson/releases">orjson's
releases</a>.</em></p>
<blockquote>
<h2>3.12.0</h2>
<h3>Changed</h3>
<ul>
<li>Serialization implementation substantially rewritten.</li>
<li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later,
<code>manylinux_2_39</code> (2024) is targeted instead of
<code>manylinux_2_17</code> (2012).</li>
<li>No longer publish PyPI wheels for ppc64le and s390x.</li>
</ul>
<h2>3.11.9</h2>
<h3>Changed</h3>
<ul>
<li>Build now depends on Rust 1.95 or later instead of 1.89.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fix building on Rust 1.95.</li>
</ul>
<h2>3.11.8</h2>
<h3>Changed</h3>
<ul>
<li>Build and compatibility improvements.</li>
</ul>
<h2>3.11.7</h2>
<h3>Changed</h3>
<ul>
<li>Use a faster library to serialize <code>float</code>. Users with
byte-exact regression
tests should note positive exponents are now written using a
<code>+</code>, e.g.,
<code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are
spec-compliant.</li>
<li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/ijl/orjson/blob/master/CHANGELOG.md">orjson's
changelog</a>.</em></p>
<blockquote>
<h2>3.12.0 - 2026-08-14</h2>
<h3>Changed</h3>
<ul>
<li>Serialization implementation substantially rewritten.</li>
<li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later,
<code>manylinux_2_39</code> (2024) is targeted instead of
<code>manylinux_2_17</code> (2012).</li>
<li>No longer publish PyPI wheels for ppc64le and s390x.</li>
</ul>
<h2>3.11.9 - 2026-05-06</h2>
<h3>Changed</h3>
<ul>
<li>Build now depends on Rust 1.95 or later instead of 1.89.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fix building on Rust 1.95.</li>
</ul>
<h2>3.11.8 - 2026-03-31</h2>
<h3>Changed</h3>
<ul>
<li>Build and compatibility improvements.</li>
</ul>
<h2>3.11.7 - 2026-02-02</h2>
<h3>Changed</h3>
<ul>
<li>Use a faster library to serialize <code>float</code>. Users with
byte-exact regression
tests should note positive exponents are now written using a
<code>+</code>, e.g.,
<code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are
spec-compliant.</li>
<li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ijl/orjson/commit/6737895a1a4e3e26df0569a40147893a786f9a58"><code>6737895</code></a>
3.12.0</li>
<li><a
href="https://github.com/ijl/orjson/commit/c2a6e8ff7b898635fb68a85bd5a62df1edf61cfc"><code>c2a6e8f</code></a>
JsonWriter, iterators</li>
<li><a
href="https://github.com/ijl/orjson/commit/6a2d7a7d66dc3c5698625a7b334c40db459e46ae"><code>6a2d7a7</code></a>
yyjson 1ea2fb0</li>
<li><a
href="https://github.com/ijl/orjson/commit/97bf170d9726e91c891f35eae4892801520b9dce"><code>97bf170</code></a>
build update</li>
<li><a
href="https://github.com/ijl/orjson/commit/705515d77b28429d0b7c30c3d781abe52e8a1e5a"><code>705515d</code></a>
3.11.9</li>
<li><a
href="https://github.com/ijl/orjson/commit/d19055d5bab432f98d53b71606a9c6c23fb21bf6"><code>d19055d</code></a>
build update</li>
<li><a
href="https://github.com/ijl/orjson/commit/77e2d96c3febe099cde2447856fe2523d68c71b0"><code>77e2d96</code></a>
MSRV 1.95, remove compiler feature detection</li>
<li><a
href="https://github.com/ijl/orjson/commit/5cbb3d0398a2f42de51210270286fecd798c5d78"><code>5cbb3d0</code></a>
3.11.8</li>
<li><a
href="https://github.com/ijl/orjson/commit/4195d7f263e33076295b75efdcbaf6a55af8674e"><code>4195d7f</code></a>
writer::half</li>
<li><a
href="https://github.com/ijl/orjson/commit/d00641b69410728a735f0855eb1c2843b0a5819b"><code>d00641b</code></a>
writer::uuid</li>
<li>Additional commits viewable in <a
href="https://github.com/ijl/orjson/compare/3.11.6...3.12.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=orjson&package-manager=uv&previous-version=3.11.6&new-version=3.12.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:02:59 -07:00
dependabot[bot] c583b5b043 chore(deps): bump python-dotenv from 1.2.2 to 1.2.3 in /libs/partners/chroma (#40126)
Bumps [python-dotenv](https://github.com/theskumar/python-dotenv) from
1.2.2 to 1.2.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/theskumar/python-dotenv/releases">python-dotenv's
releases</a>.</em></p>
<blockquote>
<h2>v1.2.3</h2>
<h3>Fixed</h3>
<ul>
<li>Strip a leading UTF-8 BOM from <code>.env</code> file contents so
the first variable is no longer silently lost when the file is saved
with BOM (e.g. by some JetBrains IDEs on Windows) by [<a
href="https://github.com/h1whelan"><code>@​h1whelan</code></a>] in <a
href="https://redirect.github.com/theskumar/python-dotenv/issues/640">#640</a></li>
<li><code>set_key</code> now escapes backslashes, so values containing
them (Windows paths, regular expressions) survive a write/read
round-trip. Quoted values ending in an escaped backslash are no longer
mis-parsed as an escaped quote, which used to swallow the following
lines by [<a
href="https://github.com/dchaudhari7177"><code>@​dchaudhari7177</code></a>]
in <a
href="https://redirect.github.com/theskumar/python-dotenv/issues/680">#680</a></li>
<li><code>dotenv run</code> now prints a friendly error instead of a
traceback when no command is given by [<a
href="https://github.com/bbc2"><code>@​bbc2</code></a>] in <a
href="https://redirect.github.com/theskumar/python-dotenv/issues/606">#606</a></li>
<li>Cache the parsed result for empty <code>.env</code> files so
repeated <code>dotenv_values</code>/<code>load_dotenv</code> calls no
longer re-read the file by [<a
href="https://github.com/ReinerBRO"><code>@​ReinerBRO</code></a>] in <a
href="https://redirect.github.com/theskumar/python-dotenv/issues/638">#638</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md">python-dotenv's
changelog</a>.</em></p>
<blockquote>
<h2>[1.2.3] - 2026-08-16</h2>
<h3>Fixed</h3>
<ul>
<li>Strip a leading UTF-8 BOM from <code>.env</code> file contents so
the first variable is no longer silently lost when the file is saved
with BOM (e.g. by some JetBrains IDEs on Windows) by [<a
href="https://github.com/h1whelan"><code>@​h1whelan</code></a>] in <a
href="https://redirect.github.com/theskumar/python-dotenv/issues/640">#640</a></li>
<li><code>set_key</code> now escapes backslashes, so values containing
them (Windows paths, regular expressions) survive a write/read
round-trip. Quoted values ending in an escaped backslash are no longer
mis-parsed as an escaped quote, which used to swallow the following
lines by [<a
href="https://github.com/dchaudhari7177"><code>@​dchaudhari7177</code></a>]
in <a
href="https://redirect.github.com/theskumar/python-dotenv/issues/680">#680</a></li>
<li><code>dotenv run</code> now prints a friendly error instead of a
traceback when no command is given by [<a
href="https://github.com/bbc2"><code>@​bbc2</code></a>] in <a
href="https://redirect.github.com/theskumar/python-dotenv/issues/606">#606</a></li>
<li>Cache the parsed result for empty <code>.env</code> files so
repeated <code>dotenv_values</code>/<code>load_dotenv</code> calls no
longer re-read the file by [<a
href="https://github.com/ReinerBRO"><code>@​ReinerBRO</code></a>] in <a
href="https://redirect.github.com/theskumar/python-dotenv/issues/638">#638</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59"><code>49515af</code></a>
Bump version: 1.2.2 → 1.2.3</li>
<li><a
href="https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1"><code>8ac846f</code></a>
chore: add release runbook (RELEASING.md) and make release target</li>
<li><a
href="https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166"><code>bb31c94</code></a>
docs: add 1.2.3 release notes (<a
href="https://redirect.github.com/theskumar/python-dotenv/issues/606">#606</a>,
<a
href="https://redirect.github.com/theskumar/python-dotenv/issues/638">#638</a>,
<a
href="https://redirect.github.com/theskumar/python-dotenv/issues/680">#680</a>)</li>
<li><a
href="https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266"><code>f7b18d9</code></a>
fix: round-trip backslashes through set_key (<a
href="https://redirect.github.com/theskumar/python-dotenv/issues/680">#680</a>)</li>
<li><a
href="https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124"><code>751f8c1</code></a>
ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the
github-actions gro...</li>
<li><a
href="https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb"><code>f1937b6</code></a>
chore(deps): update mkdocs-include-markdown-plugin requirement from
&gt;=6.0.0 t...</li>
<li><a
href="https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8"><code>45b9372</code></a>
chore(deps): update pytest requirement from &gt;=3.9 to &gt;=9.0.3 (<a
href="https://redirect.github.com/theskumar/python-dotenv/issues/653">#653</a>)</li>
<li><a
href="https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a"><code>72896e9</code></a>
docs: fix broken mkdocs link in CONTRIBUTING.md (<a
href="https://redirect.github.com/theskumar/python-dotenv/issues/636">#636</a>)</li>
<li><a
href="https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d"><code>72754a1</code></a>
ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the
github-a...</li>
<li><a
href="https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c"><code>078325e</code></a>
ci(security): harden CI/CD supply chain with SHA pinning and
least-privilege ...</li>
<li>Additional commits viewable in <a
href="https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=python-dotenv&package-manager=uv&previous-version=1.2.2&new-version=1.2.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:02:55 -07:00
dependabot[bot] b0d66d19d9 chore(deps): bump idna from 3.15 to 3.19 in /libs/partners/chroma (#40128)
Bumps [idna](https://github.com/kjd/idna) from 3.15 to 3.19.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/kjd/idna/releases">idna's
releases</a>.</em></p>
<blockquote>
<h2>v3.19</h2>
<ul>
<li>Restore the <code>std3_rules</code> option, which had no effect
since changes
to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a>
processing in Unicode 16. Note that <code>uts46_remap()</code>
defaults to enabling STD3 rules, so direct callers will see input
containing non-LDH ASCII characters rejected again.</li>
<li>Performance improvements to UTS <a
href="https://redirect.github.com/kjd/idna/issues/46">#46</a> mapping,
particularly for
ASCII-only domains.</li>
<li>Test on free-threaded CPython with the GIL disabled and document
thread safety.</li>
<li>Expose the Unicode version of the generated tables as
<code>idna.unicode_version</code>, and show it in <code>idna
--version</code>.</li>
<li>Add <code>code</code>, <code>text</code>, <code>codepoint</code> and
<code>position</code> attributes to
<code>IDNAError</code> so that the failed rule and the offending
character can
be identified without parsing the exception message.</li>
<li>The deprecated <code>transitional</code> argument to
<code>encode()</code> and
<code>uts46_remap()</code> is now completely ignored, and gives a
deprecation warning
for the latter.</li>
<li>Reject A-labels that are not the canonical Punycode encoding of
their U-label.</li>
<li>Fix CONTEXTJ violations raising <code>IDNAError</code> instead of
<code>InvalidCodepointContext</code>.</li>
<li>Consistently raise <code>IDNAError</code> for empty labels and
non-ASCII bytes
passed to label helper functions and the incremental codec.</li>
<li>Add property-based tests, extended fuzzing targets, coverage
measurement, and CI checks that the data tables match the generator
output.</li>
<li>Various code quality and tooling improvements.</li>
</ul>
<p>Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for
contributions to this release.</p>
<h2>v3.18</h2>
<p>No release notes provided.</p>
<h2>v3.17</h2>
<p>No release notes provided.</p>
<h2>v3.16</h2>
<p>No release notes provided.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/kjd/idna/blob/master/HISTORY.md">idna's
changelog</a>.</em></p>
<blockquote>
<h2>3.19 (2026-08-18)</h2>
<ul>
<li>Restore the <code>std3_rules</code> option, which had no effect
since changes
to UTS <a href="https://redirect.github.com/kjd/idna/issues/46">#46</a>
processing in Unicode 16. Note that <code>uts46_remap()</code>
defaults to enabling STD3 rules, so direct callers will see input
containing non-LDH ASCII characters rejected again.</li>
<li>Performance improvements to UTS <a
href="https://redirect.github.com/kjd/idna/issues/46">#46</a> mapping,
particularly for
ASCII-only domains.</li>
<li>Test on free-threaded CPython with the GIL disabled and document
thread safety.</li>
<li>Expose the Unicode version of the generated tables as
<code>idna.unicode_version</code>, and show it in <code>idna
--version</code>.</li>
<li>Add <code>code</code>, <code>text</code>, <code>codepoint</code> and
<code>position</code> attributes to
<code>IDNAError</code> so that the failed rule and the offending
character can
be identified without parsing the exception message.</li>
<li>The deprecated <code>transitional</code> argument to
<code>encode()</code> and
<code>uts46_remap()</code> is now completely ignored, and gives a
deprecation warning
for the latter.</li>
<li>Reject A-labels that are not the canonical Punycode encoding of
their U-label.</li>
<li>Fix CONTEXTJ violations raising <code>IDNAError</code> instead of
<code>InvalidCodepointContext</code>.</li>
<li>Consistently raise <code>IDNAError</code> for empty labels and
non-ASCII bytes
passed to label helper functions and the incremental codec.</li>
<li>Add property-based tests, extended fuzzing targets, coverage
measurement, and CI checks that the data tables match the generator
output.</li>
<li>Various code quality and tooling improvements.</li>
</ul>
<p>Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for
contributions to this release.</p>
<h2>3.18 (2026-06-02)</h2>
<ul>
<li>When decoding a domain, add a <code>display</code> argument that
will pass
through invalid labels rather than raising an exception.</li>
</ul>
<h2>3.17 (2026-05-28)</h2>
<ul>
<li>Substantial 75% reduction in memory usage through new data
structures and some optimization in processing speed.</li>
<li>Added a general 1024-character input length cap to the public
validation, conversion, and codec entry points. This is well above
any legitimate domain or label and guards against pathological
inputs.</li>
</ul>
<h2>3.16 (2026-05-22)</h2>
<ul>
<li>Add a command-line interface (<code>python -m idna</code>, also
available as
the <code>idna</code> script). Encodes or decodes one or more domains
supplied</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/kjd/idna/commit/03a9a11dd8aecd4fea742cabe20f4d3d9ed82abb"><code>03a9a11</code></a>
Release 3.19</li>
<li><a
href="https://github.com/kjd/idna/commit/2d2a7ef0c59210a48407b3dde6d884933cecf093"><code>2d2a7ef</code></a>
Pre-release 3.19rc0</li>
<li><a
href="https://github.com/kjd/idna/commit/5cce1308d148019c5fa0febceafa13e99cdacfe7"><code>5cce130</code></a>
Merge pull request <a
href="https://redirect.github.com/kjd/idna/issues/268">#268</a> from
kjd/fix-std3-regex-alert</li>
<li><a
href="https://github.com/kjd/idna/commit/3914b75f3e4cbc11e59f92eeecdb16d10871e57f"><code>3914b75</code></a>
Split the STD3 disallowed-character range so uppercase is explicit</li>
<li><a
href="https://github.com/kjd/idna/commit/ce9fd98ac4073866db276e93834b259f2a5a4ac4"><code>ce9fd98</code></a>
Merge pull request <a
href="https://redirect.github.com/kjd/idna/issues/267">#267</a> from
kjd/housekeeping</li>
<li><a
href="https://github.com/kjd/idna/commit/809240c3cc9358c9c9c79b2d12ffe39e75ccfb0f"><code>809240c</code></a>
Fail CI when the license copyright year is behind the current year</li>
<li><a
href="https://github.com/kjd/idna/commit/d9e16c523d7d25dcc14100fa80f3e303404e09be"><code>d9e16c5</code></a>
Consolidate test fixtures, prune stale gitignore entries, and fix doc
typos</li>
<li><a
href="https://github.com/kjd/idna/commit/ef30feeed3a758e96286fdab0315a551f7f5e7d6"><code>ef30fee</code></a>
Remove dead code and pare back superfluous comments</li>
<li><a
href="https://github.com/kjd/idna/commit/b907913f854d26cc714f721c6c2cb626d41ac468"><code>b907913</code></a>
Tighten the version support and Unicode notes in the README</li>
<li><a
href="https://github.com/kjd/idna/commit/6204cbe343ef438df7c58bc80b94d0f960991d90"><code>6204cbe</code></a>
Ignore local build artifacts and stop packaging stray tooling
config</li>
<li>Additional commits viewable in <a
href="https://github.com/kjd/idna/compare/v3.15...v3.19">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=idna&package-manager=uv&previous-version=3.15&new-version=3.19)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:02:47 -07:00
dependabot[bot] 620aea77ec chore(deps): bump orjson from 3.11.6 to 3.12.0 in /libs/partners/fireworks (#40129)
Bumps [orjson](https://github.com/ijl/orjson) from 3.11.6 to 3.12.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ijl/orjson/releases">orjson's
releases</a>.</em></p>
<blockquote>
<h2>3.12.0</h2>
<h3>Changed</h3>
<ul>
<li>Serialization implementation substantially rewritten.</li>
<li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later,
<code>manylinux_2_39</code> (2024) is targeted instead of
<code>manylinux_2_17</code> (2012).</li>
<li>No longer publish PyPI wheels for ppc64le and s390x.</li>
</ul>
<h2>3.11.9</h2>
<h3>Changed</h3>
<ul>
<li>Build now depends on Rust 1.95 or later instead of 1.89.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fix building on Rust 1.95.</li>
</ul>
<h2>3.11.8</h2>
<h3>Changed</h3>
<ul>
<li>Build and compatibility improvements.</li>
</ul>
<h2>3.11.7</h2>
<h3>Changed</h3>
<ul>
<li>Use a faster library to serialize <code>float</code>. Users with
byte-exact regression
tests should note positive exponents are now written using a
<code>+</code>, e.g.,
<code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are
spec-compliant.</li>
<li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/ijl/orjson/blob/master/CHANGELOG.md">orjson's
changelog</a>.</em></p>
<blockquote>
<h2>3.12.0 - 2026-08-14</h2>
<h3>Changed</h3>
<ul>
<li>Serialization implementation substantially rewritten.</li>
<li>Publish PyPI wheels for Python 3.15. For Python 3.15 and later,
<code>manylinux_2_39</code> (2024) is targeted instead of
<code>manylinux_2_17</code> (2012).</li>
<li>No longer publish PyPI wheels for ppc64le and s390x.</li>
</ul>
<h2>3.11.9 - 2026-05-06</h2>
<h3>Changed</h3>
<ul>
<li>Build now depends on Rust 1.95 or later instead of 1.89.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fix building on Rust 1.95.</li>
</ul>
<h2>3.11.8 - 2026-03-31</h2>
<h3>Changed</h3>
<ul>
<li>Build and compatibility improvements.</li>
</ul>
<h2>3.11.7 - 2026-02-02</h2>
<h3>Changed</h3>
<ul>
<li>Use a faster library to serialize <code>float</code>. Users with
byte-exact regression
tests should note positive exponents are now written using a
<code>+</code>, e.g.,
<code>1.2e+30</code> instead of <code>1.2e30</code>. Both formats are
spec-compliant.</li>
<li>ABI compatibility with CPython 3.15 alpha 5 free-threading.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ijl/orjson/commit/6737895a1a4e3e26df0569a40147893a786f9a58"><code>6737895</code></a>
3.12.0</li>
<li><a
href="https://github.com/ijl/orjson/commit/c2a6e8ff7b898635fb68a85bd5a62df1edf61cfc"><code>c2a6e8f</code></a>
JsonWriter, iterators</li>
<li><a
href="https://github.com/ijl/orjson/commit/6a2d7a7d66dc3c5698625a7b334c40db459e46ae"><code>6a2d7a7</code></a>
yyjson 1ea2fb0</li>
<li><a
href="https://github.com/ijl/orjson/commit/97bf170d9726e91c891f35eae4892801520b9dce"><code>97bf170</code></a>
build update</li>
<li><a
href="https://github.com/ijl/orjson/commit/705515d77b28429d0b7c30c3d781abe52e8a1e5a"><code>705515d</code></a>
3.11.9</li>
<li><a
href="https://github.com/ijl/orjson/commit/d19055d5bab432f98d53b71606a9c6c23fb21bf6"><code>d19055d</code></a>
build update</li>
<li><a
href="https://github.com/ijl/orjson/commit/77e2d96c3febe099cde2447856fe2523d68c71b0"><code>77e2d96</code></a>
MSRV 1.95, remove compiler feature detection</li>
<li><a
href="https://github.com/ijl/orjson/commit/5cbb3d0398a2f42de51210270286fecd798c5d78"><code>5cbb3d0</code></a>
3.11.8</li>
<li><a
href="https://github.com/ijl/orjson/commit/4195d7f263e33076295b75efdcbaf6a55af8674e"><code>4195d7f</code></a>
writer::half</li>
<li><a
href="https://github.com/ijl/orjson/commit/d00641b69410728a735f0855eb1c2843b0a5819b"><code>d00641b</code></a>
writer::uuid</li>
<li>Additional commits viewable in <a
href="https://github.com/ijl/orjson/compare/3.11.6...3.12.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=orjson&package-manager=uv&previous-version=3.11.6&new-version=3.12.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:02:45 -07:00
dependabot[bot] 5b0f646b77 chore(deps): bump langsmith from 0.10.16 to 0.12.1 in /libs/partners/fireworks (#40130)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from
0.10.16 to 0.12.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's
releases</a>.</em></p>
<blockquote>
<h2>v0.12.1</h2>
<h2>What's Changed</h2>
<ul>
<li>release(js): 0.10.0 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3474">langchain-ai/langsmith-sdk#3474</a></li>
<li>fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3475">langchain-ai/langsmith-sdk#3475</a></li>
<li>release(py): 0.12.1 by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3478">langchain-ai/langsmith-sdk#3478</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1">https://github.com/langchain-ai/langsmith-sdk/compare/v0.12.0...v0.12.1</a></p>
<h2>v0.12.0</h2>
<h2>What's Changed</h2>
<ul>
<li>ci: enable CodSpeed flame graphs and pin the benchmarks to one CPU
by <a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3449">langchain-ai/langsmith-sdk#3449</a></li>
<li>fix(py,js)!: make trace sampling deterministic by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3183">langchain-ai/langsmith-sdk#3183</a></li>
<li>fix(py): suppress import-untyped on the optional langsmith_pyo3
import by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3462">langchain-ai/langsmith-sdk#3462</a></li>
<li>chore(py)!: swtich to httpx2 dependency while keeping httpx as a
fallback by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3406">langchain-ai/langsmith-sdk#3406</a></li>
<li>fix!: fail-closed when per-function anonymization callables fail by
<a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3328">langchain-ai/langsmith-sdk#3328</a></li>
<li>fix(py): compress replica writes that carry their own credentials by
<a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3448">langchain-ai/langsmith-sdk#3448</a></li>
<li>perf(py): serialize identical replicas once, into one frame by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3450">langchain-ai/langsmith-sdk#3450</a></li>
<li>release(py): 0.12.0 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3472">langchain-ai/langsmith-sdk#3472</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.2...v0.12.0</a></p>
<h2>v0.11.2</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: exclude password and email env vars from run metadata by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3417">langchain-ai/langsmith-sdk#3417</a></li>
<li>feat(js): Avoid redundantly sending inputs up in patch by <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3425">langchain-ai/langsmith-sdk#3425</a></li>
<li>release(js): 0.9.0 by <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3426">langchain-ai/langsmith-sdk#3426</a></li>
<li>test(py): continuous benchmarking with CodSpeed by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3420">langchain-ai/langsmith-sdk#3420</a></li>
<li>fix: point migration guide links at their new per-area pages by <a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3421">langchain-ai/langsmith-sdk#3421</a></li>
<li>fix(js): send langsmith-js User-Agent on generated client calls by
<a
href="https://github.com/KiewanVillatel"><code>@​KiewanVillatel</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3411">langchain-ai/langsmith-sdk#3411</a></li>
<li>test(py): pin multipart ingest retry matrix and drop warning by <a
href="https://github.com/QuentinBrosse"><code>@​QuentinBrosse</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3377">langchain-ai/langsmith-sdk#3377</a></li>
<li>chore: sync langsmith_api by <a
href="https://github.com/langtions-bot"><code>@​langtions-bot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3407">langchain-ai/langsmith-sdk#3407</a></li>
<li>fix(py): handle 64bit+ integers without loss of precision by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3409">langchain-ai/langsmith-sdk#3409</a></li>
<li>fix(py): exclude replica config from the serialized run body by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3442">langchain-ai/langsmith-sdk#3442</a></li>
<li>fix(py,js): consistent (non-v7) UUID rewriting for replicas by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3445">langchain-ai/langsmith-sdk#3445</a></li>
<li>ci: report Python benchmarks to Datadog Test Optimization by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3408">langchain-ai/langsmith-sdk#3408</a></li>
<li>fix(js): close the argument-shape bypass in Anthropic MCP redaction
by <a href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3378">langchain-ai/langsmith-sdk#3378</a></li>
<li>feat(livekit): align trace audio with the span timeline by <a
href="https://github.com/carolinedivittorio"><code>@​carolinedivittorio</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3452">langchain-ai/langsmith-sdk#3452</a></li>
<li>release(py): 0.11.2 by <a
href="https://github.com/carolinedivittorio"><code>@​carolinedivittorio</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3457">langchain-ai/langsmith-sdk#3457</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2">https://github.com/langchain-ai/langsmith-sdk/compare/v0.11.1...v0.11.2</a></p>
<h2>v0.11.1</h2>
<h2>What's Changed</h2>
<ul>
<li>release(js): 0.8.11 by <a
href="https://github.com/emil-lc"><code>@​emil-lc</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3401">langchain-ai/langsmith-sdk#3401</a></li>
<li>chore: sync langsmith_api by <a
href="https://github.com/langtions-bot"><code>@​langtions-bot</code></a>[bot]
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3340">langchain-ai/langsmith-sdk#3340</a></li>
<li>fix(sandbox): retry transient WebSocket upgrades in Python and JS by
<a
href="https://github.com/ramon-langchain"><code>@​ramon-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3388">langchain-ai/langsmith-sdk#3388</a></li>
<li>fix: report incomplete pytest suites accurately by <a
href="https://github.com/jkennedyvz"><code>@​jkennedyvz</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3398">langchain-ai/langsmith-sdk#3398</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/11093852f2fe7b4fc63b88565da37d6cb796bcda"><code>1109385</code></a>
release(py): 0.12.1 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3478">#3478</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/73ac3029c90a8d64aadb71848db87f83acaf97a5"><code>73ac302</code></a>
fix(py,js): drain the anonymizer walk queue in O(1) [LSDK-412] (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3475">#3475</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/11f7208efcf2484d020ecd6d6ba4f4d6f675a606"><code>11f7208</code></a>
release(js): 0.10.0 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3474">#3474</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/a95cddfe4f406bdef6d92213e7ff30bb7c980d85"><code>a95cddf</code></a>
release(py): 0.12.0 (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3472">#3472</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/4ddfa249823d102183054c750fc4ba4a9a356899"><code>4ddfa24</code></a>
perf(py): serialize identical replicas once, into one frame (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3450">#3450</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/983e00acc1c7a5f944fe530db8d0aa13063a2392"><code>983e00a</code></a>
fix(py): compress replica writes that carry their own credentials (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3448">#3448</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/3239181c87dbdb5815746534cd9082227a443595"><code>3239181</code></a>
fix!: fail-closed when per-function anonymization callables fail (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3328">#3328</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/0d3256709ee31a73647cee4846256ecf0be38932"><code>0d32567</code></a>
chore(py)!: swtich to httpx2 dependency while keeping httpx as a
fallback (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3">#3</a>...</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/1b64f94fe226f07fcacc81ea8a3e7486c1fc5c14"><code>1b64f94</code></a>
fix(py): suppress import-untyped on the optional langsmith_pyo3 import
(<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3462">#3462</a>)</li>
<li><a
href="https://github.com/langchain-ai/langsmith-sdk/commit/e5360c9833cfad5dc20beeef5f42dcd7bd1b4116"><code>e5360c9</code></a>
fix(py,js)!: make trace sampling deterministic (<a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3183">#3183</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.16...v0.12.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=langsmith&package-manager=uv&previous-version=0.10.16&new-version=0.12.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langchain/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-02 01:02:41 -07:00
Sydney Runkleandopen-swe[bot] 49da5817a8 fix(openai): route gpt-5.6-sol to responses API (#40133)
`ChatOpenAI` recognized `gpt-5.6-sol` as a reasoning model but did not
infer that it requires the Responses API. Requests using function tools
and reasoning were therefore sent to Chat Completions and rejected by
OpenAI.

This adds `gpt-5.6-sol` and its dated snapshots to the Responses-only
model inference, with focused unit coverage.

Made by [Open
SWE](https://openswe.vercel.app/agents/2eaa47e3-35c8-5a06-b3af-ad8671c0b584)

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-01 21:43:53 -07:00
ccurmeandopen-swe[bot] 8973dbc6f5 perf(anthropic,langchain): omit middleware trace inputs (#40098)
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-01 21:04:19 -04:00
Hunter Lovellandopen-swe[bot] cf22b84d75 feat(anthropic): add Claude Fable 5.1 support (#40106)
### Summary

- add the `claude-fable-5-1` model profile with its 1M-token context
window, 128K output limit, structured output, and adaptive-reasoning
capabilities
- validate Fable 5-family unsupported sampling and thinking
configurations before requests are sent
- omit default sampling values from Fable request payloads

### Testing

- `uv run --group test pytest tests/unit_tests/test_chat_models.py -q
--no-header --no-summary -k 'fable_5_1 or claude_fable_5_1'`
- `uv run --group lint ruff format --check
langchain_anthropic/chat_models.py langchain_anthropic/data/_profiles.py
tests/unit_tests/test_chat_models.py`
- `uv run --group lint ruff check langchain_anthropic/chat_models.py
langchain_anthropic/data/_profiles.py
tests/unit_tests/test_chat_models.py`

Made by [Open
SWE](https://openswe.vercel.app/agents/ad6c064d-f1de-5f1e-b46d-6b2c5b5c333f)

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-09-01 12:35:31 -07:00
Badar Rahman b4d46a503e docs(xai): point structured outputs guide link to official xAI docs (#40026) 2026-08-31 10:04:49 -04:00
ccurmeandHotragn Pettugani e92c8a08bf fix(core): avoid mutation in google-genai standard content (#40023)
Co-authored-by: Hotragn Pettugani <103170876+Hotragn@users.noreply.github.com>
2026-08-29 22:44:25 -04:00
ccurmeandZhewen Tan 36f0d10348 fix(core): avoid mutation in bedrock converse standard content (#40022)
Co-authored-by: Zhewen Tan <127607634+tandede@users.noreply.github.com>
2026-08-29 22:16:32 -04:00
1e1e238703 fix(langchain): include model destination in agent tool routing (#38355)
Fixes #38351

This PR fixes `create_agent` conditional edge routing when middleware
injects synthetic `ToolMessage` objects for already-satisfied tool
calls.

Previously, `_make_model_to_tools_edge` could return the model loop
entry destination, but that destination was not always included in
`model_to_tools_destinations`. This caused LangGraph to raise
`KeyError("model")`.

Changes:

* Include `loop_entry_node` in `model_to_tools_destinations`.
* Add a regression test covering synthetic `ToolMessage` injection
through `wrap_model_call` middleware using `ExtendedModelResponse` and
`Command(update={"messages": ...})`.

Test:

* `uv run --group test pytest
tests/unit_tests/agents/middleware/core/test_framework.py::test_create_agent_synthetic_tool_messages_reroute_to_model`

Result:

* Passed

---------
Co-authored-by: ccurme <26529506+ccurme@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-08-29 21:41:07 -04:00
Mason Daughertyandopen-swe[bot] 5893459c4f chore(langchain): bump vcrpy test dependency minimum to >=8.2.0 (#39942)
Raises the minimum `vcrpy` version from `>=8.0.0` to `>=8.2.0` in the
integration-test dependencies of `langchain-classic` and `langchain`,
aligning them with `langchain-openai` (`>=8.2.0`) and `langchain-tests`
(`>=8.2.1`), which already require newer versions.

Made by [Open
SWE](https://openswe.vercel.app/agents/cedc18ba-0856-5697-949e-3c6616845c60)

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-08-27 22:28:11 -04:00
67fa96ffad docs(groq): remove duplicate method block from with_structured_output docstring (#39978)
Closes #39977

---

Anyone reading the `ChatGroq.with_structured_output` reference sees the
`method` argument documented twice, and the two blocks disagree with
each other.

The first block is the current one. It lists three options and matches
how the sibling `langchain-openai` package documents the same argument.
The second block is older. It says the argument is `'function_calling'`
or `'json_mode'`, which stopped being true when `'json_schema'` support
was added. A reader who stops at the second block will not know
`'json_schema'` exists, and the duplicate key also breaks API reference
rendering.

This removes the stale block. The one thing it said that the surviving
block did not was the warning that `'json_mode'` does not support
streaming responses or stop sequences, so that warning moves up rather
than being dropped. Everything else in it was already covered above.

No behaviour changes, docstring only.

The added unit test asserts `method` appears once and that `json_schema`
is still described. It fails on the current `master` and passes with
this change.

---

Disclaimer: this contribution was prepared with the assistance of an AI
agent. I reviewed the change, verified the reproduction from the issue
against `master`, and ran the package unit tests and `ruff` locally
before opening it.

---------

Signed-off-by: Mason Daugherty <github@mdrxy.com>
Co-authored-by: Mason Daugherty <github@mdrxy.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-08-27 19:00:42 -04:00
Mason Daugherty 885e858ac4 release(fireworks): 1.6.1 (#39975)
Bumps `langchain-fireworks` to 1.6.1, a patch release carrying one fix
since 1.6.0:

- `fix(fireworks): drop reasoning history blocks` (#39973)
langchain-fireworks==1.6.1
2026-08-27 17:34:05 -04:00
Mason Daughertyandopen-swe[bot] 033ff67b33 fix(fireworks): drop reasoning history blocks (#39973)
Fixed Fireworks requests failing after switching from a model that
stores reasoning blocks in conversation history.

---

Users switching from an OpenAI Responses model to Fireworks could
receive a 400 because canonical `reasoning` blocks remained in
conversation history. `ChatFireworks` now drops those provider-specific
blocks before serializing Chat Completions requests, matching its
handling of other unsupported reasoning formats.

Made by [Open
SWE](https://openswe.vercel.app/agents/15bd8573-dbbf-55f8-8f22-d5295ec6de11)

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-08-27 17:28:40 -04:00
ccurme 4fe9d3062f chore(openai): fix tests (#39972) langchain-core==1.6.1 2026-08-27 15:21:39 -04:00
ccurme 8fa38dc143 revert: release(core): 1.6.2 (#39971) 2026-08-27 14:39:23 -04:00
ccurme 122030d79e release(core): 1.6.2 (#39967) 2026-08-27 14:31:42 -04:00