build(deps): bump the python-deps group across 1 directory with 21 updates#915
Open
dependabot[bot] wants to merge 2 commits into
Open
build(deps): bump the python-deps group across 1 directory with 21 updates#915dependabot[bot] wants to merge 2 commits into
dependabot[bot] wants to merge 2 commits into
Conversation
…dates Bumps the python-deps group with 19 updates in the / directory: | Package | From | To | | --- | --- | --- | | [redis](https://github.com/redis/redis-py) | `7.4.0` | `8.0.1` | | [tuf](https://github.com/theupdateframework/python-tuf) | `6.0.0` | `7.0.0` | | [dynaconf](https://github.com/dynaconf/dynaconf) | `3.2.13` | `3.3.0` | | [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.49` | `2.0.51` | | [psycopg2](https://github.com/psycopg/psycopg2) | `2.9.11` | `2.9.12` | | [alembic](https://github.com/sqlalchemy/alembic) | `1.18.4` | `1.18.5` | | [pydantic](https://github.com/pydantic/pydantic) | `2.12.5` | `2.13.4` | | [boto3](https://github.com/boto/boto3) | `1.42.85` | `1.43.36` | | [awswrangler](https://github.com/aws/aws-sdk-pandas) | `3.15.1` | `3.17.0` | | [sigstore](https://github.com/sigstore/sigstore-python) | `4.2.0` | `4.3.0` | | [pymysql](https://github.com/PyMySQL/PyMySQL) | `1.1.2` | `1.2.0` | | [google-cloud-kms](https://github.com/googleapis/google-cloud-python) | `3.12.0` | `3.14.0` | | [tox](https://github.com/tox-dev/tox) | `4.52.0` | `4.56.1` | | [coverage](https://github.com/coveragepy/coveragepy) | `7.13.5` | `7.14.3` | | [ruff](https://github.com/astral-sh/ruff) | `0.15.9` | `0.15.20` | | [mypy](https://github.com/python/mypy) | `1.20.0` | `2.1.0` | | [pytest](https://github.com/pytest-dev/pytest) | `9.0.3` | `9.1.1` | | [pre-commit](https://github.com/pre-commit/pre-commit) | `4.5.1` | `4.6.0` | | [myst-parser](https://github.com/executablebooks/MyST-Parser) | `5.0.0` | `5.1.0` | Updates `redis` from 7.4.0 to 8.0.1 - [Release notes](https://github.com/redis/redis-py/releases) - [Changelog](https://github.com/redis/redis-py/blob/master/CHANGES) - [Commits](redis/redis-py@v7.4.0...v8.0.1) Updates `tuf` from 6.0.0 to 7.0.0 - [Release notes](https://github.com/theupdateframework/python-tuf/releases) - [Changelog](https://github.com/theupdateframework/python-tuf/blob/develop/docs/CHANGELOG.md) - [Commits](theupdateframework/python-tuf@v6.0.0...v7.0.0) Updates `dynaconf` from 3.2.13 to 3.3.0 - [Release notes](https://github.com/dynaconf/dynaconf/releases) - [Changelog](https://github.com/dynaconf/dynaconf/blob/master/CHANGELOG.md) - [Commits](dynaconf/dynaconf@3.2.13...3.3.0) Updates `securesystemslib` from 1.3.1 to 1.4.0 - [Release notes](https://github.com/secure-systems-lab/securesystemslib/releases) - [Changelog](https://github.com/secure-systems-lab/securesystemslib/blob/main/CHANGELOG.md) - [Commits](secure-systems-lab/securesystemslib@v1.3.1...v1.4.0) Updates `sqlalchemy` from 2.0.49 to 2.0.51 - [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases) - [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst) - [Commits](https://github.com/sqlalchemy/sqlalchemy/commits) Updates `psycopg2` from 2.9.11 to 2.9.12 - [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS) - [Commits](psycopg/psycopg2@2.9.11...2.9.12) Updates `alembic` from 1.18.4 to 1.18.5 - [Release notes](https://github.com/sqlalchemy/alembic/releases) - [Changelog](https://github.com/sqlalchemy/alembic/blob/main/CHANGES) - [Commits](https://github.com/sqlalchemy/alembic/commits) Updates `pydantic` from 2.12.5 to 2.13.4 - [Release notes](https://github.com/pydantic/pydantic/releases) - [Changelog](https://github.com/pydantic/pydantic/blob/main/HISTORY.md) - [Commits](pydantic/pydantic@v2.12.5...v2.13.4) Updates `boto3` from 1.42.85 to 1.43.36 - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.42.85...1.43.36) Updates `awswrangler` from 3.15.1 to 3.17.0 - [Release notes](https://github.com/aws/aws-sdk-pandas/releases) - [Commits](aws/aws-sdk-pandas@3.15.1...3.17.0) Updates `sigstore` from 4.2.0 to 4.3.0 - [Release notes](https://github.com/sigstore/sigstore-python/releases) - [Changelog](https://github.com/sigstore/sigstore-python/blob/main/CHANGELOG.md) - [Commits](sigstore/sigstore-python@v4.2.0...v4.3.0) Updates `pymysql` from 1.1.2 to 1.2.0 - [Release notes](https://github.com/PyMySQL/PyMySQL/releases) - [Changelog](https://github.com/PyMySQL/PyMySQL/blob/main/CHANGELOG.md) - [Commits](PyMySQL/PyMySQL@v1.1.2...v1.2.0) Updates `google-cloud-kms` from 3.12.0 to 3.14.0 - [Release notes](https://github.com/googleapis/google-cloud-python/releases) - [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md) - [Commits](googleapis/google-cloud-python@google-cloud-kms-v3.12.0...google-cloud-kms-v3.14.0) Updates `tox` from 4.52.0 to 4.56.1 - [Release notes](https://github.com/tox-dev/tox/releases) - [Changelog](https://github.com/tox-dev/tox/blob/main/docs/changelog.rst) - [Commits](tox-dev/tox@4.52.0...4.56.1) Updates `coverage` from 7.13.5 to 7.14.3 - [Release notes](https://github.com/coveragepy/coveragepy/releases) - [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst) - [Commits](coveragepy/coveragepy@7.13.5...7.14.3) Updates `ruff` from 0.15.9 to 0.15.20 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.15.9...0.15.20) Updates `mypy` from 1.20.0 to 2.1.0 - [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md) - [Commits](python/mypy@v1.20.0...v2.1.0) Updates `pytest` from 9.0.3 to 9.1.1 - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst) - [Commits](pytest-dev/pytest@9.0.3...9.1.1) Updates `virtualenv` from 21.2.0 to 21.5.1 - [Release notes](https://github.com/pypa/virtualenv/releases) - [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst) - [Commits](pypa/virtualenv@21.2.0...21.5.1) Updates `pre-commit` from 4.5.1 to 4.6.0 - [Release notes](https://github.com/pre-commit/pre-commit/releases) - [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md) - [Commits](pre-commit/pre-commit@v4.5.1...v4.6.0) Updates `myst-parser` from 5.0.0 to 5.1.0 - [Release notes](https://github.com/executablebooks/MyST-Parser/releases) - [Changelog](https://github.com/executablebooks/MyST-Parser/blob/master/CHANGELOG.md) - [Commits](executablebooks/MyST-Parser@v5.0.0...v5.1.0) --- updated-dependencies: - dependency-name: redis dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: python-deps - dependency-name: tuf dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: python-deps - dependency-name: dynaconf dependency-version: 3.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: securesystemslib dependency-version: 1.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: sqlalchemy dependency-version: 2.0.51 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-deps - dependency-name: psycopg2 dependency-version: 2.9.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-deps - dependency-name: alembic dependency-version: 1.18.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-deps - dependency-name: pydantic dependency-version: 2.13.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: boto3 dependency-version: 1.43.36 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: awswrangler dependency-version: 3.17.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: sigstore dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: pymysql dependency-version: 1.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: google-cloud-kms dependency-version: 3.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: tox dependency-version: 4.56.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: coverage dependency-version: 7.14.3 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: ruff dependency-version: 0.15.20 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-deps - dependency-name: mypy dependency-version: 2.1.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: python-deps - dependency-name: pytest dependency-version: 9.1.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: virtualenv dependency-version: 21.5.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: pre-commit dependency-version: 4.6.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: myst-parser dependency-version: 5.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps ... Signed-off-by: dependabot[bot] <support@github.com>
kairoaraujo
approved these changes
Jun 29, 2026
tuf 7.0.0 changed `Metadata.from_dict` / `Signed.from_dict` (and `securesystemslib`'s `Key.from_dict`) to be destructive as they consume the dict passed by reference, popping `signed`/`signatures` and mutating the nested `keys` dict in place (dict values become `SSlibKey` objects). Signed-off-by: Kairo de Araujo <kairo@dearaujo.nl>
kairoaraujo
approved these changes
Jun 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the python-deps group with 19 updates in the / directory:
7.4.08.0.16.0.07.0.03.2.133.3.02.0.492.0.512.9.112.9.121.18.41.18.52.12.52.13.41.42.851.43.363.15.13.17.04.2.04.3.01.1.21.2.03.12.03.14.04.52.04.56.17.13.57.14.30.15.90.15.201.20.02.1.09.0.39.1.14.5.14.6.05.0.05.1.0Updates
redisfrom 7.4.0 to 8.0.1Release notes
Sourced from redis's releases.
... (truncated)
Commits
7c0fd11Updating lib version to 8.0.1b7a4d7dAvoid per-check fd allocation in hiredis_socket_can_read()— usepoll()...eec778efix(asyncio): release pooled connection when Pipeline.reset() is cancelled (#...08e01bbFixing pubsub's listen method to be blocking. (#4119)3d5257afix(search): parse RESP3 FT.SEARCH responses with bytes-typed keys (#4109)cce28ffFix hiredis readiness checks for high file descriptors (#4115)e20691cFixed async MultiDBClient with underlying RedisCluster (#4108)ea37fccFix async cluster node connection release on write errors (#4111)f4146faUpdating lib version + supported Redis versions in README.md + updating the R...d47674eBumping github-versions actions (#4102)Updates
tuffrom 6.0.0 to 7.0.0Release notes
Sourced from tuf's releases.
Changelog
Sourced from tuf's changelog.
Commits
353bdb7Merge pull request #2942 from jku/release-prep85ce3e8Prepare 7.0 release1a62020Merge commit from fork5c0c36dMerge pull request #2938 from theupdateframework/dependabot/pip/test-and-lint...57cc1a7Merge pull request #2937 from theupdateframework/dependabot/pip/build-and-rel...9d7d1b9Merge pull request #2939 from theupdateframework/dependabot/pip/dependencies-...be4f314Merge pull request #2941 from theupdateframework/dependabot/github_actions/ac...6348502build(deps): bump the action-dependencies group across 1 directory with 2 upd...4b6e35abuild(deps): bump cryptography in the dependencies group4883f02build(deps): bump the test-and-lint-dependencies group with 2 updatesUpdates
dynaconffrom 3.2.13 to 3.3.0Release notes
Sourced from dynaconf's releases.
... (truncated)
Changelog
Sourced from dynaconf's changelog.
... (truncated)
Commits
f425fdbRelease version 3.3.010d090bchore(ci): disable backport creation for 3.3.0 release only0b7aaa4chore(ci): go back to using uv sync + uv runec6119fchore(ci): update to use uv tool install2068632chore(ci): add missing venv creation to uv installa6393f1chore(ci): remove unnecessary uv install from workflowsa49ba70chore(ci): don't generate uv.lock for release/publish workflows8d8e061chore(ci): add new release 'framework' to the CI2edaa2crefactor(cache): scope value cache to instance and remove global id counter70164cedocs: Fix broken links and wrong merge behaviorUpdates
securesystemslibfrom 1.3.1 to 1.4.0Release notes
Sourced from securesystemslib's releases.
Changelog
Sourced from securesystemslib's changelog.
Commits
47b0f45Merge pull request #1130 from jku/prep-1.4.0e4f4bdaPrepare 1.4.03e130e8Merge pull request #1107 from Spinbazz/fix/cka_id_size_limita690d88Merge pull request #1127 from secure-systems-lab/dependabot/pip/test-and-lint...c03c919build(deps): bump the test-and-lint-dependencies group with 2 updates6363b26lint fixese4d0d33Fix issue with odd hex length keyids442d842Merge pull request #1121 from secure-systems-lab/dependabot/pip/build-and-rel...5cfe19eMerge pull request #1083 from jku/enable-hsm-tests-on-mac2303329tests: Enable HSM tests on MacUpdates
sqlalchemyfrom 2.0.49 to 2.0.51Release notes
Sourced from sqlalchemy's releases.
... (truncated)
Commits
Updates
psycopg2from 2.9.11 to 2.9.12Changelog
Sourced from psycopg2's changelog.
... (truncated)
Commits
3a6d9d6ci: include almalinux in whieel buildingebca6bfchore: bump to version 3.9.120196f02build(deps): bump pypa/cibuildwheel from 3.3.1 to 3.4.0d157bdcbuild(deps): bump docker/setup-qemu-action from 3 to 47fccc0fbuild(deps): bump actions/upload-artifact from 6 to 7d52a61echore: bump dependency librariesb231d72chore: fix building binary images6d76e84Merge pull request #1836 from psycopg/fix-1835f7e314cfix: overflow in malformed intervaleb905c1docs: replace bare except clause with except ExceptionUpdates
alembicfrom 1.18.4 to 1.18.5Release notes
Sourced from alembic's releases.
... (truncated)
Commits
Updates
pydanticfrom 2.12.5 to 2.13.4Release notes
Sourced from pydantic's releases.
... (truncated)
Changelog
Sourced from pydantic's changelog.
... (truncated)
Commits
cf67d4bFix lintingf0d8a21Prepare release v2.13.45e3fe1dCheck for pydantic tag pattern in CI7f9edccDocument tagging conventionsb46a0c9Adaptpydantic-corelinker flags on macOS50629c8Update to PyPy 7.3.228522ebbPreserveRootModelcore metadataa37f3afAdaptMISSINGsentinel test to work with unreleasedtyping_extensionsver...909259aRemove Logfire example in documentation2c4174cBump libc from 0.2.155 to 0.2.185Updates
boto3from 1.42.85 to 1.43.36Commits
1d26f21Merge branch 'release-1.43.36'111333bBumping version to 1.43.369d1fa23Add changelog entries from botocore6d7f3c2Update security docs to use newer versions of openssl and python (#4796)c5b26caMerge branch 'release-1.43.35'c3750acMerge branch 'release-1.43.35' into develop46e77cdBumping version to 1.43.359919edeAdd changelog entries from botocore1820b7dMerge branch 'release-1.43.34'0065dbeMerge branch 'release-1.43.34' into developUpdates
awswranglerfrom 3.15.1 to 3.17.0Release notes
Sourced from awswrangler's releases.
... (truncated)
Commits
60a6ffb[skip ci] chore: Update layers.rstca8f64d[skip ci] chore: Update layers.rst07c8a25fix(lambda-layer): drop unused libicu DT_NEEDED via --as-needed linker flag434fbdachore: Release 3.17.0 (#3371)917601fchore(lambda-layer): bump pyarrow to 24.0.0 (#3375)639e488chore(deps): bump pydantic-settings from 2.13.1 to 2.14.2 (#3386)783e7e9chore(deps-dev): bump msgpack from 1.2.0 to 1.2.1 (#3385)75d0dfachore(deps-dev): bump the development-dependencies group with 6 updates (#3383)