Skip to content

chore(deps): bump the rag group across 1 directory with 16 updates - #13

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend/rag/rag-aed48fbc3a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend/rag/rag-aed48fbc3a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown

Bumps the rag group with 16 updates in the /backend/rag directory:

Package From To
annotated-types 0.7.0 0.8.0
anyio 4.12.1 4.15.1
certifi 2026.2.25 2026.7.22
grpcio 1.78.0 1.84.0
idna 3.15 3.20
numpy 2.4.3 2.5.3
ollama 0.6.1 0.6.2
portalocker 3.2.0 4.3.2
protobuf 7.34.0 7.36.2
pydantic 2.12.5 2.13.5
pydantic-core 2.41.5 2.49.0
python-dotenv 1.2.2 1.2.3
qdrant-client 1.17.1 1.19.1
typing-inspection 0.4.2 0.4.4
typing-extensions 4.15.0 4.16.0
urllib3 2.7.0 2.8.0

Updates annotated-types from 0.7.0 to 0.8.0

Release notes

Sourced from annotated-types's releases.

v0.8.0

What's Changed

New Contributors

Full Changelog: annotated-types/annotated-types@v0.7.0...v0.8.0

Commits

Updates anyio from 4.12.1 to 4.15.1

Release notes

Sourced from anyio's releases.

4.15.1

  • Implemented a compatibility fix for supporting direct access of anyio.* submodules from the main package even when those submodules were not directly imported first (#1311 <agronholm/anyio#1311)

4.15.0

  • Added support for the newer keyword-only arguments on anyio.Path methods to match the standard library pathlib.Path:

    • follow_symlinks on exists() (Python 3.12+)
    • follow_symlinks on is_dir() (Python 3.13+)
    • follow_symlinks on is_file() (Python 3.13+)
    • follow_symlinks on owner() (Python 3.13+)
    • follow_symlinks on group() (Python 3.13+)
    • newline on read_text() (Python 3.13+)

    (#1286, #1293; PR by @​jaideeppyne)

  • Added amap, gather, and as_completed utility functions to simplify common patterns (#1173; PR by @​Graeme22)

  • Added --anyio-mode command-line option as an alternative to the anyio_mode ini setting, and fix the pytest plugin's auto mode detection to recognize the mode when set via either mechanism(e.g: pytest_asyncio). (#1242; PR by @​EmmanuelNiyonshuti)

  • Added the anyio.Future synchronization primitive which behaves similar to asyncio.Future, allowing tasks to wait for a value (or exception) from another task (#1146; PR by @​Vizonex)

  • Added guidance for managing multiple memory object stream producers and consumers with cloned streams (#330; PR by @​nightcityblade)

  • Added StapledObjectStream.send_nowait() that delegates to the underlying ObjectSendStream, if it implements it (#1241; PR by @​davidbrochart)

  • Added the move_on_at() and fail_at() functions to complement move_on_after() and fail_after()

  • Changed the default name for a task spawned with TaskGroup.create_task(func()) to match the default task name for the analogous task spawned with TaskGroup.start_soon(func) or TaskGroup.start(func) in more situations. Previously, the default name of a TaskGroup.create_task task never included the module name. (The default name for a task spawned with TaskGroup.start_soon or TaskGroup.start typically includes the module name.) (#1234; PR by @​gschaffner)

  • Changed the anyio and anyio.abc modules to lazily (much like 810) import the necessary submodules. This is done by parsing the AST of the module and building a lookup table from the if TYPE_CHECKING: block. A fallback mode has been provided for installations where the source code is unavailable (e.g. PyInstaller). (#1169)

  • Fixed free-threading compatibility issues arising from the fact that on Python 3.14 free-threading builds, newly created threads inherit the current context by default, causing AnyIO to behave erroneously in relation to start_blocking_portal() and anyio.to_thread.run_sync() (#1224; PR by @​EmmanuelNiyonshuti)

  • Fixed SpooledTemporaryFile.readinto() and readinto1() reading twice before rollover, so the destination buffer was overwritten by the second read and the file position advanced twice, silently losing data (#1215; PR by @​c-tonneslan)

  • Added a reason parameter to fail_after (and the new fail_at) allowing for added exception context when raising TimeoutError (#1227; PR by @​Graeme22)

  • Fixed the default TaskHandle.name missing part of the task name for tasks started with TaskGroup.start on Trio (#1231; PR by @​gschaffner)

  • Fixed anyio.run leaking, or at least, delaying collection of loop and root_task due to the root task being cached in a RunVar. (#1203; PR by @​tapetersen)

  • Fixed anyio.Path.with_stem() silently producing a wrong path (e.g. Path(".txt")) instead of raising ValueError when given an empty stem on a path with a non-empty suffix, unlike pathlib.PurePath.with_stem (#1200; PR by @​Sanjays2402)

  • Fixed UNIXSocketStream.aclose() raising asyncio.InvalidStateError when a concurrent receive or send operation had just been cancelled on the asyncio backend (#1267; PR by @​alloutflo)

  • Fixed the pytest plugin importing the deprecated _pytest.python.CallSpec2 alias, which triggers PytestRemovedIn10Warning on pytest>=9.2 and crashes pytest at startup when filterwarnings = error is configured (#1271; PR by @​matthewfeickert)

  • Fixed an asyncio worker thread race that could raise RuntimeError when the event loop closed between checking its state and scheduling the worker result (#1265; PR by @​hansu650)

  • Fixed CapacityLimiter on the asyncio backend over-granting tokens when total_tokens was raised while the limiter was over-subscribed (#1223; PR by @​zelinewang)

... (truncated)

Commits
  • ffcd154 Bumped up the version
  • 0ecf5ed Added a workaround for third party code accessing unimported submodules (#1309)
  • 9283662 Bumped up the version
  • d137692 Improved the instructions for AI agents
  • 033fc52 Shield TemporaryDirectory cleanup from cancellation (#1304)
  • 942e9a6 [pre-commit.ci] pre-commit autoupdate (#1305)
  • b825c3b Fixed pyproject.toml changes not triggering the test suite
  • 9727dc5 Fixed start inconsistencies between trio and asyncio (#1198)
  • b05fe6d Fixed wrong type in move_on_after (#1297)
  • 44d0c93 Fixed asyncio task group coroutine cleanup (#1275)
  • Additional commits viewable in compare view

Updates certifi from 2026.2.25 to 2026.7.22

Commits

Updates grpcio from 1.78.0 to 1.84.0

Release notes

Sourced from grpcio's releases.

Release v1.84.0

This is release 1.84.0 (gimbal) of gRPC Core.

For gRPC documentation, see grpc.io. For previous releases, see Releases.

This release contains refinements, improvements, and bug fixes, with highlights listed below.

Core

  • [promise_based_filter] enable v2_non_owning_waker_implementation experiment. (#43253)
  • [xDS] allow server listener address to match wildcard port. (#43247)
  • [WRR] remove env var guard for custom backend metrics. (#43198)
  • [subchannel] enable connection scaling service config fields. (#43116)
  • [subchannel] add metrics as per A94. (#43140)
  • Fix incorrect hostname suffix matching in no_proxy handling (prevents proxy bypass). (#41915)

C#

  • [C# Grpc.Tools] Add native macOS ARM64 support via universal binaries. (#41222)

Python

  • [Python] Fix -Werror=unused-result error triggered by Cythonized code. (#43313)
  • [Python] Release Python 3.15 wheels publicly. (#43259)
  • [Python][AsyncIO] Fixed reference cycles. (#43121)
  • [Python] fix: remove ghost key in grpc.aio.Metadata.delitem when last value is deleted. (#42974)
  • [Python] Fix the StatusCode Enums to be int. (#43167)
  • [Python] Fixed the parenthesis placement. (#43111)
  • [Python] Removed UsageError exception from registered method. (#43086)
  • [Python] Added registered methods support in AsyncIO stack . (#41796)
  • [Python] AIO Part 4 - Typehints fixes and add Pyright for aio/_channel.py. (#42736)
  • [Python] grpc-status: Relax protobuf dependency lower bound to allow 6.x. (#43000)
  • [Python] Observability plugin fixes. (#42785)

Ruby

  • [Ruby] Fix: Addressed Array of strings passed as metadata. (#42827)

Release v1.84.0-pre2

This is a prerelease of gRPC Core 1.84.0 (gimbal).

For gRPC documentation, see grpc.io. For previous releases, see Releases.

This is a Python-only pre-release that introduces pre-built wheels for Python 3.15.

... (truncated)

Commits
  • 3252a89 Bump release version to 1.84.0 on v1.84.x branch (#43405)
  • c633e39 [Release] Bump version to 1.84.0-pre2 (on v1.84.x branch) (#43401)
  • 12cafee [Backport][v1.84.x] Revert "[Python] Revert Python 3.15 changes due to sanity...
  • 56e86cb Bump release version to 1.84.0-pre1 on v1.84.x branch (#43327)
  • 7ef6a9e [build] Source reflection and channelz v1 schemas from BCR (@​grpc_proto) (#43...
  • c337c3e [core][filters] Unit test framework for v3 filter (#42969)
  • ce22bb4 [PH2][CHTTP2] Retire stream flow control delta early to avoid data race
  • 25c16f9 [PH2][Test] Add destructor tests for the Seq promise combinator.
  • a7fabec [Python] Fix -Werror=unused-result error triggered by Cythonized code (#43313)
  • d92ee43 [util] remove LoadFile() option to append null byte (#41478)
  • Additional commits viewable in compare view

Updates idna from 3.15 to 3.20

Release notes

Sourced from idna's releases.

v3.20

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.

v3.19

  • Restore the std3_rules option, which had no effect since changes to UTS #46 processing in Unicode 16. Note that uts46_remap() defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again.
  • Performance improvements to UTS #46 mapping, particularly for ASCII-only domains.
  • Test on free-threaded CPython with the GIL disabled and document thread safety.
  • Expose the Unicode version of the generated tables as idna.unicode_version, and show it in idna --version.
  • Add code, text, codepoint and position attributes to IDNAError so that the failed rule and the offending character can be identified without parsing the exception message.
  • The deprecated transitional argument to encode() and uts46_remap() is now completely ignored, and gives a deprecation warning for the latter.
  • Reject A-labels that are not the canonical Punycode encoding of their U-label.
  • Fix CONTEXTJ violations raising IDNAError instead of InvalidCodepointContext.
  • Consistently raise IDNAError for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec.
  • Add property-based tests, extended fuzzing targets, coverage measurement, and CI checks that the data tables match the generator output.
  • Various code quality and tooling improvements.

Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for contributions to this release.

v3.18

No release notes provided.

v3.17

No release notes provided.

v3.16

No release notes provided.

Changelog

Sourced from idna's changelog.

3.20 (2026-09-17)

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.

3.19 (2026-08-18)

  • Restore the std3_rules option, which had no effect since changes to UTS #46 processing in Unicode 16. Note that uts46_remap() defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again.
  • Performance improvements to UTS #46 mapping, particularly for ASCII-only domains.
  • Test on free-threaded CPython with the GIL disabled and document thread safety.
  • Expose the Unicode version of the generated tables as idna.unicode_version, and show it in idna --version.
  • Add code, text, codepoint and position attributes to IDNAError so that the failed rule and the offending character can be identified without parsing the exception message.
  • The deprecated transitional argument to encode() and uts46_remap() is now completely ignored, and gives a deprecation warning for the latter.
  • Reject A-labels that are not the canonical Punycode encoding of their U-label.
  • Fix CONTEXTJ violations raising IDNAError instead of InvalidCodepointContext.
  • Consistently raise IDNAError for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec.
  • Add property-based tests, extended fuzzing targets, coverage measurement, and CI checks that the data tables match the generator output.
  • Various code quality and tooling improvements.

Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for contributions to this release.

3.18 (2026-06-02)

  • When decoding a domain, add a display argument that will pass through invalid labels rather than raising an exception.

3.17 (2026-05-28)

  • Substantial 75% reduction in memory usage through new data structures and some optimization in processing speed.
  • Added a general 1024-character input length cap to the public validation, conversion, and codec entry points. This is well above

... (truncated)

Commits
  • d55e65e Release 3.20
  • 0c0824a Pre-release 3.20rc0
  • bd7c316 Note Python 3.15 support in the 3.20 changelog
  • b6cce85 Merge pull request #276 from kjd/unicode-18
  • 9a4bc59 Update to Unicode 18.0.0
  • dfab5a0 Merge branch 'python-3.15'
  • 417c354 Read the latest Unicode version from the DerivedAge.txt header instead of the...
  • cd17392 Merge pull request #274 from kjd/fix-decode-length-check
  • c5796d7 Skip the decode round-trip check for domains past encode's length limit
  • d6ee690 Update to Python 3.15 release candidate in CI and add trove classifier
  • Additional commits viewable in compare view

Updates numpy from 2.4.3 to 2.5.3

Release notes

Sourced from numpy's releases.

v2.5.3 (Sep 6, 2026)

NumPy 2.5.3 Release Notes

The NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2 release. Apart from the usual bug and maintenance work, there are a number of StringDType related fixes for problems discovered during the ongoing string work in the main branch.

This release supports Python versions 3.12-3.15

Changes

  • Casting a fixed-width byte string array (np.bytes_) to StringDType now raises TypeError when the bytes are not valid UTF-8. Previously the invalid bytes were stored as-is and later caused undefined behavior in string operations.

    (gh-32296)

  • MaskedArray._fill_value would become stale when ufuncs that change dtype left the result holding a fill_value typed for the old dtype. The mismatch was silent until something later called _check_fill_value, such as .view(), and then a TypeError would be raised. Now, when the copied fill_value is no longer valid for the new dtype, fall back to the default fill_value for that dtype instead of propagating the stale value. This may raise a ComplexWarning if the fill_value is complex and the new dtype is real.

    (gh-32423)

Contributors

A total of 9 people contributed to this release. People with a "+" by their names contributed a patch for the first time.

  • Charles Harris
  • Iason Krommydas
  • James Davies +
  • Joren Hammudoglu
  • Maanas Arora
  • Matti Picus
  • Nathan Goldbaum
  • Shikhar Goel +
  • Yeonho Kim +

Pull requests merged

A total of 27 pull requests were merged for this release.

  • #32235: MAINT: Prepare 2.5.x for further development

... (truncated)

Commits
  • dd88c0c Merge pull request #32511 from charris/prepare-2.5.3
  • edcac6a REL: Prepare for the NumPy 2.5.3 release
  • fd4d908 Merge pull request #32509 from charris/backport-32496
  • 65bb1da BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (#32496)
  • 294956e Merge pull request #32506 from charris/backport-32503
  • 26428d9 DOC: fix scipy docs links in intersphinx mapping (#32507)
  • 5fab1cb DOC: use static scipy doc site for intershpinx (#32503)
  • 7beed2f Merge pull request #32481 from ngoldbaum/stringdtype-backport
  • 8972f70 Merge pull request #32478 from charris/backport-32466
  • ab1b589 Merge pull request #32477 from charris/backport-32423
  • Additional commits viewable in compare view

Updates ollama from 0.6.1 to 0.6.2

Release notes

Sourced from ollama's releases.

v0.6.2

What's Changed

New Contributors

Full Changelog: ollama/ollama-python@v0.6.1...v0.6.2

Commits

Updates portalocker from 3.2.0 to 4.3.2

Release notes

Sourced from portalocker's releases.

v4.3.2

4.3.2:

  • Restored the coverage badge. CI now merges the coverage data from every matrix cell, holds the merged result to the same 100% threshold each cell already enforces, and uploads it to Coveralls, so the badge measures a build instead of repeating a fixed claim. This release carries that README to PyPI. No library code changed.
  • Refreshed the pinned revisions of the CI actions, setup-uv across a major version among them.

v4.3.1

4.3.1:

  • Refreshed the README in Markdown and added a branded documentation landing page, light and dark logos, and links to the locking guides. README examples now run directly from their Markdown source in tests.
  • Corrected the Linux mandatory-locking advice and clarified that Redis subscription removal and local loss detection can happen at different times during a network failure.
  • Capped Redis retry sleeps at the acquisition deadline. A large check_interval no longer adds a full interval after the timeout. Reply polling retains its final read so buffered holder responses are processed before deciding that a holder is unavailable.
  • Fixed cancelled Redis acquisition leaving a subscription or elected writer behind. Cancellation during setup or between attempts now releases resources, preserves the original exception and permits reuse.
  • Updated the single-file bundler for the Markdown README. Source distributions now include the supporting files needed by their tests.
  • Added workflow security analysis and isolated wheel/sdist installation checks before publication. Actions are pinned to reviewed revisions, job permissions are explicit, and live Redis CI checks fail when the required server is unavailable.

v4.3.0

4.3.0:

  • The filehandle returned by Lock and RLock is now typed by the open mode (#97): a literal text mode yields IO[str], a literal binary mode IO[bytes], so fh.read() type-checks as str or bytes instead of Any. Both classes are generic over the filehandle (Lock[IO[bytes]]), with a PEP 696 default that keeps a bare Lock annotation valid and equal to Lock[IO[str]], matching the default mode of 'a'. A mode that is not a literal at the call site (a Mode-typed variable, a conditional) falls back to the honest IO[Any] of 4.2.0 through a catch-all overload. TemporaryFileLock and its PidFileLock subclass are pinned to IO[str]. No runtime dependency was added: the type variable default comes from a typing_extensions import that only type checkers see.

... (truncated)

Changelog

Sourced from portalocker's changelog.

4.3.2:

  • Restored the coverage badge. CI now merges the coverage data from every matrix cell, holds the merged result to the same 100% threshold each cell already enforces, and uploads it to Coveralls, so the badge measures a build instead of repeating a fixed claim. This release carries that README to PyPI. No library code changed.
  • Refreshed the pinned revisions of the CI actions, setup-uv across a major version among them.

4.3.1:

  • Refreshed the README in Markdown and added a branded documentation landing page, light and dark logos, and links to the locking guides. README examples now run directly from their Markdown source in tests.
  • Corrected the Linux mandatory-locking advice and clarified that Redis subscription removal and local loss detection can happen at different times during a network failure.
  • Capped Redis retry sleeps at the acquisition deadline. A large check_interval no longer adds a full interval after the timeout. Reply polling retains its final read so buffered holder responses are processed before deciding that a holder is unavailable.
  • Fixed cancelled Redis acquisition leaving a subscription or elected writer behind. Cancellation during setup or between attempts now releases resources, preserves the original exception and permits reuse.
  • Updated the single-file bundler for the Markdown README. Source distributions now include the supporting files needed by their tests.
  • Added workflow security analysis and isolated wheel/sdist installation checks before publication. Actions are pinned to reviewed revisions, job permissions are explicit, and live Redis CI checks fail when the required server is unavailable.

4.3.0:

  • The filehandle returned by Lock and RLock is now typed by the open mode (#97): a literal text mode yields IO[str], a literal binary mode IO[bytes], so fh.read() type-checks as str or bytes instead of Any. Both classes are generic over the filehandle (Lock[IO[bytes]]), with a PEP 696 default that keeps a bare Lock annotation valid and equal to Lock[IO[str]], matching the default mode of 'a'. A mode that is not a literal at the call site (a Mode-typed variable, a conditional) falls back to the honest IO[Any] of 4.2.0 through a catch-all overload. TemporaryFileLock and its PidFileLock subclass are pinned to IO[str]. No runtime dependency was added: the type variable default comes from a typing_extensions import that only type checkers see.
  • New portalocker.types.TextMode and portalocker.types.BinaryMode aliases drive the overloads above. portalocker.types.Mode stays a single flat Literal, so typing.get_args(Mode) still returns

... (truncated)

Commits
  • f1f9e3b Prepare 4.3.2 with the restored coverage badge
  • b07eb6f Merge remote-tracking branch 'origin/master' into develop
  • ec881cd Publish combined matrix coverage to Coveralls and restore the badge
  • 70cc8f2 Merge pull request #148 from wolph/dependabot/github_actions/master/actions-7...
  • 9e2f28c Bump the actions group across 1 directory with 4 updates
  • 3901b65 Use integrated documentation URLs for the 4.3.1 release
  • 939d7e0 Render Redis exception references as API links
  • c6a354c Document socket timeouts across supported Redis client versions
  • cbdd2c2 Finish mobile documentation and clarify Redis loss detection
  • b558266 Keep the CI badge and link tied to master
  • Additional commits viewable in compare view

Updates protobuf from 7.34.0 to 7.36.2

Commits

Updates pydantic from 2.12.5 to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731

v2.13.4 2026-05-06

v2.13.4 (2026-05-06)

What's Changed

Packaging

Fixes

Full Changelog: pydantic/pydantic@v2.13.3...v2.13.4

v2.13.3 2026-04-20

v2.13.3 (2026-04-20)

What's Changed

Fixes

Full Changelog: pydantic/pydantic@v2.13.2...v2.13.3

v2.13.2 2026-04-17

v2.13.2 (2026-04-17)

What's Changed

Fixes

  • Fix ValidationInfo.field_name missing with model_validate_json() by @​Viicos in #13084

Full Changelog: pydantic/pydantic@v2.13.1...v2.13.2

v2.13.1 2026-04-15

... (truncated)

Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731

v2.13.4 (2026-05-06)

GitHub release

What's Changed

Packaging

Fixes

v2.13.3 (2026-04-20)

GitHub release

What's Changed

Fixes

v2.13.2 (2026-04-17)

GitHub release

What's Changed

Fixes

  • Fix ValidationInfo.field_name missing with model_validate_json() by @​Viicos in #13084

v2.13.1 (2026-04-15)

... (truncated)

Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates pydantic-core from 2.41.5 to 2.49.0

Commits

Updates python-dotenv from 1.2.2 to 1.2.3

Release notes

Sourced from python-dotenv's releases.

v1.2.3

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638
Changelog

Sourced from python-dotenv's changelog.

[1.2.3] - 2026-08-16

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638
Commits

Bumps the rag group with 16 updates in the /backend/rag directory:

| Package | From | To |
| --- | --- | --- |
| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |
| [anyio](https://github.com/agronholm/anyio) | `4.12.1` | `4.15.1` |
| [certifi](https://github.com/certifi/python-certifi) | `2026.2.25` | `2026.7.22` |
| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |
| [idna](https://github.com/kjd/idna) | `3.15` | `3.20` |
| [numpy](https://github.com/numpy/numpy) | `2.4.3` | `2.5.3` |
| [ollama](https://github.com/ollama/ollama-python) | `0.6.1` | `0.6.2` |
| [portalocker](https://github.com/wolph/portalocker) | `3.2.0` | `4.3.2` |
| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.34.0` | `7.36.2` |
| [pydantic](https://github.com/pydantic/pydantic) | `2.12.5` | `2.13.5` |
| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.5` | `2.49.0` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |
| [qdrant-client](https://github.com/qdrant/qdrant-client) | `1.17.1` | `1.19.1` |
| [typing-inspection](https://github.com/pydantic/typing-inspection) | `0.4.2` | `0.4.4` |
| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |
| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |



Updates `annotated-types` from 0.7.0 to 0.8.0
- [Release notes](https://github.com/annotated-types/annotated-types/releases)
- [Commits](annotated-types/annotated-types@v0.7.0...v0.8.0)

Updates `anyio` from 4.12.1 to 4.15.1
- [Release notes](https://github.com/agronholm/anyio/releases)
- [Commits](agronholm/anyio@4.12.1...4.15.1)

Updates `certifi` from 2026.2.25 to 2026.7.22
- [Commits](certifi/python-certifi@2026.02.25...2026.07.22)

Updates `grpcio` from 1.78.0 to 1.84.0
- [Release notes](https://github.com/grpc/grpc/releases)
- [Commits](grpc/grpc@v1.78.0...v1.84.0)

Updates `idna` from 3.15 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.15...v3.20)

Updates `numpy` from 2.4.3 to 2.5.3
- [Release notes](https://github.com/numpy/numpy/releases)
- [Changelog](https://github.com/numpy/numpy/blob/main/doc/RELEASE_WALKTHROUGH.rst)
- [Commits](numpy/numpy@v2.4.3...v2.5.3)

Updates `ollama` from 0.6.1 to 0.6.2
- [Release notes](https://github.com/ollama/ollama-python/releases)
- [Commits](ollama/ollama-python@v0.6.1...v0.6.2)

Updates `portalocker` from 3.2.0 to 4.3.2
- [Release notes](https://github.com/wolph/portalocker/releases)
- [Changelog](https://github.com/wolph/portalocker/blob/develop/CHANGELOG.rst)
- [Commits](wolph/portalocker@v3.2.0...v4.3.2)

Updates `protobuf` from 7.34.0 to 7.36.2
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Commits](https://github.com/protocolbuffers/protobuf/commits)

Updates `pydantic` from 2.12.5 to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.12.5...v2.13.5)

Updates `pydantic-core` from 2.41.5 to 2.49.0
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/main/HISTORY.md)
- [Commits](https://github.com/pydantic/pydantic/commits)

Updates `python-dotenv` from 1.2.2 to 1.2.3
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.2...v1.2.3)

Updates `qdrant-client` from 1.17.1 to 1.19.1
- [Release notes](https://github.com/qdrant/qdrant-client/releases)
- [Commits](qdrant/qdrant-client@v1.17.1...v1.19.1)

Updates `typing-inspection` from 0.4.2 to 0.4.4
- [Release notes](https://github.com/pydantic/typing-inspection/releases)
- [Changelog](https://github.com/pydantic/typing-inspection/blob/main/HISTORY.md)
- [Commits](pydantic/typing-inspection@v0.4.2...v0.4.4)

Updates `typing-extensions` from 4.15.0 to 4.16.0
- [Release notes](https://github.com/python/typing_extensions/releases)
- [Changelog](https://github.com/python/typing_extensions/blob/main/CHANGELOG.md)
- [Commits](python/typing_extensions@4.15.0...4.16.0)

Updates `urllib3` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

---
updated-dependencies:
- dependency-name: annotated-types
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
- dependency-name: anyio
  dependency-version: 4.15.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
- dependency-name: certifi
  dependency-version: 2026.7.22
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
- dependency-name: grpcio
  dependency-version: 1.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
- dependency-name: numpy
  dependency-version: 2.5.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
- dependency-name: ollama
  dependency-version: 0.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rag
- dependency-name: portalocker
  dependency-version: 4.3.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: rag
- dependency-name: protobuf
  dependency-version: 7.36.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
- dependency-name: pydantic-core
  dependency-version: 2.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
- dependency-name: python-dotenv
  dependency-version: 1.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rag
- dependency-name: qdrant-client
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
- dependency-name: typing-inspection
  dependency-version: 0.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rag
- dependency-name: typing-extensions
  dependency-version: 4.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rag
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants