Skip to content

fix(deps): bump the python-dependencies group in /backend with 6 updates - #174

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend/python-dependencies-8209b8dff3
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend/python-dependencies-8209b8dff3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group in /backend with 6 updates:

Package From To
coverage 7.16.1 7.16.2
cryptography 50.0.1 50.0.2
fastapi 0.141.1 0.142.2
pylint 4.0.9 4.1.1
pymongo 4.18.1 4.18.2
uvicorn 0.53.0 0.54.0

Updates coverage from 7.16.1 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Commits

Updates cryptography from 50.0.1 to 50.0.2

Changelog

Sourced from cryptography's changelog.

50.0.2 - 2026-09-30


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.3.
* Added ``abi3.abi3t`` wheels for free-threaded CPython 3.15 and later.
* Updated to PyO3 0.29.2, which fixes building ``cryptography`` on Cygwin and
  MSYS2.

.. _v50-0-1:

Commits

Updates fastapi from 0.141.1 to 0.142.2

Release notes

Sourced from fastapi's releases.

0.142.2

Fixes

  • 🐛 Allow startup when automatic OpenTelemetry configuration fails. PR #16418 by @​tiangolo.

0.142.1

Fixes

0.142.0

Features

Refactors

Docs

Translations

Internal

... (truncated)

Commits

Updates pylint from 4.0.9 to 4.1.1

Release notes

Sourced from pylint's releases.

v4.1.1

What's new in Pylint 4.1.1?

Release date: 2026-09-29

Other Changes

  • Pylint 4.1.0 could not be uploaded to PyPI, because it required an unreleased version of dill on Python 3.15, and PyPI refuses such a dependency. 4.1.1 is the first 4.1 release available on PyPI, see the 4.1.0 changes below.

    Refs #11495

v4.1.0

What's new in Pylint 4.1.0?

Release date: 2026-09-29

Startup is about 25% faster thanks to lazy imports. The import checker caches its isort configuration, which makes pylint about 17% faster on ansible. Finding the files to lint with --recursive=y no longer walks ignored directories such as .venv or node_modules, which took seconds on large trees. The duplicate-code checker and symilar also received optimizations that result in considerable performance improvements and memory use reduction on larger codebases. For example, pandas analysis went from 20 min to 55 s and pylint does not get OOM-killed when analyzing cpython anymore.

Python 3.15 support progresses: the unpacking in comprehensions added by PEP 798 no longer raises false positives, and the standard library deprecations of Python 3.15 are followed.

For CI, there is a new built-in junit output format (--output-format=junit), the NO_COLOR and FORCE_COLOR environment variables are respected, and the files to lint can now be set with the files option in the configuration file.

New checks: looping-through-iterator, impossible-comparison, chained-comparison-all-equal and using-comprehension-unpacking-in-unsupported-version.

Running with --jobs no longer duplicates the messages of extensions or ignores extensions enabled in the configuration.

Plugin authors: the confidence parameter can no longer be None, except in is_message_enabled, and the MSG_STATE_* constants are deprecated in favor of the MessageDisableReason enum.

The required astroid version is now 4.3.2. See the astroid changelog for additional fixes, features, and performance improvements applicable to pylint.

... (truncated)

Commits
  • 8c6daca Bump pylint to 4.1.1, update changelog (#11499)
  • bdb17b3 [Backport maintenance/4.1.x] Only pin the unreleased dill for the tests (#11498)
  • 92bb7ba Bump pylint to 4.1.0, update changelog
  • 9144956 Fix a crash in import-private-name on attribute access rooted at a non-Name n...
  • 68366cb Fix false positive for unnecessary-lambda when variable is reassigned or de...
  • c741677 [pre-commit.ci] pre-commit autoupdate (#11488)
  • a9ebdf6 Add regression test for unsubscriptable-object FP on class_getitem (#11487)
  • b877d3b Do not flag ungrouped imports inside OS platform guards (#11217)
  • 87351be Update OSS-Fuzz docs for Python 3.14 (#11485)
  • 4f263c1 Fix access checks through called methods (#11456)
  • Additional commits viewable in compare view

Updates pymongo from 4.18.1 to 4.18.2

Release notes

Sourced from pymongo's releases.

PyMongo 4.18.2

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-2-released/343732

CVE-2026-96749 CVE-2026-96748 CVE-2026-96747

Changelog

Sourced from pymongo's changelog.

Changes in Version 4.18.2 (2026/09/24)

Version 4.18.2 is a bug fix release.

  • Hardened the bson buffer size guard against signed integer overflow. (CVE-2026-96749_).
  • Fixed connection string parsing to percent-decode each host individually. (CVE-2026-96748_).
  • Client-side field level encryption now rejects a KMS endpoint ending in .sock. (CVE-2026-96747_).

.. _CVE-2026-96749: https://www.cve.org/CVERecord?id=CVE-2026-96749 .. _CVE-2026-96748: https://www.cve.org/CVERecord?id=CVE-2026-96748 .. _CVE-2026-96747: https://www.cve.org/CVERecord?id=CVE-2026-96747

Issues Resolved ...............

See the PyMongo 4.18.2 release notes in JIRA_ for the list of resolved issues in this release.

.. _PyMongo 4.18.2 release notes in JIRA: https://jira.mongodb.org/secure/ReleaseNote.jspa?projectId=10004&version=52896

Commits

Updates uvicorn from 0.53.0 to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-dependencies group in /backend with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.16.1` | `7.16.2` |
| [cryptography](https://github.com/pyca/cryptography) | `50.0.1` | `50.0.2` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.141.1` | `0.142.2` |
| [pylint](https://github.com/pylint-dev/pylint) | `4.0.9` | `4.1.1` |
| [pymongo](https://github.com/mongodb/mongo-python-driver) | `4.18.1` | `4.18.2` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.53.0` | `0.54.0` |


Updates `coverage` from 7.16.1 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.1...7.16.2)

Updates `cryptography` from 50.0.1 to 50.0.2
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@50.0.1...50.0.2)

Updates `fastapi` from 0.141.1 to 0.142.2
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.141.1...0.142.2)

Updates `pylint` from 4.0.9 to 4.1.1
- [Release notes](https://github.com/pylint-dev/pylint/releases)
- [Commits](pylint-dev/pylint@v4.0.9...v4.1.1)

Updates `pymongo` from 4.18.1 to 4.18.2
- [Release notes](https://github.com/mongodb/mongo-python-driver/releases)
- [Changelog](https://github.com/mongodb/mongo-python-driver/blob/main/doc/changelog.rst)
- [Commits](mongodb/mongo-python-driver@4.18.1...4.18.2)

Updates `uvicorn` from 0.53.0 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.53.0...0.54.0)

---
updated-dependencies:
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: cryptography
  dependency-version: 50.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: fastapi
  dependency-version: 0.142.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: pylint
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: pymongo
  dependency-version: 4.18.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added backend python Pull requests that update python code labels Oct 3, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) October 3, 2026 22:16

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants